Ensure 'syslog hosts' is configured correctly

Information

Sets the SNMP notification recipient or the NMS or SNMP manager that can connect to the Firepower.

Rationale:

Syslog messages are an invaluable tool for accounting, monitoring, and routine troubleshooting. Logging to a central syslog server is a method of collecting messages from devices to a server running a syslog daemon. This helps in aggregation of logs and alerts. This form of logging provides protected long-term storage for logs, since are also useful in incident handling.

Solution

Firepower Device Manager:

Use Objects > Syslog Servers and Device > System Settings > Logging Settings.

or

Firepower Management Center:

Device > Platform Setting > Threat Defense Policy > Syslog > Syslog Settings

See Also

https://www.cisco.com/c/en/us/td/docs/security/firepower/640/hardening/ftd/FTD_Hardening_Guide_v64.html

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-4(1)

Plugin: Cisco_Firepower

Control ID: 57749511daa5e1c1aab9e004159dd56f9165b152d10f3ffd8e0d36a76b501434