<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Logging level that will show when rules are added/changed/deleted? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/logging-level-that-will-show-when-rules-are-added-changed/m-p/2340193#M343735</link>
    <description>&lt;P&gt;What level of logging on the ASA will enable the syslog to see when a firewall rule has been changed?&amp;nbsp; I know debugging on the config level should be able to, but I don't want to put my firewall through that level of logging for everything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any help would be greatly appreciated!&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 02:32:19 GMT</pubDate>
    <dc:creator>lcnorwood</dc:creator>
    <dc:date>2019-03-12T02:32:19Z</dc:date>
    <item>
      <title>Logging level that will show when rules are added/changed/deleted?</title>
      <link>https://community.cisco.com/t5/network-security/logging-level-that-will-show-when-rules-are-added-changed/m-p/2340193#M343735</link>
      <description>&lt;P&gt;What level of logging on the ASA will enable the syslog to see when a firewall rule has been changed?&amp;nbsp; I know debugging on the config level should be able to, but I don't want to put my firewall through that level of logging for everything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any help would be greatly appreciated!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:32:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/logging-level-that-will-show-when-rules-are-added-changed/m-p/2340193#M343735</guid>
      <dc:creator>lcnorwood</dc:creator>
      <dc:date>2019-03-12T02:32:19Z</dc:date>
    </item>
    <item>
      <title>Logging level that will show when rules are added/changed/delete</title>
      <link>https://community.cisco.com/t5/network-security/logging-level-that-will-show-when-rules-are-added-changed/m-p/2340194#M343743</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would seem to me that you would be looking for Syslog messages with the following IDs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;111008 (level 5 = Notifications)&lt;/LI&gt;&lt;LI&gt;111009 (level 7 = Debugging)&lt;/LI&gt;&lt;LI&gt;111010 (level 5 = Notifications)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/syslog-guide/logmsgs.html#wp4769400"&gt;http://www.cisco.com/en/US/docs/security/asa/syslog-guide/logmsgs.html#wp4769400&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also change a level of a particular Syslog ID without changing the global level configured for certain destination&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lets say you wanted the change the above Debugging level message changed to the Notifications level you would configure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;logging message 111009 level notifications&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not completely sure would you also need to add these to specify how many of such log messages could be generated and in what timeframe. Though there is an option for &lt;STRONG&gt;"unlimited"&lt;/STRONG&gt; also. &lt;SPAN __jive_emoticon_name="plain" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;logging rate-limit &lt;NUMBER of="" log="" messages=""&gt; &lt;TIME interval=""&gt; message 111009&lt;/TIME&gt;&lt;/NUMBER&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;logging rate-limit &lt;/STRONG&gt;&lt;STRONG&gt;&lt;NUMBER of="" log="" messages=""&gt; &lt;TIME interval=""&gt;&lt;/TIME&gt;&lt;/NUMBER&gt;&lt;/STRONG&gt;&lt;STRONG&gt; message 111008&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;logging rate-limit &lt;/STRONG&gt;&lt;STRONG&gt;&lt;NUMBER of="" log="" messages=""&gt; &lt;TIME interval=""&gt; &lt;/TIME&gt;&lt;/NUMBER&gt;&lt;/STRONG&gt;&lt;STRONG&gt;message 111010&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Aug 2013 15:14:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/logging-level-that-will-show-when-rules-are-added-changed/m-p/2340194#M343743</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-08-29T15:14:04Z</dc:date>
    </item>
  </channel>
</rss>

