<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA firewall doesn't send logs to syslog server in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-firewall-doesn-t-send-logs-to-syslog-server/m-p/4792123#M1098609</link>
    <description>&lt;P&gt;are you sure server listen to UDP 514 ? ore it use different UDP port or use TCP port?&lt;BR /&gt;try&lt;/P&gt;
&lt;P class="p"&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;ping&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;[&lt;VAR&gt;if_name&lt;/VAR&gt;]&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR&gt;host&lt;/VAR&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;[&lt;SPAN class="keyword kwd"&gt;repeat&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR&gt;count&lt;/VAR&gt;] [&lt;SPAN class="keyword kwd"&gt;timeout&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR&gt;seconds&lt;/VAR&gt;] [&lt;SPAN class="keyword kwd"&gt;data&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR&gt;pattern&lt;/VAR&gt;] [&lt;SPAN class="keyword kwd"&gt;size&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR&gt;bytes&lt;/VAR&gt;] [&lt;SPAN class="keyword kwd"&gt;validate&lt;/SPAN&gt;]&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;ping to log server using management interface. check the reachability&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 12 Mar 2023 14:53:15 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2023-03-12T14:53:15Z</dc:date>
    <item>
      <title>ASA firewall doesn't send logs to syslog server</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-doesn-t-send-logs-to-syslog-server/m-p/4792111#M1098606</link>
      <description>&lt;DIV class="lia-message-template-content-zone"&gt;&lt;P&gt;Hi., I have a problem. my ASA firewall doesn't send traffic to syslog server for UDP 514. however, it seems it works on other ports because I can see the checkpoint firewall showing the flow as it is the next hope.&lt;BR /&gt;we have two syslog server. it doesn't log on one but sometimes it works on the other one.,&lt;BR /&gt;it used to work but it stopped working&lt;BR /&gt;I increased the size to 1024 and reload the device, didn't help. just the drops disappeared. can somebody help please?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;no logging hide username&lt;BR /&gt;logging buffer-size 1048576&lt;BR /&gt;logging asdm-buffer-size 512&lt;BR /&gt;logging monitor informational&lt;BR /&gt;logging buffered debugging&lt;BR /&gt;logging trap informational&lt;BR /&gt;logging history informational&lt;BR /&gt;logging asdm emergencies&lt;BR /&gt;logging queue 1024&lt;BR /&gt;logging device-id hostname&lt;BR /&gt;logging host management x.x.x.x.&lt;BR /&gt;logging host management x.x.x.x.&lt;BR /&gt;logging debug-trace&lt;BR /&gt;logging flash-minimum-free 3076&lt;BR /&gt;logging flash-maximum-allocation 51200&lt;/P&gt;&lt;P&gt;----------&lt;/P&gt;&lt;P&gt;Logging Queue length limit : 1024 msg(s)&lt;BR /&gt;0 msg(s) discarded due to queue overflow&lt;BR /&gt;0 msg(s) discarded due to memory allocation failure&lt;BR /&gt;Current 0 msg on queue, 976 msgs most on queue&lt;BR /&gt;---------------&lt;BR /&gt;capture shows the packet is being sent:&lt;BR /&gt;1: 14:51:12.826754 0050.56ab.21cd 0050.569c.0624 0x0800 Length: 345&lt;BR /&gt;ASA Firewall ip.514 &amp;gt; 1st syslog server.514: [udp sum ok] udp 303 (ttl 255, id 32544)&lt;BR /&gt;2: 14:51:12.826754 0050.56ab.21cd 0050.569c.0624 0x0800 Length: 345&lt;BR /&gt;ASA Firewall ip.514 &amp;gt; 2st syslog server.514: [udp sum ok] udp 303 (ttl 255, id 4313)&lt;/P&gt;&lt;P&gt;___________________&lt;BR /&gt;Cisco Adaptive Security Appliance Software Version 9.16(2)14&lt;BR /&gt;SSP Operating System Version 2.10(1.182)&lt;BR /&gt;Device Manager Version 7.17(1)152&lt;BR /&gt;REST API Agent Version 7.16.1.75&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sun, 12 Mar 2023 13:50:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-doesn-t-send-logs-to-syslog-server/m-p/4792111#M1098606</guid>
      <dc:creator>Mehrzad Sharifi</dc:creator>
      <dc:date>2023-03-12T13:50:24Z</dc:date>
    </item>
    <item>
      <title>Re: ASA firewall doesn't send logs to syslog server</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-doesn-t-send-logs-to-syslog-server/m-p/4792115#M1098607</link>
      <description>&lt;PRE&gt;&lt;STRONG&gt;logging host&lt;/STRONG&gt; interface_name ip_address [tcp[/port] | udp[/port]] [format emblem]&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;config UDP/TCP port and host IP and interface that ASA use to connect to host.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Mar 2023 14:50:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-doesn-t-send-logs-to-syslog-server/m-p/4792115#M1098607</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-03-12T14:50:18Z</dc:date>
    </item>
    <item>
      <title>Re: ASA firewall doesn't send logs to syslog server</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-doesn-t-send-logs-to-syslog-server/m-p/4792117#M1098608</link>
      <description>&lt;P&gt;Hi, Thanks for repling,&lt;BR /&gt;As you can see above , it is configured like this :&lt;BR /&gt;&lt;SPAN&gt;logging host management x.x.x.x.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;logging host management x.x.x.x.&lt;BR /&gt;&lt;/SPAN&gt;and I can see in ASDM that port 514 is configured for it, so I don't think this is the solution&lt;/P&gt;</description>
      <pubDate>Sun, 12 Mar 2023 14:05:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-doesn-t-send-logs-to-syslog-server/m-p/4792117#M1098608</guid>
      <dc:creator>Mehrzad Sharifi</dc:creator>
      <dc:date>2023-03-12T14:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: ASA firewall doesn't send logs to syslog server</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-doesn-t-send-logs-to-syslog-server/m-p/4792123#M1098609</link>
      <description>&lt;P&gt;are you sure server listen to UDP 514 ? ore it use different UDP port or use TCP port?&lt;BR /&gt;try&lt;/P&gt;
&lt;P class="p"&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;ping&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;[&lt;VAR&gt;if_name&lt;/VAR&gt;]&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR&gt;host&lt;/VAR&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;[&lt;SPAN class="keyword kwd"&gt;repeat&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR&gt;count&lt;/VAR&gt;] [&lt;SPAN class="keyword kwd"&gt;timeout&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR&gt;seconds&lt;/VAR&gt;] [&lt;SPAN class="keyword kwd"&gt;data&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR&gt;pattern&lt;/VAR&gt;] [&lt;SPAN class="keyword kwd"&gt;size&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR&gt;bytes&lt;/VAR&gt;] [&lt;SPAN class="keyword kwd"&gt;validate&lt;/SPAN&gt;]&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;ping to log server using management interface. check the reachability&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Mar 2023 14:53:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-doesn-t-send-logs-to-syslog-server/m-p/4792123#M1098609</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-03-12T14:53:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA firewall doesn't send logs to syslog server</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-doesn-t-send-logs-to-syslog-server/m-p/4792543#M1098624</link>
      <description>&lt;P&gt;yes, it is reachable. the interesting part is sometimes it works and sometimes it doesn't, so connectivity is totally fine,&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2023 11:00:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-doesn-t-send-logs-to-syslog-server/m-p/4792543#M1098624</guid>
      <dc:creator>Mehrzad Sharifi</dc:creator>
      <dc:date>2023-03-13T11:00:19Z</dc:date>
    </item>
  </channel>
</rss>

