Configure a Syslog Server
To configure a syslog server to handle messages generated from your system, perform the following steps.
If you want this syslog server to receive security events such as connection and intrusion events, see also FTD Platform Settings That Apply to Security Event Syslog Messages.
Note | In ?? and later, the Management and Diagnostic interfaces are merged. If Platform Settings for syslog servers or SNMP hosts specify the Diagnostic interface by name, then you must use separate Platform Settings policies for merged and unmerged devices (?? and earlier, and some upgraded ?? FTDs). |
Before you begin
-
See requirements in Guidelines for Logging.
-
Make sure your devices can reach your syslog collector on the network.
Procedure
Step 1 | Select FTD policy. and create or edit the |
Step 2 | Select . |
Step 3 | Check the Allow user traffic to pass when TCP syslog server is down check box, to allow traffic if any syslog server that is using the TCP protocol is down. |
Step 4 | Enter a size of the queue for storing syslog messages on the security appliance when syslog server is busy in the Message queue size (messages) field. The minimum is 1 message. The default is 512. Specify 0 to allow an unlimited number of messages to be queued (subject to available block memory). |
Step 5 | Click Add to add a new syslog server. |
Step 6 | Click Save. You can now go to and deploy the policy to assigned devices. The changes are not active until you deploy them. |
What to do next
-
Deploy configuration changes; see Deploy Configuration Changes.