Send Cloud-Delivered Firewall Management Center-Managed Events to SAL (SaaS) Using Syslog
This procedure provides information about the configuration for sending syslog messages for security events (connection, security intelligence, intrusion, file, and malware events) from devices managed by Security Cloud Control.
Before you begin
-
Configure policies to generate security events, and verify that the events you expect to see are displayed in the applicable tables under the Events & Logs menu.
-
Gather information relating to the syslog server IP address, port, and protocol (UDP or TCP).
-
Ensure that your devices can reach the syslog server.
Procedure
Step 1 | In the left pane, click to open the Services page. |
Step 2 | Click and select Cloud-Delivered FMC and then click Configuration. |
Step 3 | Configure the syslog settings for your threat defense device: |
Step 4 | Configure the general logging settings for the access control policy (including file and malware logging): |
Step 5 | Enable logging for security intelligence events for the access control policy: |
Step 6 | Enable syslog logging for each rule in the access control policy:
|
Step 7 | If you have made all the required changes, deploy your changes to the managed devices. |