Cisco ASA with FirePOWER services
Last updated
Last updated
Creating a Syslog Alert Response
Choose ASA Firepower Configuration > Policies > Actions > Alerts.
From the Create Alert drop-down menu, choose Create Syslog Alert.
Enter a Name for the alert.
In the Host field, enter the hostname or IP address of “Log Collector”.
In the Port field, enter the port the server uses for syslog messages. Please check Appendix A for default port list.
From the Facility list, choose a facility LOCAL7.
From the Severity list, choose a severity INFO.
Click Save.
Configuration for sending the Traffic Events
Navigate to ASA Firepower Configuration > Policies > Access Control Policy
Edit the access rule and navigate to logging option.
Select log at Beginning and End of Connection options.
Navigate to Send Connection Events to option , select Syslog, and then select a Syslog alert response.
Click Save.