<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-syslog-stops-every-second-hour/m-p/2951228#M149157</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please take captures on the interface going to the Syslog server during the time of the issue.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;G class="gr_ gr_118 gr-alert gr_gramm gr_run_anim Punctuation multiReplace" id="118" data-gr-id="118"&gt;Also&lt;/G&gt; share the output of show logging queue of the ASA and show run logging.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts and mark correct answers.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 18 Oct 2016 05:43:50 GMT</pubDate>
    <dc:creator>Aditya Ganjoo</dc:creator>
    <dc:date>2016-10-18T05:43:50Z</dc:date>
    <item>
      <title>ASA Syslog stops every second hour</title>
      <link>https://community.cisco.com/t5/network-security/asa-syslog-stops-every-second-hour/m-p/2951227#M149156</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have a Cisco ASA5510 running v8.4(7)30. &amp;nbsp;I have it logging syslog messages to a Linux server.&lt;/P&gt;
&lt;P&gt;I have noticed that every second hour it stops logging for one hour. &amp;nbsp;For example this morning there was a one hour gap between 04:32:09 and 05:32:11. &amp;nbsp;Then there is another gap from 06:32:04 to 07:32:28. &amp;nbsp;So I get one hour of logs, then one hour with no logs, then another hour of logs and so on.&lt;/P&gt;
&lt;P&gt;I've looked back and noticed that this has been happening since this line was added to the config:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN&gt;same-security-traffic&amp;nbsp;permit&amp;nbsp;intra-interface&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;It has just stopped again. &amp;nbsp;I logged on to ASDM and I can still see log messages coming through there, but nothing on my syslog server.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;On the console I type in show logging and it show this:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;Trap logging: level informational, facility 20, &lt;SPAN style="text-decoration: underline;"&gt;9966824&lt;/SPAN&gt; messages logged&lt;BR /&gt;    Logging to inside syslog&lt;/PRE&gt;
&lt;P&gt;I do it again and the number of messages is still incrementing.&lt;/P&gt;
&lt;P&gt;I have lots of switches and another ASA5512 logging to the same syslog server and I don't see this happening with any other device.&lt;/P&gt;
&lt;P&gt;Does anyone have any idea what's going on? &amp;nbsp;It seems that most times when I need to watch the log, the logs are not being written.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:24:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-syslog-stops-every-second-hour/m-p/2951227#M149156</guid>
      <dc:creator>davidrkirk</dc:creator>
      <dc:date>2019-03-12T08:24:39Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/asa-syslog-stops-every-second-hour/m-p/2951228#M149157</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please take captures on the interface going to the Syslog server during the time of the issue.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;G class="gr_ gr_118 gr-alert gr_gramm gr_run_anim Punctuation multiReplace" id="118" data-gr-id="118"&gt;Also&lt;/G&gt; share the output of show logging queue of the ASA and show run logging.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts and mark correct answers.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 05:43:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-syslog-stops-every-second-hour/m-p/2951228#M149157</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-10-18T05:43:50Z</dc:date>
    </item>
    <item>
      <title>Hi Aditya,</title>
      <link>https://community.cisco.com/t5/network-security/asa-syslog-stops-every-second-hour/m-p/2951229#M149158</link>
      <description>&lt;P&gt;Hi Aditya,&lt;/P&gt;
&lt;P&gt;I've done a tcpdump on the Linux server and can see the data is coming through, so the problem is not with the ASA.&lt;/P&gt;
&lt;P&gt;I've done some more investigation on the Linux side. &amp;nbsp;The syslog server logs to "/var/log/hosts/$HOST/$HOST.log". &amp;nbsp;So, it relies on being able to do a reverse dns lookup. &amp;nbsp;The ASA has two names in dns - "firewall" and "vpn". &amp;nbsp;Once I deleted the second hostname in the reverse zone it seems to be logging all messages.&lt;/P&gt;
&lt;P&gt;Thanks for your help&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2016 20:14:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-syslog-stops-every-second-hour/m-p/2951229#M149158</guid>
      <dc:creator>davidrkirk</dc:creator>
      <dc:date>2016-10-18T20:14:27Z</dc:date>
    </item>
  </channel>
</rss>

