<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic XLATE Logs into Splunk ES in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/xlate-logs-into-splunk-es/m-p/4130355#M1072629</link>
    <description>&lt;P&gt;The quick 'n dirty:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Cisco ASAs logging informational level send to a server running syslog-ng, which is ingested into Splunk Enterprise Security.&lt;/P&gt;&lt;P&gt;- Client wants to see xlate / NAT translations in the search of the log&lt;/P&gt;&lt;P&gt;- Is the only way to really achieve this to have an API call of a show xlate / show conn so it can be logged, searchable, and retained within Splunk?&lt;/P&gt;&lt;P&gt;- As a workaround I am offering the "built connection" log from the ASA to see if that can satisfy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Tue, 04 Aug 2020 19:11:42 GMT</pubDate>
    <dc:creator>amlc</dc:creator>
    <dc:date>2020-08-04T19:11:42Z</dc:date>
    <item>
      <title>XLATE Logs into Splunk ES</title>
      <link>https://community.cisco.com/t5/network-security/xlate-logs-into-splunk-es/m-p/4130355#M1072629</link>
      <description>&lt;P&gt;The quick 'n dirty:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Cisco ASAs logging informational level send to a server running syslog-ng, which is ingested into Splunk Enterprise Security.&lt;/P&gt;&lt;P&gt;- Client wants to see xlate / NAT translations in the search of the log&lt;/P&gt;&lt;P&gt;- Is the only way to really achieve this to have an API call of a show xlate / show conn so it can be logged, searchable, and retained within Splunk?&lt;/P&gt;&lt;P&gt;- As a workaround I am offering the "built connection" log from the ASA to see if that can satisfy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 19:11:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/xlate-logs-into-splunk-es/m-p/4130355#M1072629</guid>
      <dc:creator>amlc</dc:creator>
      <dc:date>2020-08-04T19:11:42Z</dc:date>
    </item>
    <item>
      <title>Re: XLATE Logs into Splunk ES</title>
      <link>https://community.cisco.com/t5/network-security/xlate-logs-into-splunk-es/m-p/4130505#M1072638</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Look for these syslog messages. Built connection syslog doesn't indicate&lt;BR /&gt;xlate always.&lt;BR /&gt;&lt;BR /&gt;305009&lt;BR /&gt;&lt;BR /&gt;Error Message %ASA-6-305009: Built {dynamic|static} translation from&lt;BR /&gt;interface_name&lt;BR /&gt;[(acl-name)]:real_address [(idfw_user )] to interface_name :mapped_address&lt;BR /&gt;&lt;BR /&gt;Explanation An address translation slot was created. The slot translates&lt;BR /&gt;the source address from the local side to the global side. In reverse, the&lt;BR /&gt;slot translates the destination address from the global side to the local&lt;BR /&gt;side.&lt;BR /&gt;&lt;BR /&gt;Recommended Action None required.&lt;BR /&gt;305010&lt;BR /&gt;&lt;BR /&gt;Error Message %ASA-6-305010: Teardown {dynamic|static} translation from&lt;BR /&gt;interface_name :real_address [(idfw_user )] to interface_name :&lt;BR /&gt;mapped_address duration time&lt;BR /&gt;&lt;BR /&gt;Explanation The address translation slot was deleted.&lt;BR /&gt;&lt;BR /&gt;Recommended Action None required.&lt;BR /&gt;305011&lt;BR /&gt;&lt;BR /&gt;Error Message %ASA-6-305011: Built {dynamic|static} {TCP|UDP|ICMP}&lt;BR /&gt;translation from interface_name :real_address/real_port [(idfw_user )] to&lt;BR /&gt;interface_name :mapped_address/mapped_port&lt;BR /&gt;&lt;BR /&gt;Explanation A TCP, UDP, or ICMP address translation slot was created. The&lt;BR /&gt;slot translates the source socket from the local side to the global side.&lt;BR /&gt;In reverse, the slot translates the destination socket from the global side&lt;BR /&gt;to the local side.&lt;BR /&gt;&lt;BR /&gt;Recommended Action None required.&lt;BR /&gt;305012&lt;BR /&gt;&lt;BR /&gt;Error Message %ASA-6-305012: Teardown {dynamic|static} {TCP|UDP|ICMP}&lt;BR /&gt;translation from interface_name [(acl-name )]:real_address /{real_port |&lt;BR /&gt;real_ICMP_ID } [(idfw_user )] to interface_name :mapped_address /{&lt;BR /&gt;mapped_port |mapped_ICMP_ID } duration time&lt;BR /&gt;&lt;BR /&gt;Explanation The address translation slot was deleted.&lt;BR /&gt;&lt;BR /&gt;Recommended Action None required.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;***** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Wed, 05 Aug 2020 01:25:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/xlate-logs-into-splunk-es/m-p/4130505#M1072638</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2020-08-05T01:25:40Z</dc:date>
    </item>
  </channel>
</rss>

