Configure Cisco FTD firewall syslog forwarding using standalone FDM version 6.4 and newer
You can configure Cisco Firepower Threat Defense (FTD)® to send the necessary logs to Arctic Wolf® for security monitoring.
Note: Changing the severity level of a log message after initial setup causes unexpected alerts. Contact your Concierge Security® Team (CST) before changing a severity level.
These resources are required:
- An activated Arctic Wolf Sensor or Virtual Log Collector (vLC)
- Access to the Cisco Firepower Management Console (FMC) interface with administrator permissions
Add a syslog server
Configure access rules using standalone FDM version 6.4 and newer
- Sign in to the FDM interface.
- In the menu bar, click Policies.
- For each rule that you want Arctic Wolf to log, complete these steps:
- For each policy that you want Arctic Wolf to log, complete these steps:
- Click Edit.
- In the Edit logging settings dialog, in the Send connection events field, enter the IP address of the Arctic Wolf Sensor.
- Click OK.
- On the toolbar, click Deployment to review the pending changes.
- Select Deploy to deploy the changes.