<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Suppressing Specific authpriv Log Messages on NXOS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/suppressing-specific-authpriv-log-messages-on-nxos/m-p/5303508#M596990</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm looking for a way to suppress specific log messages similar to the following:&lt;/P&gt;&lt;P&gt;"AUTHPRIV-6-SYSTEM_MSG: pam_unix(crond:session): session opened for user root"&lt;/P&gt;&lt;P&gt;"AUTHPRIV-6-SYSTEM_MSG: pam_unix(crond:session): session closed for user root"&lt;/P&gt;&lt;P&gt;I understand that reducing the authpriv logging level from 6 to 5 might prevent these messages, but due to STIG compliance requirements, I need to keep the logging level at 6. Is there a recommended method to suppress or filter these specific log entries while maintaining the current logging level?&lt;/P&gt;&lt;P&gt;Thanks in advance for any guidance.&lt;/P&gt;</description>
    <pubDate>Fri, 27 Jun 2025 19:10:24 GMT</pubDate>
    <dc:creator>Paul M Dycus</dc:creator>
    <dc:date>2025-06-27T19:10:24Z</dc:date>
    <item>
      <title>Suppressing Specific authpriv Log Messages on NXOS</title>
      <link>https://community.cisco.com/t5/network-access-control/suppressing-specific-authpriv-log-messages-on-nxos/m-p/5303508#M596990</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm looking for a way to suppress specific log messages similar to the following:&lt;/P&gt;&lt;P&gt;"AUTHPRIV-6-SYSTEM_MSG: pam_unix(crond:session): session opened for user root"&lt;/P&gt;&lt;P&gt;"AUTHPRIV-6-SYSTEM_MSG: pam_unix(crond:session): session closed for user root"&lt;/P&gt;&lt;P&gt;I understand that reducing the authpriv logging level from 6 to 5 might prevent these messages, but due to STIG compliance requirements, I need to keep the logging level at 6. Is there a recommended method to suppress or filter these specific log entries while maintaining the current logging level?&lt;/P&gt;&lt;P&gt;Thanks in advance for any guidance.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jun 2025 19:10:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/suppressing-specific-authpriv-log-messages-on-nxos/m-p/5303508#M596990</guid>
      <dc:creator>Paul M Dycus</dc:creator>
      <dc:date>2025-06-27T19:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: Suppressing Specific authpriv Log Messages on NXOS</title>
      <link>https://community.cisco.com/t5/network-access-control/suppressing-specific-authpriv-log-messages-on-nxos/m-p/5303515#M596991</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1892028"&gt;@Paul M Dycus&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;NX-OS does not support logging discriminators which are commonly used on IOS and IOS-XE for this purpose.&lt;/P&gt;
&lt;P&gt;So you are limited to filtering by severity and facility which is not an option for you due to STIG compliance.&lt;/P&gt;
&lt;P&gt;Therefore, you could only use external syslog processing tools for more granular filtering.&lt;/P&gt;
&lt;P&gt;HTH!&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jun 2025 19:30:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/suppressing-specific-authpriv-log-messages-on-nxos/m-p/5303515#M596991</guid>
      <dc:creator>Jens Albrecht</dc:creator>
      <dc:date>2025-06-27T19:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: Suppressing Specific authpriv Log Messages on NXOS</title>
      <link>https://community.cisco.com/t5/network-access-control/suppressing-specific-authpriv-log-messages-on-nxos/m-p/5303520#M596992</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1892028"&gt;@Paul M Dycus&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you're using a SIEM or syslog analyzer, it's a good practice to ignore low value messages like this session logs in alerting rules rather than fully supressing them...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jun 2025 19:57:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/suppressing-specific-authpriv-log-messages-on-nxos/m-p/5303520#M596992</guid>
      <dc:creator>M02@rt37</dc:creator>
      <dc:date>2025-06-27T19:57:23Z</dc:date>
    </item>
  </channel>
</rss>

