<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA syslog issues in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-syslog-issues/m-p/4777647#M1097924</link>
    <description>&lt;P&gt;can I see last config&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 17 Feb 2023 19:20:40 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2023-02-17T19:20:40Z</dc:date>
    <item>
      <title>ASA syslog issues</title>
      <link>https://community.cisco.com/t5/network-security/asa-syslog-issues/m-p/4777089#M1097877</link>
      <description>&lt;P&gt;Seems I'm having some issues configuring the syslog output correctly.&lt;/P&gt;&lt;P&gt;My config is as follows:&lt;BR /&gt;PPOK-EC-FW-2# sho run logging&lt;BR /&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;no logging hide username&lt;BR /&gt;logging list vpn level warnings&lt;BR /&gt;logging list vpn message 722022&lt;BR /&gt;logging list vpn message 722023&lt;BR /&gt;logging buffer-size 8092&lt;BR /&gt;logging console warnings&lt;BR /&gt;logging monitor errors&lt;BR /&gt;logging buffered vpn&lt;BR /&gt;logging trap warnings&lt;BR /&gt;logging asdm warnings&lt;BR /&gt;logging from-address EC2.ASA@ppok.com&lt;BR /&gt;logging recipient-address firewalladmin@ppok.com level alerts&lt;BR /&gt;logging facility 21&lt;BR /&gt;logging device-id ipaddress inside&lt;BR /&gt;logging host inside x.x.x.x&lt;BR /&gt;logging permit-hostdown&lt;BR /&gt;logging class auth trap informational&lt;BR /&gt;logging class vpdn trap informational&lt;BR /&gt;logging class vpn trap informational&lt;BR /&gt;logging class vpnc trap informational&lt;BR /&gt;logging class webvpn trap informational&lt;BR /&gt;logging class svc trap informational&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;i am only interested in receiving levels 0-4 and the specific 2 level 6 messages.&amp;nbsp; however, i am seeing quite a few extra level 6 messages that i need to eliminate.&amp;nbsp; when i remove the logging class commands, i stop receiving all the extra messages, as well as 722022.&amp;nbsp; then i'm stuck only getting the 722023 message and levels 0-4.&amp;nbsp; any thoughts?&amp;nbsp; i'm not sure what is going on, it's odd that i have to have those extra messages.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;Jay&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 22:51:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-syslog-issues/m-p/4777089#M1097877</guid>
      <dc:creator>James Lytle</dc:creator>
      <dc:date>2023-02-16T22:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA syslog issues</title>
      <link>https://community.cisco.com/t5/network-security/asa-syslog-issues/m-p/4777093#M1097879</link>
      <description>&lt;P&gt;what extra messages do you have as an example?&lt;/P&gt;
&lt;P&gt;check the message list with priority:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/syslog/b_syslog/messages-listed-by-severity-level.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/syslog/b_syslog/messages-listed-by-severity-level.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;logging facility 21 ( so amend the correct facility to get all the output)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Cisco FW shows it as 16-23 and the same are interpreted as 0-7 by syslog server&lt;/P&gt;
&lt;P&gt;16 = Local0 on syslog&lt;/P&gt;
&lt;P&gt;17 = Local1&amp;nbsp;on rsyslog&lt;/P&gt;
&lt;P&gt;18 = Local2&amp;nbsp;on syslog&lt;/P&gt;
&lt;P&gt;19 = Local3&amp;nbsp;on syslog&lt;/P&gt;
&lt;P&gt;20 = Local4&amp;nbsp;on syslog&lt;/P&gt;
&lt;P&gt;21 = Local5&amp;nbsp;on syslog&lt;/P&gt;
&lt;P&gt;22 = Local6&amp;nbsp;on syslog&lt;/P&gt;
&lt;P&gt;23 = Local7&amp;nbsp;on syslog&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 23:10:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-syslog-issues/m-p/4777093#M1097879</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-02-16T23:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: ASA syslog issues</title>
      <link>https://community.cisco.com/t5/network-security/asa-syslog-issues/m-p/4777128#M1097882</link>
      <description>&lt;P&gt;I'm seeing multiple level 6 messages other than 722022 and 722023.&amp;nbsp; Currently, I'm seeing 722055, 716002, 716038, 716058, 716059, 113012, 716002, 113008, 611101, 113009 and 113039.&amp;nbsp; There may be more unless I missed it.&amp;nbsp; These extra messages amount to quite a few extra messages per day, filling the syslogs with messages that are basically being ignored.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 02:12:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-syslog-issues/m-p/4777128#M1097882</guid>
      <dc:creator>James Lytle</dc:creator>
      <dc:date>2023-02-17T02:12:07Z</dc:date>
    </item>
    <item>
      <title>Re: ASA syslog issues</title>
      <link>https://community.cisco.com/t5/network-security/asa-syslog-issues/m-p/4777309#M1097886</link>
      <description>&lt;P&gt;&lt;A href="https://www.packetswitch.co.uk/cisco-asa-syslog-simplified/" target="_blank"&gt;Cisco ASA Syslog Simplified (packetswitch.co.uk)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;there are some solution check each one&amp;nbsp;&lt;BR /&gt;1-&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;no logging message 722055 716002&lt;/LI-CODE&gt;
&lt;P&gt;2-&lt;BR /&gt;&amp;nbsp;using message class&amp;nbsp;&lt;BR /&gt;3-&lt;BR /&gt;using logging list&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 09:19:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-syslog-issues/m-p/4777309#M1097886</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-02-17T09:19:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA syslog issues</title>
      <link>https://community.cisco.com/t5/network-security/asa-syslog-issues/m-p/4777393#M1097895</link>
      <description>&lt;P&gt;Okay.&amp;nbsp; I'll try option #1.&amp;nbsp; I'm already using option #2 and #3.&amp;nbsp; If I remove the message class statements, it corrects some of the issue, but then I stop getting the 722022 messages and only receive the 722023.&amp;nbsp; However, all the other messages stop coming in as well, so that's a partial solution.&amp;nbsp; I'm using the logging list command in an attempt to narrow down to only those 2 level 6 messages, and allow anything 0-4, which is where the issue all started.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 12:11:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-syslog-issues/m-p/4777393#M1097895</guid>
      <dc:creator>James Lytle</dc:creator>
      <dc:date>2023-02-17T12:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: ASA syslog issues</title>
      <link>https://community.cisco.com/t5/network-security/asa-syslog-issues/m-p/4777646#M1097923</link>
      <description>&lt;P&gt;well, option #1 did not affect the events being sent to syslog.&amp;nbsp; back to square one.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 19:14:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-syslog-issues/m-p/4777646#M1097923</guid>
      <dc:creator>James Lytle</dc:creator>
      <dc:date>2023-02-17T19:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: ASA syslog issues</title>
      <link>https://community.cisco.com/t5/network-security/asa-syslog-issues/m-p/4777647#M1097924</link>
      <description>&lt;P&gt;can I see last config&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 19:20:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-syslog-issues/m-p/4777647#M1097924</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-02-17T19:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA syslog issues</title>
      <link>https://community.cisco.com/t5/network-security/asa-syslog-issues/m-p/4777653#M1097925</link>
      <description>&lt;P&gt;&lt;SPAN&gt;ogging enable&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;logging timestamp&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;no logging hide username&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;logging list vpn level warnings&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;logging list vpn message 722022&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;logging list vpn message 722023&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;logging buffer-size 8092&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;logging console warnings&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;logging monitor errors&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;logging buffered vpn&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;logging trap warnings&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;logging asdm warnings&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;logging from-address EC2.ASA@ppok.com&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;logging recipient-address firewalladmin@ppok.com level alerts&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;logging facility 21&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;logging device-id ipaddress inside&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;logging host inside x.x.x.x&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;logging permit-hostdown&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;logging class auth trap informational&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;logging class vpdn trap informational&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;logging class vpn trap informational&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;logging class vpnc trap informational&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;logging class webvpn trap informational&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;logging class svc trap informational&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 19:35:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-syslog-issues/m-p/4777653#M1097925</guid>
      <dc:creator>James Lytle</dc:creator>
      <dc:date>2023-02-17T19:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: ASA syslog issues</title>
      <link>https://community.cisco.com/t5/network-security/asa-syslog-issues/m-p/4777840#M1097935</link>
      <description>&lt;P&gt;Hello Freind&amp;nbsp;&lt;BR /&gt;I think I found solution&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can only change the default level of message from Level 6 to Level 0-4&amp;nbsp;&lt;BR /&gt;this make get logging level from 0-4 and also get two message from level 6 (it level now will appear as level 0-4)&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="asa log.png" style="width: 992px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/176781iEEB65A31576A61AA/image-size/large?v=v2&amp;amp;px=999" role="button" title="asa log.png" alt="asa log.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 18 Feb 2023 10:23:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-syslog-issues/m-p/4777840#M1097935</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-02-18T10:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA syslog issues</title>
      <link>https://community.cisco.com/t5/network-security/asa-syslog-issues/m-p/4778456#M1097985</link>
      <description>&lt;P&gt;you can also try :&lt;/P&gt;
&lt;P&gt;logging message 722022 level 6&lt;BR /&gt;logging message 722023 level 6&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 09:54:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-syslog-issues/m-p/4778456#M1097985</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-02-20T09:54:20Z</dc:date>
    </item>
  </channel>
</rss>

