Learn how to send Cloud-Delivered Firewall Management Center-Managed -managed event logs directly to Security Analytics and Logging (SaaS), including enabling Cisco Cloud Events and choosing which event types to send.
Configure the Cloud-Delivered Firewall Management Center to send events directly to SAL (SaaS). Follow this procedure to enable the Cisco cloud event global setting in the Cloud-Delivered Firewall Management Center. When needed, you can exclude individual Firewall Threat Defense devices from sending event logs to SAL (SaaS). For more information, see Enable or Disable Threat Defense Devices to Send Event logs to SAL (SaaS) Using a Direct Connection.
Before you begin
-
Onboard devices to the Cloud-Delivered Firewall Management Center, assign licenses to these devices, and configure these devices to send events directly to SAL (SaaS).
-
Enable connection logging on a per-rule basis by editing a rule and choosing the Log at Beginning of Connection and Log at End of Connection options.