Configure a Cisco ASA with firepower to forward syslogs
Creating a Syslog Alert Response
- Navigate to Firepower Configuration > Policies > Actions > Alerts
- From the Create Alert drop-down menu, choose Create Syslog Alert, input or select the following values:
- Name ActZero_Logging
- Host The local IP of the ActZero VM
- Port 514
- Facility LOCAL7
- Severity INFO
- Click Save.
Update policies to log events.
- Navigate to ASA Firepower Configuration > Policies > Access Control Policy
- For each access rule, edit the configuration rule and navigate to logging option.
- Select at End of Connection options.
- In the Send Connection Events to option , select Syslog ensure that the checkbox is on
- Then select ActZero_Logging from the dropdown list.
- Click Save. Reference Cisco Firepower documentation for further detail.
Was this documentation helpful? Please send us your feedback!