<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Missing connection logs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/missing-connection-logs/m-p/5308264#M1121775</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I've successfully configured an external syslog server on FDM, and it's receiving messages correctly. I've set the Default Action Block to send syslog messages, and those are arriving as expected on the external server (among other messages).&lt;/P&gt;&lt;P&gt;However, I’ve also configured an Access Control Entry (ACE) that allows internet access (from inside to outside) with logging enabled, but I’m not seeing any syslog messages related to that rule. It seems like the logs are either not being generated or not being sent.&lt;/P&gt;&lt;P&gt;For instance, I can see these logs under Events &amp;gt; Connections&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in the FDM interface, but they are not appearing on the external syslog server.&lt;/P&gt;&lt;P&gt;Could you help me understand what might be missing or misconfigured?&lt;/P&gt;&lt;P&gt;ACE that is generating connection logs (missing):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Otvforte_0-1752232898817.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/248079i749DE98B24CB8F9F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Otvforte_0-1752232898817.png" alt="Otvforte_0-1752232898817.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Syslog server settings:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Otvforte_1-1752232989665.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/248080i6747D4A4A9CB3950/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Otvforte_1-1752232989665.png" alt="Otvforte_1-1752232989665.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;</description>
    <pubDate>Fri, 11 Jul 2025 11:30:19 GMT</pubDate>
    <dc:creator>Otvforte</dc:creator>
    <dc:date>2025-07-11T11:30:19Z</dc:date>
    <item>
      <title>Missing connection logs</title>
      <link>https://community.cisco.com/t5/network-security/missing-connection-logs/m-p/5308264#M1121775</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I've successfully configured an external syslog server on FDM, and it's receiving messages correctly. I've set the Default Action Block to send syslog messages, and those are arriving as expected on the external server (among other messages).&lt;/P&gt;&lt;P&gt;However, I’ve also configured an Access Control Entry (ACE) that allows internet access (from inside to outside) with logging enabled, but I’m not seeing any syslog messages related to that rule. It seems like the logs are either not being generated or not being sent.&lt;/P&gt;&lt;P&gt;For instance, I can see these logs under Events &amp;gt; Connections&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in the FDM interface, but they are not appearing on the external syslog server.&lt;/P&gt;&lt;P&gt;Could you help me understand what might be missing or misconfigured?&lt;/P&gt;&lt;P&gt;ACE that is generating connection logs (missing):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Otvforte_0-1752232898817.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/248079i749DE98B24CB8F9F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Otvforte_0-1752232898817.png" alt="Otvforte_0-1752232898817.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Syslog server settings:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Otvforte_1-1752232989665.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/248080i6747D4A4A9CB3950/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Otvforte_1-1752232989665.png" alt="Otvforte_1-1752232989665.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jul 2025 11:30:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/missing-connection-logs/m-p/5308264#M1121775</guid>
      <dc:creator>Otvforte</dc:creator>
      <dc:date>2025-07-11T11:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: Missing connection logs</title>
      <link>https://community.cisco.com/t5/network-security/missing-connection-logs/m-p/5308267#M1121776</link>
      <description>&lt;P&gt;&amp;gt; show running logging&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Share this&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jul 2025 11:35:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/missing-connection-logs/m-p/5308267#M1121776</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-11T11:35:08Z</dc:date>
    </item>
    <item>
      <title>Re: Missing connection logs</title>
      <link>https://community.cisco.com/t5/network-security/missing-connection-logs/m-p/5308281#M1121777</link>
      <description>&lt;P&gt;Here you are,&lt;/P&gt;&lt;P&gt;show running-config logging&lt;BR /&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging console informational&lt;BR /&gt;logging buffered informational&lt;BR /&gt;logging trap informational&lt;BR /&gt;logging host inside 192.168.0.2&lt;BR /&gt;logging permit-hostdown&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jul 2025 11:56:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/missing-connection-logs/m-p/5308281#M1121777</guid>
      <dc:creator>Otvforte</dc:creator>
      <dc:date>2025-07-11T11:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: Missing connection logs</title>
      <link>https://community.cisco.com/t5/network-security/missing-connection-logs/m-p/5308283#M1121778</link>
      <description>&lt;P&gt;It OK' is server connect to inside interface?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jul 2025 12:01:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/missing-connection-logs/m-p/5308283#M1121778</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-11T12:01:20Z</dc:date>
    </item>
    <item>
      <title>Re: Missing connection logs</title>
      <link>https://community.cisco.com/t5/network-security/missing-connection-logs/m-p/5308286#M1121779</link>
      <description>&lt;P&gt;Yes, and its also already receiving some logs from FDM, but missing connections logs.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jul 2025 12:07:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/missing-connection-logs/m-p/5308286#M1121779</guid>
      <dc:creator>Otvforte</dc:creator>
      <dc:date>2025-07-11T12:07:10Z</dc:date>
    </item>
    <item>
      <title>Re: Missing connection logs</title>
      <link>https://community.cisco.com/t5/network-security/missing-connection-logs/m-p/5308287#M1121780</link>
      <description>&lt;P&gt;What is action you use trust ? (I can not see it clearly)&lt;/P&gt;
&lt;P&gt;If yes then change it to allow&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Trust normally not generate log&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jul 2025 12:12:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/missing-connection-logs/m-p/5308287#M1121780</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-11T12:12:50Z</dc:date>
    </item>
    <item>
      <title>Re: Missing connection logs</title>
      <link>https://community.cisco.com/t5/network-security/missing-connection-logs/m-p/5308361#M1121783</link>
      <description>&lt;P&gt;Tried with action 'Allow', same results. Most of the syslogs are like this bellow and don't show the URL, which is what i'm looking for&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Otvforte_0-1752246792669.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/248088i2D780DC6B4206D40/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Otvforte_0-1752246792669.png" alt="Otvforte_0-1752246792669.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Again, on Events / Connection, logs are fine&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Otvforte_1-1752246900199.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/248089i3FDF70F67559D27D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Otvforte_1-1752246900199.png" alt="Otvforte_1-1752246900199.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jul 2025 15:15:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/missing-connection-logs/m-p/5308361#M1121783</guid>
      <dc:creator>Otvforte</dc:creator>
      <dc:date>2025-07-11T15:15:22Z</dc:date>
    </item>
    <item>
      <title>Re: Missing connection logs</title>
      <link>https://community.cisco.com/t5/network-security/missing-connection-logs/m-p/5308430#M1121787</link>
      <description>&lt;P&gt;&amp;gt; show conn&amp;nbsp;&lt;BR /&gt;then&amp;nbsp;&lt;BR /&gt;&amp;gt;clear conn &amp;lt;IP&amp;gt;&lt;BR /&gt;&lt;BR /&gt;note:- use Allow not trust as action&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jul 2025 19:48:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/missing-connection-logs/m-p/5308430#M1121787</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-11T19:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: Missing connection logs</title>
      <link>https://community.cisco.com/t5/network-security/missing-connection-logs/m-p/5308432#M1121788</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I couldn't understand how this command can be related with the logs issue.&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jul 2025 20:00:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/missing-connection-logs/m-p/5308432#M1121788</guid>
      <dc:creator>Otvforte</dc:creator>
      <dc:date>2025-07-11T20:00:55Z</dc:date>
    </item>
    <item>
      <title>Re: Missing connection logs</title>
      <link>https://community.cisco.com/t5/network-security/missing-connection-logs/m-p/5308434#M1121789</link>
      <description>&lt;P&gt;if the FTD have Conn then it not pass traffic via ACP and hence you can not get Log&amp;nbsp;&lt;BR /&gt;clear Conn so the connection start hit ACP&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jul 2025 20:03:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/missing-connection-logs/m-p/5308434#M1121789</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-11T20:03:55Z</dc:date>
    </item>
    <item>
      <title>Re: Missing connection logs</title>
      <link>https://community.cisco.com/t5/network-security/missing-connection-logs/m-p/5308576#M1121795</link>
      <description>&lt;P&gt;Any update?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sat, 12 Jul 2025 14:52:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/missing-connection-logs/m-p/5308576#M1121795</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-12T14:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: Missing connection logs</title>
      <link>https://community.cisco.com/t5/network-security/missing-connection-logs/m-p/5309033#M1121808</link>
      <description>&lt;P&gt;Hi, no changes yet, still missing success connection logs on syslog (not on Events). It's a lab so I'll reset the FTD and try again, let you know if I find out the answer. Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jul 2025 11:37:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/missing-connection-logs/m-p/5309033#M1121808</guid>
      <dc:creator>Otvforte</dc:creator>
      <dc:date>2025-07-14T11:37:20Z</dc:date>
    </item>
    <item>
      <title>Re: Missing connection logs</title>
      <link>https://community.cisco.com/t5/network-security/missing-connection-logs/m-p/5314504#M1121995</link>
      <description>&lt;P&gt;I also participate in other post&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Same issue&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I suggest to him use packet tracer&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Abd after that engineer get log.&lt;/P&gt;
&lt;P&gt;Try same way&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sun, 27 Jul 2025 13:07:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/missing-connection-logs/m-p/5314504#M1121995</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-27T13:07:26Z</dc:date>
    </item>
  </channel>
</rss>

