<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Syslog Names in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-syslog-names/m-p/2284664#M343636</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is anyone aware if it is possible to control the syslog name resolution independently of the names/no names configuration command of the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a large number of devices deployed across a network, all log to a central SYSLOG service. Generally names is enabled on the firewalls and SYSLOG output consequently includes the names. However, occasionally during troubleshooting names are turned off on the firewall &lt;STRONG style="font-family: courier new,courier; "&gt;'no names'&lt;/STRONG&gt;, unforetunately this then means that all syslog output then only has the IP addresses included. When searching through syslog output at a later date it then means that logs could appear in one of two formats i.e. with names or without.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to consistently output either names or IP's in syslog messages independently of the 'names/no names' config? Something like &lt;STRONG style="font-family: courier new,courier; "&gt;'logging names' &lt;/STRONG&gt;or &lt;STRONG style="font-family: courier new,courier; "&gt;'logging no names' &lt;/STRONG&gt;would be nice?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 02:33:11 GMT</pubDate>
    <dc:creator>Andrew Kirkby</dc:creator>
    <dc:date>2019-03-12T02:33:11Z</dc:date>
    <item>
      <title>ASA Syslog Names</title>
      <link>https://community.cisco.com/t5/network-security/asa-syslog-names/m-p/2284664#M343636</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is anyone aware if it is possible to control the syslog name resolution independently of the names/no names configuration command of the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a large number of devices deployed across a network, all log to a central SYSLOG service. Generally names is enabled on the firewalls and SYSLOG output consequently includes the names. However, occasionally during troubleshooting names are turned off on the firewall &lt;STRONG style="font-family: courier new,courier; "&gt;'no names'&lt;/STRONG&gt;, unforetunately this then means that all syslog output then only has the IP addresses included. When searching through syslog output at a later date it then means that logs could appear in one of two formats i.e. with names or without.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to consistently output either names or IP's in syslog messages independently of the 'names/no names' config? Something like &lt;STRONG style="font-family: courier new,courier; "&gt;'logging names' &lt;/STRONG&gt;or &lt;STRONG style="font-family: courier new,courier; "&gt;'logging no names' &lt;/STRONG&gt;would be nice?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:33:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-syslog-names/m-p/2284664#M343636</guid>
      <dc:creator>Andrew Kirkby</dc:creator>
      <dc:date>2019-03-12T02:33:11Z</dc:date>
    </item>
    <item>
      <title>ASA Syslog Names</title>
      <link>https://community.cisco.com/t5/network-security/asa-syslog-names/m-p/2284665#M343638</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Because of this inconsistency I try to never use the names if possible. With that I know hat the syslog always includes the IP regardless for which system I'm searching. If you are using a linux/unix syslog server the following scenario should be quite easy to implement:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Build a name-table on the syslog-server with an IP to name-mapping&lt;/P&gt;&lt;P&gt;2) build a script that changes the IP to the name based on the name-table.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With that you could take the best of both approaches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Sep 2013 12:18:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-syslog-names/m-p/2284665#M343638</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-09-02T12:18:42Z</dc:date>
    </item>
    <item>
      <title>ASA Syslog Names</title>
      <link>https://community.cisco.com/t5/network-security/asa-syslog-names/m-p/2284666#M343640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i sould like to ask how to create a separate server in which ASA will dump logs on it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i already created a separate syslog server for my ASA, but ASA will not dump logs on it. &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Sep 2013 02:51:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-syslog-names/m-p/2284666#M343640</guid>
      <dc:creator>theboywhocriedwolf</dc:creator>
      <dc:date>2013-09-10T02:51:47Z</dc:date>
    </item>
  </channel>
</rss>

