Cisco Security Cloud Control: Secure Firewall Device Management

PDF

Cisco Security Cloud Control: Secure Firewall Device Management

Syslog server objects

Want to summarize with AI?

Log in

An overview of syslog server objects, including SEC destinations, ports, severity levels, custom event lists, and cloud event delivery.


FDM-managed devices have a limited capacity to store events. To maximize storage for events, you can configure an external server. A system log (syslog) server object identifies a server that can receive connection-oriented or diagnostic syslog messages. If you have a syslog server set up for log collection and analysis, you can use the Security Cloud Control to create objects to define them and use the objects in the related policies.


Create and Edit Syslog Server Objects

To create a new syslog server object, follow these steps:

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the left pane, click Objects.

3.

Click the Create Object button .

4.

Select Syslog Server under FDM-managed device object types

5.

Configure the syslog server object properties:

  • IP Address—Enter the IP address of the syslog server.

  • Protocol Type—Select the protocol that your syslog server uses to receive messages. If you select TCP, the system can recognize when the syslog server is not available, and stops sending events until the server is available again.

  • Port Number—Enter a valid port number to use for syslog. If your syslog server uses default ports, enter 514 as the default UDP port or 1470 as the default TCP port. If the server does not use default ports, enter the correct port number. The port must be in the range 1025 to 65535.

  • Select an interface—Select which interface should be used for sending diagnostic syslog messages. Connection and intrusion events always use the management interface. Your interface selection determines the IP address associated with syslog messages. Note that you can only select one of the options listed below. You cannot select both. Select one of the following options:

    • Data Interface—Use the data interface you select for diagnostic syslog messages. Select an interface from the generated list. If the server is accessible through a bridge group member interface, select the bridge group interface (BVI). If it is accessible through the Diagnostic interface (the physical management interface), we recommend that you select Management Interface instead of this option. You cannot select a passive interface. For connection and intrusion syslog messages, the source IP address will either be for the management interface, or for the gateway interface if you route through data interfaces.

    • Management Interface—Use the virtual management interface for all types of syslog messages. The source IP address will either be for the management interface, or for the gateway interface if you route through data interfaces.

6.

Click Add.

7.

Review and deploy now the changes you made, or wait and deploy multiple changes at once.


Edit Syslog Server Objects

To edit an existing syslog server object, follow these steps:

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the left pane, click Objects.

3.

Locate the desired syslog server object and select it. You can filter the object list by the syslog server object type.

4.

In the Actions pane, click Edit.

5.

Make the desired edits and click Save.

6.

Confirm the changes you made.

7.

Review and deploy now the changes you made, or wait and deploy multiple changes at once.


Create a Syslog Server Object for Secure Logging Analytics (SaaS)

Create a syslog server object with the IP address, TCP port, or UDP port of the Secure Event Connector (SEC) you want to send events to. You would create one syslog object for every SEC that you have onboarded to your tenant but you would only send events from one rule to one syslog object representing one SEC.


Procedure

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the left pane, click Objects.

3.

Click the Create Object button .

4.

Select Syslog Server under FDM-managed device object types.

5.

Configure the syslog server object properties. To find these properties of the SEC, from the navigation pane on the left, choose Tools & Services > Secure Connectors. Then select the Secure Event Connector you want to configure the syslog object for and look in the Details pane on the right.

  • IP Address—Enter the IP address of the SEC.

  • Protocol Type—Select TCP or UDP.

  • Port Number—Enter port 10125 if you selected TCP or 10025 if you selected UDP.

  • Select an interface—Select the interface configured to reach the SEC.

Note

FDM-managed device supports one syslog object per IP address so you will have to choose between using TCP and UDP.

6.

Click Add.