> For the complete documentation index, see [llms.txt](https://docs.blusapphire.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.blusapphire.io/log-forwarding/03_log-forwarding-guide/log-forward/cisco/cisco-ironport.md).

# Cisco Ironport

## CISCO IRONPORT&#x20;

To configure IronPort device to send syslog events, please follow the following steps:&#x20;

* Log in to Cisco IronPort user interface.&#x20;
* Select System Administration \ Log Subscriptions.&#x20;
* Click Add Log Subscription.&#x20;
* Configure the following values:&#x20;
* Log Type - Define a log subscription for both Ironport Text Mail Logs and System Logs.&#x20;
* Log Name - Type a log name.&#x20;
* File Name - Use the default configuration value.&#x20;
* Maximum File Size - Use the default configuration value.&#x20;
* Log Level - Select Information (Default).&#x20;
* Retrieval Method - Select Syslog Push.&#x20;
* Hostname - Type the IP address of Log Collector.&#x20;
* Protocol - Select UDP.&#x20;
* Facility - Use the default configuration value. This value depends on the configured Log Type.&#x20;
* Save the subscription.&#x20;
