Learn how to send Cloud-Delivered Firewall Management Center-Managed -managed event logs directly to Security Analytics and Logging (SaaS), including enabling Cisco Cloud Events and choosing which event types to send.
Configure the Cloud-Delivered Firewall Management Center to send events directly to SAL (SaaS). Follow this procedure to enable the Cisco cloud event global setting in the Cloud-Delivered Firewall Management Center. When needed, you can exclude individual Firewall Threat Defense devices from sending event logs to SAL (SaaS). For more information, see Enable or Disable Threat Defense Devices to Send Event logs to SAL (SaaS) Using a Direct Connection.
Before you begin
-
Onboard devices to the Cloud-Delivered Firewall Management Center, assign licenses to these devices, and configure these devices to send events directly to SAL (SaaS).
-
Enable connection logging on a per-rule basis by editing a rule and choosing the Log at Beginning of Connection and Log at End of Connection options.
Procedure
| 1. | Log in to Security Cloud Control. |
|
| 2. | From the Security Cloud Control Home page, click Firewall. |
|
| 3. | In the left pane, click . |
|
| 4. | Click Cloud-Delivered FMC, and in the System pane that is located at the right-side, click Cisco Cloud Events. |
|
| 5. | In the Configure Cisco Cloud Events widget, do the following:
|