Cisco Multicloud Defense User Guide

PDF

Cisco Multicloud Defense User Guide

Log Forwarding Profile

Want to summarize with AI?

Log in

Learn how a Log Forwarding Profile sends gateway, VPC, and VNet logs to one or more third-party destinations for monitoring and analysis.


A log forwarding profile allows you to send a collection of gateway, VPC, and VNet logs to a third party. The communication between Multicloud Defense and the third party of your choice contains the log type that needs to be forwarded and the destination server profiles the logs will be sent to. You can have a single profile or a profile group that sends logs to multiple endpoints simultaneously.

Note that this profile does not include metrics. See Gateway Metrics Forwarding Profile for more information about forwarding log metrics.


Create a Standalone Log Forwarding Profile

Use the following procedure to create a standalone profile to forward logs with:

Procedure

1.

Navigate to Infrastructure > Profiles > Log Forwarding.

2.

Click Create.

3.

Enter a unique Profile Name.

4.

(Optional) Enter a Description. This may help differentiate from other profiles with a similar name.

5.

Expand the Type drop-down menu and select Standalone.

6.

Expand the Destination drop-down menu and select the third-party application to send logs to.

7.

Based on the type of destination you select in step 7, enter the appropriate information when prompted to secure the final endpoint where the logs are forwarded to. Note that not all options are available based on the type of destination.

8.

Click Save.

What to do next

Attach the profile to a policy rule set. See Rule Sets and Rule Set Groups for more information.


Create a Log Forwarding Group

Use the following procedure to create a profile group to forward logs with:

Before you begin

  • You must have at least one third party application to forward the metric to prior to creating this profile.

  • You must have at least two standalone metrics forwarding profiles already created. See Create a Standalone Log Forwarding Profile for more information.

Procedure

1.

Navigate to Infrastructure > Profiles > Log Forwarding.

2.

Click Create.

3.

Enter a unique Profile Name.

4.

(Optional) Enter a Description. This may help differentiate from other profiles with a similar name.

5.

Expand the Type drop-down menu and select Group.

6.

Under Group Details, click Add for every new row you need to add to the profile.

7.

Expand the drop-down menus for each row to select a profile to add to the group. If you want to remove a profile at any point prior to saving, select the profile's checkbox so it is highlighted and select Remove.

8.

Click Save.

What to do next

Attach the profile to a policy rule set. See Rule Sets and Rule Set Groups for more information.