Create a Remote Log Source - Cisco ISR

 

Topics Discussed

 

You can use this document to send Cisco Integrated Services Router (ISR) logs to Armor's Security Information & Event Management (SIEM).

This document only applies to:

  • Cisco Integrated Services Router (ISR) (IOS)


Pre-Deployment Considerations


To create a remote Log Relay, you must already have:


Update Your Cisco ISR Device


  1. Log into your Cisco ISR device.

  2. Access the privileged EXEC mode:

    hostname> enable
  3. Access the global configuration mode:

    hostname# configure terminal
  4. Enable logging:

    hostname(config)# logging on
  5. Configure the global logging settings:

  6. Configure the logs to be sent to a designated Armor Log Relay device:

  7. Exit the configuration:

  8. Save the changes:

  9. Review the logging configuration:

Troubleshooting

Verify that logs are formatted correctly, similar to the following example: