Ensure 'logging buffered severity ' is greater than or equal to '3'

Information

Determines which syslog messages should be temporary stored in the local buffer so they can be checked by the administrator

Rationale:

The internal log buffer serves as a temporary storage location, thus allowing the administrator performing a health check on the system to locally have the last logs generated. Given that the size of the buffer is limited, it is better to have a specific set of syslog messages to be kept therein.

Solution

Firepower Management Center:

Devices > Platform settings > Syslog > Logging setup

See Also

https://www.cisco.com/c/en/us/td/docs/security/firepower/640/hardening/ftd/FTD_Hardening_Guide_v64.html

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12c.

Plugin: Cisco_Firepower

Control ID: b0131b6e6f3484f86df002c75aaac2bbde0b700f9eeb62985fa89c11c1e6e29d