Cisco Cisco Firepower Management Center 4000
15-6
FireSIGHT System User Guide
Chapter 15 Configuring External Alerting
Working with Alert Responses
The following table lists the standard syslog severity levels you can select.
Before you start sending syslog alerts, make sure that the syslog server can accept remote messages.
To create a syslog alert:
Access:
Admin
Step 1
Select
Policies > Actions > Alerts
.
The Alerts page appears.From the
Create Alert
drop-down menu, select
Create Syslog Alert
.
The Create Syslog Alert Configuration pop-up window appears.
Step 2
In the
Name
field, type the name you want to use to identify the saved response.
Step 3
In the
Host
field, type the hostname or IP address of your syslog server.
Note that the system does not warn you if you enter an invalid IPv4 address (such as 192.168.1.456) in
this field. Instead, the invalid address is treated as a hostname.
this field. Instead, the invalid address is treated as a hostname.
DAEMON
A message generated by a system daemon.
FTP
A message generated by the FTP daemon.
KERN
A message generated by the kernel. On many systems, these messages are
printed to the console when they appear.
printed to the console when they appear.
LOCAL0-LOCAL7
A message generated by an internal process.
LPR
A message generated by the printing subsystem.
MAIL
A message generated by a mail system.
NEWS
A message generated by the network news subsystem.
NTP
A message generated by the NTP daemon.
SYSLOG
A message generated by the syslog daemon.
USER
A message generated by a user-level process.
UUCP
A message generated by the UUCP subsystem.
Table 15-2
Available Syslog Facilities (continued)
Facility
Description
Table 15-3
Syslog Severity Levels
Level
Description
ALERT
A condition that should be corrected immediately.
CRIT
A critical condition.
DEBUG
Messages that contain debugging information.
EMERG
A panic condition broadcast to all users.
ERR
An error condition.
INFO
Informational messages.
NOTICE
Conditions that are not error conditions, but require attention.
WARNING
Warning messages.