<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Syslog Server in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/syslog-server/m-p/3231864#M1012835</link>
    <description>&lt;P&gt;There is another option for your situation, use the &lt;STRONG&gt;logging flash-bufferwrap&lt;/STRONG&gt; command. This will save the existing buffer before it begins to be overwritten with new logs, to the internal flash.&lt;/P&gt;
&lt;P&gt;You could then use a script to periodically scrap these .TXT files off the ASA and delete them when completed.&lt;/P&gt;
&lt;P&gt;Your next challenge would to then inject these logs into your syslog server...?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cheers,&lt;/P&gt;
&lt;P&gt;Seb.&lt;/P&gt;</description>
    <pubDate>Wed, 13 Dec 2017 20:16:12 GMT</pubDate>
    <dc:creator>Seb Rupik</dc:creator>
    <dc:date>2017-12-13T20:16:12Z</dc:date>
    <item>
      <title>Syslog Server</title>
      <link>https://community.cisco.com/t5/network-security/syslog-server/m-p/3227270#M1012831</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like to configure our ASA firewall to send all it's logs to a syslog server. Does anyone know of a good syslog server which I can use? Any help would be greatly appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Lake&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:54:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-server/m-p/3227270#M1012831</guid>
      <dc:creator>Lake</dc:creator>
      <dc:date>2020-02-21T14:54:27Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Server</title>
      <link>https://community.cisco.com/t5/network-security/syslog-server/m-p/3227670#M1012832</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;At the most simple end of the spectrum, just configure a syslog service on a BSD/ Linux box. This setup would require a little effort to search and parse the logs once collected.&lt;/P&gt;
&lt;P&gt;At the other end take a look at graylog: &lt;A href="https://www.graylog.org/" target="_blank"&gt;https://www.graylog.org/&lt;/A&gt; . This is slightly more complicated to setup, but search the logs is a breeze!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;...both are free and should provide you with what you need.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cheers,&lt;/P&gt;
&lt;P&gt;Seb.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 09:05:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-server/m-p/3227670#M1012832</guid>
      <dc:creator>Seb Rupik</dc:creator>
      <dc:date>2017-12-06T09:05:23Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Server</title>
      <link>https://community.cisco.com/t5/network-security/syslog-server/m-p/3228767#M1012833</link>
      <description>&lt;P&gt;Thank you very much.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2017 16:44:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-server/m-p/3228767#M1012833</guid>
      <dc:creator>Lake</dc:creator>
      <dc:date>2017-12-07T16:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Server</title>
      <link>https://community.cisco.com/t5/network-security/syslog-server/m-p/3231799#M1012834</link>
      <description>&lt;P&gt;Please confirm my conclusion: although a USB drive can be mounted on the&amp;nbsp;ASA 5506W-X firewall as "disk1:", there is no way to redirect syslog to this device?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If that's true, it's a real bummer since we are using the firewall in the field (outside a data center) and it means we will have to drag another box along with us. Sending syslog to a remote server isn't an option since Internet connectivity isn't continuous.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2017 18:24:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-server/m-p/3231799#M1012834</guid>
      <dc:creator>Patrick.Bryant</dc:creator>
      <dc:date>2017-12-13T18:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Server</title>
      <link>https://community.cisco.com/t5/network-security/syslog-server/m-p/3231864#M1012835</link>
      <description>&lt;P&gt;There is another option for your situation, use the &lt;STRONG&gt;logging flash-bufferwrap&lt;/STRONG&gt; command. This will save the existing buffer before it begins to be overwritten with new logs, to the internal flash.&lt;/P&gt;
&lt;P&gt;You could then use a script to periodically scrap these .TXT files off the ASA and delete them when completed.&lt;/P&gt;
&lt;P&gt;Your next challenge would to then inject these logs into your syslog server...?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cheers,&lt;/P&gt;
&lt;P&gt;Seb.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2017 20:16:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-server/m-p/3231864#M1012835</guid>
      <dc:creator>Seb Rupik</dc:creator>
      <dc:date>2017-12-13T20:16:12Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog Server</title>
      <link>https://community.cisco.com/t5/network-security/syslog-server/m-p/3300112#M1012836</link>
      <description>&lt;P&gt;Thanks Seb&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Dec 2017 14:34:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-server/m-p/3300112#M1012836</guid>
      <dc:creator>Lake</dc:creator>
      <dc:date>2017-12-21T14:34:15Z</dc:date>
    </item>
  </channel>
</rss>

