Cisco Cisco Firepower Management Center 4000

Page of 1844
 
15-6
FireSIGHT System User Guide
 
Chapter 15      Configuring External Alerting 
  Working with Alert Responses
The following table lists the standard syslog severity levels you can select.
Before you start sending syslog alerts, make sure that the syslog server can accept remote messages.
To create a syslog alert:
Access: 
Admin
Step 1
Select 
Policies > Actions > Alerts
.
The Alerts page appears.From the 
Create Alert
 drop-down menu, select 
Create Syslog Alert
.
The Create Syslog Alert Configuration pop-up window appears.
Step 2
In the 
Name
 field, type the name you want to use to identify the saved response.
Step 3
In the 
Host
 field, type the hostname or IP address of your syslog server.
Note that the system does not warn you if you enter an invalid IPv4 address (such as 192.168.1.456) in 
this field. Instead, the invalid address is treated as a hostname.
DAEMON
A message generated by a system daemon.
FTP
A message generated by the FTP daemon.
KERN
A message generated by the kernel. On many systems, these messages are 
printed to the console when they appear.
LOCAL0-LOCAL7
A message generated by an internal process.
LPR
A message generated by the printing subsystem.
MAIL
A message generated by a mail system.
NEWS
A message generated by the network news subsystem.
NTP
A message generated by the NTP daemon.
SYSLOG
A message generated by the syslog daemon.
USER
A message generated by a user-level process.
UUCP
A message generated by the UUCP subsystem.
Table 15-2
Available Syslog Facilities (continued)
Facility
Description
Table 15-3
Syslog Severity Levels 
Level
Description
ALERT
A condition that should be corrected immediately.
CRIT
A critical condition.
DEBUG
Messages that contain debugging information.
EMERG 
A panic condition broadcast to all users.
ERR
An error condition.
INFO
Informational messages.
NOTICE
Conditions that are not error conditions, but require attention.
WARNING
Warning messages.