Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: LEm with Cisco Firepower / Firesight syslog

$
0
0

JS,

 

Did you modify the connector to point to the correct log facility?

In the Sourcefire connector, you should see /var/log/auth.log in the configuration if you set it up the same way as below(Image from the Cisco page you posted above)

Cisco Syslog config

 

Another thing to check is that you are receiving logs in the auth.log folder.

Open a SSH session(cmc login) or VMWare console to the LEM.

Type appliance and then checklogs.

Type the number to select the auth.log file and see if it contains anything from the sourcefire device.

If your are still running into the issue, feel free to reach out to us in support!

 

Thanks,

Chris 


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>