Configure Cisco FTD firewall log forwarding using Cisco FMC version 6.3 and newer
You can configure Cisco Firepower Threat Defense (FTD)® to send the necessary logs to Arctic Wolf® for security monitoring.
Note: Changing the severity level of a log message after initial setup causes unexpected alerts. Contact your Concierge Security® Team (CST) before changing a severity level.
These resources are required:
- An activated Arctic Wolf Sensor or Virtual Log Collector (vLC)
- Access to the Cisco Firepower Management Console (FMC) web UI with administrator permissions
Create a new policy
Configure syslog servers using Cisco FMC version 6.3 and newer
Update access control policy
- In the menu bar, click .
- Click
Edit next to the access control policy targeting your Cisco FTD device.
- Click
.
- Configure these settings:
- Select the Use the syslog settings configured in the FTD Platform Settings policy deployed on the device checkbox.
- In the Syslog Severity list, select INFO.
- Select the Send Syslog messages for IPS events checkbox.
- Select the Send Syslog messages for File and Malware events checkbox.
- Click Save.
- Click the Access Control tab.
- Select the Select all rules from this page checkbox.
- In the Select Bulk Action list, select Edit.
- Select the Log at end of connection checkbox and select Yes from the dropdown.
- Click Apply.
- Deploy your changes to your Cisco FTD devices.