<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA logging to syslog server shows errors and drops in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-logging-to-syslog-server-shows-errors-and-drops/m-p/4791923#M1098594</link>
    <description>&lt;P&gt;Hi., I have a problem. my ASA firewall doesn't send traffic to syslog server for UDP 514. however, it seems it works on other ports because I can see the checkpoint firewall showing the flow as it is the next hope.&lt;BR /&gt;I increased the size to 1024 and reload the device, didn't help. just the drops disappeared. can somebody help please?&lt;BR /&gt;here is the config:&lt;BR /&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;no logging hide username&lt;BR /&gt;logging buffer-size 1048576&lt;BR /&gt;logging asdm-buffer-size 512&lt;BR /&gt;logging monitor informational&lt;BR /&gt;logging buffered debugging&lt;BR /&gt;logging trap informational&lt;BR /&gt;logging history informational&lt;BR /&gt;logging asdm emergencies&lt;BR /&gt;logging queue 1024&lt;BR /&gt;logging device-id hostname&lt;BR /&gt;logging host management x.x.x.x.&lt;BR /&gt;logging host management x.x.x.x.&lt;BR /&gt;logging debug-trace&lt;BR /&gt;logging flash-minimum-free 3076&lt;BR /&gt;logging flash-maximum-allocation 51200&lt;BR /&gt;&lt;BR /&gt;----------&lt;BR /&gt;&lt;BR /&gt;Logging Queue length limit : 1024 msg(s)&lt;BR /&gt;0 msg(s) discarded due to queue overflow&lt;BR /&gt;0 msg(s) discarded due to memory allocation failure&lt;BR /&gt;Current 0 msg on queue, 976 msgs most on queue&lt;BR /&gt;---------------&lt;BR /&gt;capture shows the packet is being sent:&lt;BR /&gt;&lt;SPAN&gt;1: 14:51:12.826754 0050.56ab.21cd 0050.569c.0624 0x0800 Length: 345&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ASA Firewall ip.514 &amp;gt; 1st syslog server.514: [udp sum ok] udp 303 (ttl 255, id 32544)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2: 14:51:12.826754 0050.56ab.21cd 0050.569c.0624 0x0800 Length: 345&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ASA Firewall ip.514 &amp;gt; 2st syslog server.514: [udp sum ok] udp 303 (ttl 255, id 4313)&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;___________________&lt;BR /&gt;Cisco Adaptive Security Appliance Software Version 9.16(2)14&lt;BR /&gt;SSP Operating System Version 2.10(1.182)&lt;BR /&gt;Device Manager Version 7.17(1)152&lt;BR /&gt;REST API Agent Version 7.16.1.75&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 11 Mar 2023 13:58:35 GMT</pubDate>
    <dc:creator>Mehrzad Sharifi</dc:creator>
    <dc:date>2023-03-11T13:58:35Z</dc:date>
    <item>
      <title>ASA logging to syslog server shows errors and drops</title>
      <link>https://community.cisco.com/t5/network-security/asa-logging-to-syslog-server-shows-errors-and-drops/m-p/2675293#M193795</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On Cisco ASA i see below config&lt;/P&gt;&lt;P&gt;&lt;SPAN style="line-height: 115%; font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;&lt;FONT color="#000000"&gt;sh logging setting&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Syslog logging: enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Facility: 21&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Timestamp logging: enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Standby logging: disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Debug-trace logging: disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Console logging: level critical, 7665441 messages logged&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Monitor logging: disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Buffer logging: disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Trap logging: level informational, facility 21, 449604701 messages logged&lt;/P&gt;&lt;P&gt;Logging to server 192.168.1.50 udp/51410 errors: 13 &amp;nbsp;dropped: 137573588&lt;/P&gt;&lt;P&gt;Need to know why ASA is dropping packets to this syslog server?&lt;/P&gt;&lt;P&gt;What does error mean here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:16:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-logging-to-syslog-server-shows-errors-and-drops/m-p/2675293#M193795</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2019-03-12T06:16:17Z</dc:date>
    </item>
    <item>
      <title>Hello Mahesh,</title>
      <link>https://community.cisco.com/t5/network-security/asa-logging-to-syslog-server-shows-errors-and-drops/m-p/2675294#M193797</link>
      <description>&lt;P&gt;Hello Mahesh,&lt;/P&gt;
&lt;P&gt;Can you provide the output from the following command:&lt;/P&gt;

&lt;PRE&gt;
show logging queue&lt;/PRE&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Jose Orozco.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2015 20:14:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-logging-to-syslog-server-shows-errors-and-drops/m-p/2675294#M193797</guid>
      <dc:creator>joseoroz</dc:creator>
      <dc:date>2015-07-16T20:14:49Z</dc:date>
    </item>
    <item>
      <title> Hi Jose, Here is info h</title>
      <link>https://community.cisco.com/t5/network-security/asa-logging-to-syslog-server-shows-errors-and-drops/m-p/2675295#M193801</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Jose,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is info&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;h logging queue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Logging Queue length limit : 1024 msg(s)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 13255392 msg(s) discarded due to queue overflow&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 msg(s) discarded due to memory allocation failure&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Current 0 msg on queue, 512 msgs most on queue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yesterday i changed the Queue size to 1024&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2015 21:20:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-logging-to-syslog-server-shows-errors-and-drops/m-p/2675295#M193801</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2015-07-16T21:20:31Z</dc:date>
    </item>
    <item>
      <title>Hello Mahesh,As you can see</title>
      <link>https://community.cisco.com/t5/network-security/asa-logging-to-syslog-server-shows-errors-and-drops/m-p/2675296#M193802</link>
      <description>&lt;P&gt;Hello Mahesh,&lt;/P&gt;&lt;P&gt;As you can see there the discarded logs were caused by log overflows. The firewall will store maximum amount of logs per type per minute and drop the rest. That rate can be seen with the command:&lt;/P&gt;&lt;P&gt;sh running-config all logging | in rate-limit&lt;/P&gt;&lt;P&gt;You can modify the values. Be aware that any change that you do can affect the performance on the device.&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Jose Orozco.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2015 01:54:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-logging-to-syslog-server-shows-errors-and-drops/m-p/2675296#M193802</guid>
      <dc:creator>joseoroz</dc:creator>
      <dc:date>2015-07-17T01:54:25Z</dc:date>
    </item>
    <item>
      <title> Hi Jose, I ran the command</title>
      <link>https://community.cisco.com/t5/network-security/asa-logging-to-syslog-server-shows-errors-and-drops/m-p/2675297#M193804</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Jose,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ran the command here is output&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sh running-config all logging | in rate-limit&lt;BR /&gt;logging rate-limit 1 1 message 402116&lt;BR /&gt;logging rate-limit 1 10 message 620002&lt;BR /&gt;logging rate-limit 1 10 message 717015&lt;BR /&gt;logging rate-limit 1 10 message 717018&lt;BR /&gt;logging rate-limit 1 10 message 201013&lt;BR /&gt;logging rate-limit 1 10 message 201012&lt;BR /&gt;logging rate-limit 1 10 message 419003&lt;BR /&gt;logging rate-limit 1 10 message 405002&lt;BR /&gt;logging rate-limit 1 10 message 421007&lt;BR /&gt;logging rate-limit 1 10 message 405001&lt;BR /&gt;logging rate-limit 1 10 message 421001&lt;BR /&gt;logging rate-limit 1 10 message 421002&lt;BR /&gt;logging rate-limit 1 10 message 337004&lt;BR /&gt;logging rate-limit 1 10 message 337005&lt;BR /&gt;logging rate-limit 1 10 message 337001&lt;BR /&gt;logging rate-limit 1 10 message 337002&lt;BR /&gt;logging rate-limit 1 10 message 337003&lt;BR /&gt;logging rate-limit 2 5 message 199011&lt;BR /&gt;logging rate-limit 1 10 message 199010&lt;BR /&gt;logging rate-limit 1 10 message 337009&lt;BR /&gt;logging rate-limit 2 5 message 199012&lt;BR /&gt;logging rate-limit 1 10 message 710002&lt;BR /&gt;logging rate-limit 1 10 message 209003&lt;BR /&gt;logging rate-limit 1 10 message 209004&lt;BR /&gt;logging rate-limit 1 10 message 209005&lt;BR /&gt;logging rate-limit 1 10 message 431002&lt;BR /&gt;logging rate-limit 1 10 message 431001&lt;BR /&gt;logging rate-limit 1 1 message 447001&lt;BR /&gt;logging rate-limit 1 10 message 110003&lt;BR /&gt;logging rate-limit 1 10 message 110002&lt;BR /&gt;logging rate-limit 1 10 message 216004&lt;BR /&gt;&lt;STRONG&gt;logging rate-limit 1 10 message 450001&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please tell me what does numbers 1,10 and &lt;STRONG&gt;message 450001&lt;/STRONG&gt;&amp;nbsp;mean here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2015 20:08:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-logging-to-syslog-server-shows-errors-and-drops/m-p/2675297#M193804</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2015-07-17T20:08:54Z</dc:date>
    </item>
    <item>
      <title>Hello Mahesh,The column with</title>
      <link>https://community.cisco.com/t5/network-security/asa-logging-to-syslog-server-shows-errors-and-drops/m-p/2675298#M193805</link>
      <description>&lt;P&gt;Hello Mahesh,&lt;/P&gt;&lt;P&gt;The column with the number 1 is seconds and the 10 is the amount allowed per second. The 450001 is the syslog message.&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Jose Orozco.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2015 22:16:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-logging-to-syslog-server-shows-errors-and-drops/m-p/2675298#M193805</guid>
      <dc:creator>joseoroz</dc:creator>
      <dc:date>2015-07-17T22:16:51Z</dc:date>
    </item>
    <item>
      <title>450001Error Message ASA-4</title>
      <link>https://community.cisco.com/t5/network-security/asa-logging-to-syslog-server-shows-errors-and-drops/m-p/2675299#M193806</link>
      <description>&lt;H3 class="p_H_Head2"&gt;450001&lt;/H3&gt;&lt;P&gt;&lt;SPAN class="pEM_ErrMsg"&gt;&lt;A name="pgfId-4773903"&gt;&lt;/A&gt;Error Message &lt;A name="44408"&gt;&lt;/A&gt;ASA-4-450001: Deny traffic for protocol &lt;EM class="cEmphasis"&gt; protocol_id&lt;/EM&gt; src &lt;EM class="cEmphasis"&gt; interface_name&lt;/EM&gt; :&lt;EM class="cEmphasis"&gt; IP_address&lt;/EM&gt; /&lt;EM class="cEmphasis"&gt; port&lt;/EM&gt; dst &lt;EM class="cEmphasis"&gt; interface_name&lt;/EM&gt; :&lt;EM class="cEmphasis"&gt; IP_address&lt;/EM&gt; /&lt;EM class="cEmphasis"&gt; port&lt;/EM&gt;, licensed host limit of &lt;EM class="cEmphasis"&gt; num&lt;/EM&gt; exceeded.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="pEE_ErrExp"&gt;&lt;A name="pgfId-4773904"&gt;&lt;/A&gt;Explanation The licensed host limit was exceeded. This message applies to the ASA 5505 ASA only.&lt;/P&gt;&lt;UL&gt;&lt;LI class="pBuS_BulletStepsub"&gt;&lt;A name="pgfId-4773905"&gt;&lt;/A&gt;&lt;EM class="cEmphasis"&gt; protocol_id&lt;/EM&gt; —The protocol ID number&lt;/LI&gt;&lt;LI class="pBuS_BulletStepsub"&gt;&lt;A name="pgfId-4773906"&gt;&lt;/A&gt;&lt;EM class="cEmphasis"&gt; interface_name&lt;/EM&gt; —The interface associated with the sender or receiver of the packet&lt;/LI&gt;&lt;LI class="pBuS_BulletStepsub"&gt;&lt;A name="pgfId-4773907"&gt;&lt;/A&gt;&lt;EM class="cEmphasis"&gt; IP_address&lt;/EM&gt; —The IP address of the sender/receiver of the packet&lt;/LI&gt;&lt;LI class="pBuS_BulletStepsub"&gt;&lt;A name="pgfId-4773908"&gt;&lt;/A&gt;&lt;EM class="cEmphasis"&gt; port&lt;/EM&gt; —The port number of the packet transmitted&lt;/LI&gt;&lt;LI class="pBuS_BulletStepsub"&gt;&lt;A name="pgfId-4773909"&gt;&lt;/A&gt;&lt;EM class="cEmphasis"&gt; num&lt;/EM&gt; —The maximum host limit value&lt;/LI&gt;&lt;/UL&gt;&lt;P class="pEA_ErrAct"&gt;&lt;A name="pgfId-4773910"&gt;&lt;/A&gt;Recommended Action None required.&lt;/P&gt;&lt;P class="pEA_ErrAct"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="pEA_ErrAct"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/syslog-guide/syslogs/logmsgs1.html&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2015 22:17:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-logging-to-syslog-server-shows-errors-and-drops/m-p/2675299#M193806</guid>
      <dc:creator>joseoroz</dc:creator>
      <dc:date>2015-07-17T22:17:56Z</dc:date>
    </item>
    <item>
      <title>Re: ASA logging to syslog server shows errors and drops</title>
      <link>https://community.cisco.com/t5/network-security/asa-logging-to-syslog-server-shows-errors-and-drops/m-p/4791923#M1098594</link>
      <description>&lt;P&gt;Hi., I have a problem. my ASA firewall doesn't send traffic to syslog server for UDP 514. however, it seems it works on other ports because I can see the checkpoint firewall showing the flow as it is the next hope.&lt;BR /&gt;I increased the size to 1024 and reload the device, didn't help. just the drops disappeared. can somebody help please?&lt;BR /&gt;here is the config:&lt;BR /&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;no logging hide username&lt;BR /&gt;logging buffer-size 1048576&lt;BR /&gt;logging asdm-buffer-size 512&lt;BR /&gt;logging monitor informational&lt;BR /&gt;logging buffered debugging&lt;BR /&gt;logging trap informational&lt;BR /&gt;logging history informational&lt;BR /&gt;logging asdm emergencies&lt;BR /&gt;logging queue 1024&lt;BR /&gt;logging device-id hostname&lt;BR /&gt;logging host management x.x.x.x.&lt;BR /&gt;logging host management x.x.x.x.&lt;BR /&gt;logging debug-trace&lt;BR /&gt;logging flash-minimum-free 3076&lt;BR /&gt;logging flash-maximum-allocation 51200&lt;BR /&gt;&lt;BR /&gt;----------&lt;BR /&gt;&lt;BR /&gt;Logging Queue length limit : 1024 msg(s)&lt;BR /&gt;0 msg(s) discarded due to queue overflow&lt;BR /&gt;0 msg(s) discarded due to memory allocation failure&lt;BR /&gt;Current 0 msg on queue, 976 msgs most on queue&lt;BR /&gt;---------------&lt;BR /&gt;capture shows the packet is being sent:&lt;BR /&gt;&lt;SPAN&gt;1: 14:51:12.826754 0050.56ab.21cd 0050.569c.0624 0x0800 Length: 345&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ASA Firewall ip.514 &amp;gt; 1st syslog server.514: [udp sum ok] udp 303 (ttl 255, id 32544)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2: 14:51:12.826754 0050.56ab.21cd 0050.569c.0624 0x0800 Length: 345&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ASA Firewall ip.514 &amp;gt; 2st syslog server.514: [udp sum ok] udp 303 (ttl 255, id 4313)&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;___________________&lt;BR /&gt;Cisco Adaptive Security Appliance Software Version 9.16(2)14&lt;BR /&gt;SSP Operating System Version 2.10(1.182)&lt;BR /&gt;Device Manager Version 7.17(1)152&lt;BR /&gt;REST API Agent Version 7.16.1.75&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Mar 2023 13:58:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-logging-to-syslog-server-shows-errors-and-drops/m-p/4791923#M1098594</guid>
      <dc:creator>Mehrzad Sharifi</dc:creator>
      <dc:date>2023-03-11T13:58:35Z</dc:date>
    </item>
  </channel>
</rss>

