<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to log Success and Failed Login Attempt Details to Route in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-to-log-success-and-failed-login-attempt-details-to-router/m-p/1424824#M404917</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry about that James, I didn't realize I was logged into CCO. Please try this link-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/switches/lan/catalyst2960/software/release/12.2_50_se/configuration/guide/swlog.html"&gt;http://www.cisco.com/en/US/docs/switches/lan/catalyst2960/software/release/12.2_50_se/configuration/guide/swlog.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 30 Mar 2010 21:04:37 GMT</pubDate>
    <dc:creator>Collin Clark</dc:creator>
    <dc:date>2010-03-30T21:04:37Z</dc:date>
    <item>
      <title>How to log Success and Failed Login Attempt Details to Router into Syslog?</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-log-success-and-failed-login-attempt-details-to-router/m-p/1424821#M404914</link>
      <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I configure my Cisco 837 router to log to syslog all successful and failed login attempts to the router via any interface?&amp;nbsp; I'd like to get as much verbose information about the login attempts (success and failed) as possible including source ip address, userid attempted, etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any comments and suggestions would be greatly appreciated!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:02:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-log-success-and-failed-login-attempt-details-to-router/m-p/1424821#M404914</guid>
      <dc:creator>jaesposito</dc:creator>
      <dc:date>2019-03-11T00:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to log Success and Failed Login Attempt Details to Route</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-log-success-and-failed-login-attempt-details-to-router/m-p/1424822#M404915</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You will need to send logging to a syslog server with a level of informational.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's a link on configuring message logging. It's for a switch, but it should be the same for routers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/partner/docs/switches/lan/catalyst3750/software/release/12.2_50_se/configuration/guide/swlog.html"&gt;http://www.cisco.com/en/US/partner/docs/switches/lan/catalyst3750/software/release/12.2_50_se/configuration/guide/swlog.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Mar 2010 19:45:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-log-success-and-failed-login-attempt-details-to-router/m-p/1424822#M404915</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2010-03-30T19:45:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to log Success and Failed Login Attempt Details to Route</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-log-success-and-failed-login-attempt-details-to-router/m-p/1424823#M404916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm receiving an error when trying to visit that link.&amp;nbsp; Can you copy/paste the instructions into your response?&amp;nbsp; Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;James E&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Mar 2010 19:59:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-log-success-and-failed-login-attempt-details-to-router/m-p/1424823#M404916</guid>
      <dc:creator>jaesposito</dc:creator>
      <dc:date>2010-03-30T19:59:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to log Success and Failed Login Attempt Details to Route</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-log-success-and-failed-login-attempt-details-to-router/m-p/1424824#M404917</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry about that James, I didn't realize I was logged into CCO. Please try this link-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/switches/lan/catalyst2960/software/release/12.2_50_se/configuration/guide/swlog.html"&gt;http://www.cisco.com/en/US/docs/switches/lan/catalyst2960/software/release/12.2_50_se/configuration/guide/swlog.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Mar 2010 21:04:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-log-success-and-failed-login-attempt-details-to-router/m-p/1424824#M404917</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2010-03-30T21:04:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to log Success and Failed Login Attempt Details to Route</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-log-success-and-failed-login-attempt-details-to-router/m-p/1424825#M404919</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any other specific links to routers?&amp;nbsp; I'd like little to squeeze as much information out of syslog as possible for successful and failed login attempts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Mar 2010 02:53:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-log-success-and-failed-login-attempt-details-to-router/m-p/1424825#M404919</guid>
      <dc:creator>jaesposito</dc:creator>
      <dc:date>2010-03-31T02:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to log Success and Failed Login Attempt Details to Route</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-log-success-and-failed-login-attempt-details-to-router/m-p/1424826#M404922</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;archive&lt;BR /&gt; log config&lt;BR /&gt;&amp;nbsp; logging enable&lt;BR /&gt;&amp;nbsp; notify syslog contenttype plaintext&lt;BR /&gt;&amp;nbsp; hidekeys&lt;BR /&gt;logging on&lt;BR /&gt;logging 192.168.1.1&lt;BR /&gt;login block-for 60 attempts 3 within 60&lt;BR /&gt;login on-failure log every 1&lt;BR /&gt;login on-success log every 1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Mar 2010 10:55:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-log-success-and-failed-login-attempt-details-to-router/m-p/1424826#M404922</guid>
      <dc:creator>cciesec2011</dc:creator>
      <dc:date>2010-03-31T10:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to log Success and Failed Login Attempt Details to Route</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-log-success-and-failed-login-attempt-details-to-router/m-p/1424827#M404925</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also take a look at SNMP Authentication traps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RTR(config)#snmp-server trap authentication ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Mar 2010 13:27:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-log-success-and-failed-login-attempt-details-to-router/m-p/1424827#M404925</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2010-03-31T13:27:01Z</dc:date>
    </item>
    <item>
      <title>How to log Success and Failed Login Attempt Details to Router in</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-log-success-and-failed-login-attempt-details-to-router/m-p/1424828#M404928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are there any similar commands on Nexus? i want to &lt;SPAN style="font-size: 10pt;"&gt;log all attempts to establish a management connection for administrative access to nexus.Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Dec 2013 09:00:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-log-success-and-failed-login-attempt-details-to-router/m-p/1424828#M404928</guid>
      <dc:creator>zjnbxsspjm</dc:creator>
      <dc:date>2013-12-12T09:00:10Z</dc:date>
    </item>
    <item>
      <title>Is it possible to filter only</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-log-success-and-failed-login-attempt-details-to-router/m-p/1424829#M404931</link>
      <description>&lt;P&gt;Is it possible to filter only syslog information relative to the list of this events:&lt;/P&gt;
&lt;P&gt;User Authentication&lt;BR /&gt;IKE and IPSec&lt;BR /&gt;VPN Client&lt;BR /&gt;VPN Failover&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If yes what will be the best process&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2016 11:55:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-log-success-and-failed-login-attempt-details-to-router/m-p/1424829#M404931</guid>
      <dc:creator>joearmstg</dc:creator>
      <dc:date>2016-06-09T11:55:31Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to filter only</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-log-success-and-failed-login-attempt-details-to-router/m-p/4430245#M568379</link>
      <description>&lt;P&gt;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/330383" target="_blank"&gt;@joearmstg&lt;/A&gt;&amp;nbsp;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286732" target="_blank"&gt;@jaesposito&lt;/A&gt;, I had this same problem just yesterday.&amp;nbsp; Please rate the potential solution below if helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is an answer to the question using automation.&amp;nbsp; See also, my other answer to perform Regex matches manually to filter syslog messages.&lt;BR /&gt;&lt;BR /&gt;! Turn on terminal monitoring to display syslog messages to the terminal&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;term mon&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;! Turn on system archive logging.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;archive&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;log config&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;record rc&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;logging enable&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;notify syslog contenttype plaintext&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;hidekeys&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;!&amp;nbsp;Create an EEM applet to capture config changes and login/logouts to file.&lt;/P&gt;&lt;P&gt;event manager applet &amp;lt;YOUR-EEM-APPLET-NAME&amp;gt;&lt;/P&gt;&lt;P&gt;!&amp;nbsp;Match the criteria you would like in your syslog messages&lt;/P&gt;&lt;P&gt;&amp;nbsp;event syslog occurs 1 pattern "&amp;lt;YOUR-SYSLOG-MESSAGES&amp;gt;"&lt;/P&gt;&lt;P&gt;! You may want to use ("LOGIN|LOGOUT|PARSER-5-CFGLOG_LOGGEDCMD") but see the NOTE(s) below first.&lt;/P&gt;&lt;P&gt;! Open the Logger file in append mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;action 1.0 file open fh &amp;lt;YOUR-FILE-NAME&amp;gt; a&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;! Write the syslog pattern matches to your file.&lt;BR /&gt;&amp;nbsp;action 1.1 file write fh "$_syslog_msg"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;action 1.2 file close fh&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;!&amp;nbsp;Exit config mode and view the syslog messages matched to your file name.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;more &amp;lt;YOUR-FILE-NAME&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;! NOTE WARNING: &lt;/STRONG&gt;These changes have not been attempted and validated by anyone.&amp;nbsp; If you choose to test them yourself, do so at your own risk.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;! NOTE WARNING&lt;/STRONG&gt;: You should check your system for proper storage space and take precautions so that your local storage does not exceed levels as you deem appropriate for your environment.&amp;nbsp; Also, the matching criteria you used in the "event syslog occurs 1 pattern" section can inadvertently fill up your storage system if you make the criteria too broad, or if the criteria&amp;nbsp;match a condition that occurs frequently.&amp;nbsp; Do so at your own risk.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 07:08:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-log-success-and-failed-login-attempt-details-to-router/m-p/4430245#M568379</guid>
      <dc:creator>cameron rake</dc:creator>
      <dc:date>2022-03-10T07:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to filter only</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-log-success-and-failed-login-attempt-details-to-router/m-p/4430248#M568380</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe someone would still like an answer to this old question.&amp;nbsp; You can use regular expression (Regex) pattern matching.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For instance you can run the following command to include/exclude/count/begin/section any messages with a keyword in them:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;INCLUDE:&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;show log | include CRYPTO&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;show log | i OSPF&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;show int status | i notconnect&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;INCLUDE MULTIPLE:&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Combine multiple options using a pipe "|" symbol to separate them:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;show log | i CRYPTO|OSPF|BGP|LOGIN|LOGOUT&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;EXCLUDE:&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;show log | exclude ADJCHG&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;show ip int br | ex una&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;show int status | e notconnect&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;START OF LINE:&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;to show a route that begins with a pattern, begin with the caret symbol (^) which means "beginning of line":&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;show ip route | i ^O&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;show ip route | i ^O|^S&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;show ip route | i ^O|^B|^S&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;COUNT:&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;or count a matching criteria - this will count the number of static routes in your route table:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;show ip route | count ^S&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;SECTION:&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;FONT face="courier new,courier"&gt;&lt;FONT color="#0000ff"&gt;to see all the indented lines following a matched &lt;/FONT&gt;&lt;FONT color="#000000"&gt;criteria such&lt;/FONT&gt;&lt;FONT color="#0000ff"&gt;&lt;FONT color="#000000"&gt;&amp;nbsp;as bgp, route-maps, or line commands&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;show run | section route-map&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;show run | sec bgp&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;show run | sec line&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;BEGIN:&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;the begin operator works well if the section of configuration is not indented, or you're just looking to start at a general area within your config, or syslog output&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;show run | begin interface&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;show run | b banner&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;show log | b May 16&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regular expression (REGEX) is also useful for matching criteria in route-maps.&amp;nbsp; There are good articles on the internet explaining Regex special characters.&amp;nbsp; Here are a few of the basics.&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF6600"&gt;.&lt;/FONT&gt; = any character&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF6600"&gt;*&lt;/FONT&gt; = any number of times&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF6600"&gt;.*&lt;/FONT&gt; = any character any number of times (basically means anything)&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF6600"&gt;|&lt;/FONT&gt; = or&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF6600"&gt;[0-9]&lt;/FONT&gt; = any single digit matching the numbers 0 through 9.&lt;/P&gt;&lt;P&gt;for instance&amp;nbsp;&lt;FONT face="courier new,courier" color="#0000FF"&gt;show log | i Vlan[9][0-9][0-9]&amp;nbsp;&lt;/FONT&gt;matches Vlan900 through 999 in your syslog messages&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF6600"&gt;[a-z,A-Z]&lt;/FONT&gt; = any letter upper or lower case&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF6600"&gt;^&lt;/FONT&gt; = beginning of line&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF6600"&gt;$&lt;/FONT&gt; = end of line&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF6600"&gt;^$&amp;nbsp;&lt;/FONT&gt;= an empty line a.k.a. carriage return (a line that starts and ends without any other characters on that line)&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF6600"&gt;_&lt;/FONT&gt; = a space&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF6600"&gt;\&lt;/FONT&gt; = escape (removes special meaning from special characters, or applies special meaning to standard characters)&lt;/P&gt;&lt;P&gt;for instance &lt;FONT color="#FF6600"&gt;\$&amp;nbsp;&lt;/FONT&gt;means match the dollar sign instead of the end-of-line&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/ios/12_2/dial/configuration/guide/dafaapre.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/ios/12_2/dial/configuration/guide/dafaapre.html&lt;/A&gt;&amp;nbsp;Cisco Doc on Regex&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.rexegg.com/regex-quickstart.html" target="_blank"&gt;https://www.rexegg.com/regex-quickstart.html&lt;/A&gt;&amp;nbsp;Regex Cheat Sheet&lt;/P&gt;&lt;P&gt;&lt;A href="https://packetlife.net/blog/2008/may/10/extracting-bgp-info-regex/" target="_blank"&gt;https://packetlife.net/blog/2008/may/10/extracting-bgp-info-regex/&lt;/A&gt;&amp;nbsp;Packet Life BGP Regex Cheat Sheet&lt;/P&gt;&lt;P&gt;&lt;A href="https://regexlib.com/(X(1)A(jco7bdiZ7LjDv21dagltz5-s8sQA1iCLXoZxzXTTAQNWoyob1Z5y6WqEHdJiuvaoX31MU3KCyQlaK3g1AtadOuY-7-mLgGB-s_hJrHuLY6sAdjomi8RYOFWbD3Q07YwICYu5aK-kEKc5ydrj1GqVZOHZLjLB8UFmtHcDgMYdAbCQnBNQmJs36xYH9K10ixBc0))/Search.aspx?k=mac%20address&amp;amp;AspxAutoDetectCookieSupport=1" target="_blank"&gt;https://regexlib.com&lt;/A&gt;&amp;nbsp;Regex Library and Test pattern matching tools&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 16:53:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-log-success-and-failed-login-attempt-details-to-router/m-p/4430248#M568380</guid>
      <dc:creator>cameron rake</dc:creator>
      <dc:date>2021-07-09T16:53:29Z</dc:date>
    </item>
  </channel>
</rss>

