Lumu Log Forwarder Cisco Firepower Configuration
Requirements
- Admin access to configure a Syslog server on Cisco Firepower firewall.
- The most recent version of the Lumu Virtual Appliance installed.
Once you have installed and configured a Lumu Virtual Appliance with the respective firewall collector, the next step is to set up Cisco Firepower to forward firewall metadata to Lumu. Following, you will find the overall steps to configure the forwarding of the required events. The detailed guide can be found in Cisco’s official documentation:
Events of interest
Cisco Firepower classifies its events using a specific ID and a severity level. In the next table, you can find the events of interest for Lumu:
Event ID | Severity level |
106100 | 6 (informational) |
302013 | 6 (informational) |
302014 | 6 (informational) |
302015 | 6 (informational) |
302016 | 6 (informational) |
430002 | 5 (notification) |
430003 | 1 (alert) |
Add event list filter
It’s recommended to create a custom event list filter to avoid sharing non-required events with your Lumu Log Forwarder. This allows you to optimize resources on your Firewall and also bandwidth. To create an event list filter follow these steps:
On your Firepower console (FTD), go to Objects > Event List Filters
.
- Click on the Create Event List Filter button. On the Add Event List Filter window, fill in the required information
- Fill in the Name and Description fields with an easily identifiable name.
- Add three Syslog ranges: 106100, 302013-302016, and 430002-430003.
3. Click the OK button.
Add Lumu Log Forwarder as a Syslog server
You need to add your Lumu Log Forwarder as a Syslog server object inside Cisco Firepower Firewall. Follow these steps to add a new Syslog server object:
On your Firepower console (FTD), go to Objects > Event List
Filters.
Click on the + (plus) icon on the Syslog Servers screen. Fill in the required data according to how you configured the Log Forwarder collector in the previous steps. According to your network topology, select the data interface you want to use to send Syslog messages to your Log Forwarder. Click the OK
button.
Go to the System Settings > Logging Settings menu. This menu is under the Device
screen.
- Under the Logging Settings window, toggle Data logging under the Remote Servers section. Add the Syslog Server you have created and select the Custom Logging Filter object. Click on the Save button.
Remember to deploy your changes.
Get an AI Summary
Related Articles
Deploy Collectors with Log Forwarder for Windows
Log Forwarder is designed to streamline the data collection processes from third party data collection services. While not as optimized as a fully-fledged Virtual Appliance deployment, it is a great alternative for fast and accessible deployment. ...
Deploy Collectors with Log Forwarder for Linux
The Lumu Log Forwarder Agent is available for Linux-based operating systems. In this article, you will find the installation procedures, both automatic and manual, for all the supported distributions. Log Forwarder is designed to streamline the data ...
Lumu Log Forwarder FortiGate Configuration
In scenarios where all your FortiGate deployment logs are centralized within a FortiAnalyzer, you can use it to accelerate the deployment of Lumu and forward all firewall logs at once using the FortiAnalyzer data collection capabilities from Lumu. ...
Lumu Log Forwarder MikroTik Configuration
Requirements MikroTik Router OS 6 or newer. A configured Log Forwarder Agent. Log Forwarder Agent for Linux Log Forwarder Agent for Windows Configure MikroTik to Send Metadata to Lumu Log Forwarder You will need to configure MikroTik in order to ...
Collect Firewall Metadata with Lumu VA and Cisco Firepower
Collect Firewall Metadata with Lumu VA and Cisco Firepower The Lumu Virtual Appliance (VA) offers the option to create Collectors, a seamless way to integrate the network metadata of your entire enterprise into the Lumu cloud with the lowest impact ...