<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA5510 ASDM show hits but no logs? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5510-asdm-show-hits-but-no-logs/m-p/2260674#M347705</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are trying to get logs from an ACL rule that permits traffic then you could go to the ACL rule on the ASDM and edit the rule and enable logging for it and change the level to Informational for example and then try again viewing the log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 20 Jun 2013 08:33:40 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-06-20T08:33:40Z</dc:date>
    <item>
      <title>ASA5510 ASDM show hits but no logs?</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-asdm-show-hits-but-no-logs/m-p/2260672#M347701</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to apply debug level logging to a rule set on my ASA 5510 (8.0(4)). I see in ASDM that the traffic hits the rule but when I open the real time log and filter on the rule ID (right-click -&amp;gt; show log; on the rule) I get nothing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the output of my show log command;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;Syslog logging: enabled&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Facility: 20&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Timestamp logging: disabled&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Standby logging: disabled&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Debug-trace logging: disabled&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Console logging: disabled&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Monitor logging: disabled&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Buffer logging: disabled&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Trap logging: level debugging, facility 20, 3219546753 messages logged&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Logging to management 10.126.6.4&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; History logging: disabled&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Device ID: disabled&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Mail logging: disabled&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ASDM logging: level informational, 2889493030 messages logged&lt;/SPAN&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I missing anything?&lt;STRONG&gt;'&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Thanks, Best Regards&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:00:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-asdm-show-hits-but-no-logs/m-p/2260672#M347701</guid>
      <dc:creator>jhonny.eriksson</dc:creator>
      <dc:date>2019-03-12T02:00:52Z</dc:date>
    </item>
    <item>
      <title>ASA5510 ASDM show hits but no logs?</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-asdm-show-hits-but-no-logs/m-p/2260673#M347703</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Atleast the output above shows that the ASDM logging level is Informational which wont show Debugging messages.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 08:27:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-asdm-show-hits-but-no-logs/m-p/2260673#M347703</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-06-20T08:27:18Z</dc:date>
    </item>
    <item>
      <title>ASA5510 ASDM show hits but no logs?</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-asdm-show-hits-but-no-logs/m-p/2260674#M347705</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are trying to get logs from an ACL rule that permits traffic then you could go to the ACL rule on the ASDM and edit the rule and enable logging for it and change the level to Informational for example and then try again viewing the log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 08:33:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-asdm-show-hits-but-no-logs/m-p/2260674#M347705</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-06-20T08:33:40Z</dc:date>
    </item>
    <item>
      <title>ASA5510 ASDM show hits but no logs?</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-asdm-show-hits-but-no-logs/m-p/2260675#M347706</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks. Get it. I tried to apply logging level informational to the rule as well as I assumed it might have something to do with it but I still got nothing. It's a pair of hosts to another pair of hosts rule set for a specific TCP port only. Could that traffic logging be regarded as Informational? Or do I need to set ASDM logging level to debugging as well as the rule in order to see the traffic?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 08:37:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-asdm-show-hits-but-no-logs/m-p/2260675#M347706</guid>
      <dc:creator>jhonny.eriksson</dc:creator>
      <dc:date>2013-06-20T08:37:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5510 ASDM show hits but no logs?</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-asdm-show-hits-but-no-logs/m-p/2260676#M347707</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To my understanding by default the ASA doesnt generate logs when an connection hits a rule that permits traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the other hand when traffic hits a deny rule or implicit deny rule then a log message will be generated by default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So to get the ASA to log messages when traffic hits a permit rule you need (to my understanding atleast) to add the keyword &lt;STRONG&gt;"log"&lt;/STRONG&gt; at the end of the rule and you can also set at which logging level that message should be viewed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you just wanted to log TCP and UDP connection forming then that should happen by default if you have enabled Informational logging level for the target of the Syslog messages. And by target I mean where the syslog have been configured to be sent, for example ASDM, Syslog server etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 08:44:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-asdm-show-hits-but-no-logs/m-p/2260676#M347707</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-06-20T08:44:17Z</dc:date>
    </item>
    <item>
      <title>ASA5510 ASDM show hits but no logs?</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-asdm-show-hits-but-no-logs/m-p/2260677#M347708</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I managed to solve it. I went into CLI and reconfigured the rule instead of doing it from ASDM. That solved it... No idea why though. As I switched around config in ASDM the CLI config changed so that should have been the same thing? Anyway, thanks for helping out &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jun 2013 09:24:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-asdm-show-hits-but-no-logs/m-p/2260677#M347708</guid>
      <dc:creator>jhonny.eriksson</dc:creator>
      <dc:date>2013-06-20T09:24:54Z</dc:date>
    </item>
  </channel>
</rss>

