1. Piyush Sharma
    July 16, 2018 @ 10:46 pm

    HI Todd,

    When enabling syslog on ACP, will the Snort Process always sends envet to FMC, then FMC sends the logs to the syslog server.

    is there is any way that snort process logs directly send to syslog server.

    How many syslog server we can configure in FMC…??

    We are having multiple sites and they are managed by central FMC, but we want logs (Lina and Snort) of every location on their location not to the FMC, can we directly send Snort logs to syslog server, as per your document we can have logs from Lina to local syslog, but is it also possible to Snort logs..??


    • lammle
      July 17, 2018 @ 6:59 am

      Yes, you can.
      You can send Syslog from ACP rules, for example, or from the Platform settings of the devices themselves, and they talk directly to the Syslog servers.
      You can configure 16 syslog servers, and each configuration can control the amount of messages and events sent to each server. You can also configure the destinations: console, email, internal buffer, etc.

      Todd Lammle


      • Piyush Sharma
        August 6, 2018 @ 4:55 am

        Thanks Todd..:)


