Send Security Event Syslog Messages from Classic Devices
Before you begin
-
Configure policies to generate security events.
-
Ensure that your devices can reach the syslog server(s).
-
Confirm that the syslog server(s) can accept remote messages.
-
For important information about connection logging, see the chapter on Connection Logging.
Procedure
Step 1 | Configure an alert response for your Classic devices: |
Step 2 | Configure syslog settings in the access control policy:
|
Step 3 | If you will send file and malware events:
|
Step 4 | If you will send intrusion events: |
What to do next
-
(Optional) Configure different logging settings for individual access control rules. See the applicable table rows in Configuration Locations for Syslogs for Connection and Security Intelligence Events (All Devices). These settings will require syslog alert responses, which are configured as described in Creating a Syslog Alert Response. They do not use the settings you configured above.
-
To configure security event syslog logging for FTD devices, see Send Security Event Syslog Messages from FTD Devices.