<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Log Entry Format in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204903#M358221</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bro&lt;/P&gt;&lt;P&gt;All I see is teardown and build messages. I don't see the logs for permit and deny acl. Please kindly resend.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 30 Apr 2013 05:46:07 GMT</pubDate>
    <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
    <dc:date>2013-04-30T05:46:07Z</dc:date>
    <item>
      <title>ASA Log Entry Format</title>
      <link>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204896#M358214</link>
      <description>&lt;P&gt;I am hoping this is a simple question for someone:&amp;nbsp; Why does the ASA report log events in differnt formats?&amp;nbsp; For example, permits and denys are not formatted the same.&amp;nbsp; It would be incredibly convinient if they formats would be the same, at least from my perspective when grepping or running the data into splunk.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A deny looks like this:&lt;/P&gt;&lt;PRE&gt;&lt;PRE&gt;Apr 15 2013 09:36:50: %ASA-4-106023: Deny tcp src dmz:X.X.X.30/63016 dst outside:X.X.X.8/53 by access-group "acl_dmz" [0xe3aab522, 0x0]&lt;/PRE&gt;
&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While a permitted ACL hit looks like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;Apr 15 09:34:34 EDT: %ASA-session-5-106100: access-list acl_in permitted tcp inside/X.X.X.16(2241) -&amp;gt; outside/X.X.X.89(2000) hit-cnt 1 first hit [0x71a87d94, 0x0]&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to get the permits and denys to match in format?&amp;nbsp; Perhaps there is a reason they don't...?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:28:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204896#M358214</guid>
      <dc:creator>schaef350</dc:creator>
      <dc:date>2019-03-12T01:28:20Z</dc:date>
    </item>
    <item>
      <title>ASA Log Entry Format</title>
      <link>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204897#M358215</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi bro&lt;/P&gt;&lt;P&gt;Please kindly re-explain your question. This is because Cisco ASA's PERMIT and DENY for a typical ACL is the same, as shown below;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apr 24 2013 16:00:28 INT-FW01 : %ASA-6-106100: access-list inside denied udp inside/172.29.2.101(1039) -&amp;gt; outside/192.203.230.10(53) hit-cnt 1 first hit [0xd820e56a, 0x0]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apr 24 2013 16:00:27 INT-FW01 : %ASA-6-106100: access-list inside permitted udp inside/172.29.2.3(1065) -&amp;gt; outside/204.61.216.57(53) hit-cnt 144 300-second interval [0xe982c7a4, 0x0]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ram&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 08:02:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204897#M358215</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2013-04-24T08:02:12Z</dc:date>
    </item>
    <item>
      <title>ASA Log Entry Format</title>
      <link>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204898#M358216</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is what I thought as well, however, the ASA I am working with is generating log messages as I indicated above.&amp;nbsp; I am wondering what I have to do to have the unit generate log messages like you indicated you your response. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Apr 2013 13:01:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204898#M358216</guid>
      <dc:creator>schaef350</dc:creator>
      <dc:date>2013-04-29T13:01:20Z</dc:date>
    </item>
    <item>
      <title>ASA Log Entry Format</title>
      <link>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204899#M358217</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bro&lt;/P&gt;&lt;P&gt;I think, I may know where your problem is but before I confirm anything, please paste the output of &lt;STRONG&gt;show run logging &lt;/STRONG&gt;and &lt;STRONG&gt;show logging &lt;/STRONG&gt;here, please.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Apr 2013 16:27:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204899#M358217</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2013-04-29T16:27:34Z</dc:date>
    </item>
    <item>
      <title>ASA Log Entry Format</title>
      <link>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204900#M358218</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;asa# show run logging&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging timestamp&lt;/P&gt;&lt;P&gt;logging console alerts&lt;/P&gt;&lt;P&gt;logging monitor errors&lt;/P&gt;&lt;P&gt;logging buffered informational&lt;/P&gt;&lt;P&gt;logging trap informational&lt;/P&gt;&lt;P&gt;logging history warnings&lt;/P&gt;&lt;P&gt;logging asdm warnings&lt;/P&gt;&lt;P&gt;logging facility 23&lt;/P&gt;&lt;P&gt;logging host inside 10.X.X.X 17/1025&lt;/P&gt;&lt;P&gt;no logging message 507003&lt;/P&gt;&lt;P&gt;no logging message 733100&lt;/P&gt;&lt;P&gt;no logging message 111008&lt;/P&gt;&lt;P&gt;no logging message 304002&lt;/P&gt;&lt;P&gt;no logging message 304001&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa# sho logging&lt;/P&gt;&lt;P&gt;Syslog logging: enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Facility: 23&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Timestamp logging: enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Standby logging: disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Debug-trace logging: disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Console logging: level alerts, 0 messages logged&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Monitor logging: level errors, 3824213 messages logged&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Buffer logging: level informational, 395145791 messages logged&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Trap logging: level informational, facility 23, 274270414 messages logged&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Logging to inside 10.X.X.X udp/1025 errors: 8&amp;nbsp; dropped: 775&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; History logging: level warnings, 4040728 messages logged&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Device ID: disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Mail logging: disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ASDM logging: level warnings, 4042233 messages logged&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Apr 2013 16:40:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204900#M358218</guid>
      <dc:creator>schaef350</dc:creator>
      <dc:date>2013-04-29T16:40:44Z</dc:date>
    </item>
    <item>
      <title>ASA Log Entry Format</title>
      <link>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204901#M358219</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bro&lt;/P&gt;&lt;P&gt;I don't see any logs that appeared under your show logging output. Since logging buffer and logging trap are the same level i.e. informational, what ever logs you see in your Syslog server, should be the same logs you see in show logging.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please paste the show logging output here, once you have it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Apr 2013 16:54:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204901#M358219</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2013-04-29T16:54:43Z</dc:date>
    </item>
    <item>
      <title>ASA Log Entry Format</title>
      <link>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204902#M358220</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;asa# sh logging&lt;/P&gt;&lt;P&gt;Syslog logging: enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Facility: 23&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Timestamp logging: enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Standby logging: disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Debug-trace logging: disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Console logging: level alerts, 0 messages logged&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Monitor logging: level errors, 3824252 messages logged&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Buffer logging: level informational, 395174037 messages logged&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Trap logging: level informational, facility 23, 274298660 messages logged&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Logging to inside 10.X.X.X udp/1025 errors: 8&amp;nbsp; dropped: 775&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; History logging: level warnings, 4040890 messages logged&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Device ID: disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Mail logging: disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ASDM logging: level warnings, 4042395 messages logged&lt;/P&gt;&lt;P&gt;08.67.222.222/53 to inside:X.X.1.35/53289 duration 0:00:00 bytes 128&lt;/P&gt;&lt;P&gt;Apr 29 2013 12:59:50: %ASA-6-305011: Built dynamic TCP translation from inside:X.X.3.42/4952 to outside:X.X.X.130/12834&lt;/P&gt;&lt;P&gt;Apr 29 2013 12:59:50: %ASA-6-302013: Built outbound TCP connection 89743274 for outside:X.X.X.43/443 (X.X.X.43/443) to inside:X.X.3.42/4952 (X.X.X.130/12834)&lt;/P&gt;&lt;P&gt;Apr 29 2013 12:59:50: %ASA-6-305011: Built dynamic UDP translation from inside:X.X.1.35/52925 to outside:X.X.X.130/25882&lt;/P&gt;&lt;P&gt;Apr 29 2013 12:59:50: %ASA-6-302015: Built outbound UDP connection 89743275 for outside:X.X.X.222/53 (X.X.X.222/53) to inside:X.X.1.35/52925 (X.X.X.130/25882)&lt;/P&gt;&lt;P&gt;Apr 29 2013 12:59:50: %ASA-6-305012: Teardown dynamic UDP translation from inside:X.X.1.24/63322 to outside:X.X.X.130/59309 duration 0:00:30&lt;/P&gt;&lt;P&gt;Apr 29 2013 12:59:50: %ASA-6-305011: Built dynamic TCP translation from inside:X.X.3.42/4953 to outside:X.X.X.130/45392&lt;/P&gt;&lt;P&gt;Apr 29 2013 12:59:50: %ASA-6-302013: Built outbound TCP connection 89743276 for outside:X.X.X.1/80 (X.X.X.1/80) to inside:X.X.3.42/4953 (X.X.X.130/45392)&lt;/P&gt;&lt;P&gt;Apr 29 2013 12:59:50: %ASA-6-302016: Teardown UDP connection 89743275 for outside:X.X.X.222/53 to inside:X.X.1.35/52925 duration 0:00:00 bytes 140&lt;/P&gt;&lt;P&gt;Apr 29 2013 12:59:50: %ASA-6-305011: Built dynamic TCP translation from inside:X.X.3.42/4954 to outside:X.X.X.130/10879&lt;/P&gt;&lt;P&gt;Apr 29 2013 12:59:50: %ASA-6-302013: Built outbound TCP connection 89743277 for outside:X.X.X.17/80 (X.X.X.17/80) to inside:X.X.3.42/4954 (X.X.X.130/10879)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Apr 2013 17:26:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204902#M358220</guid>
      <dc:creator>schaef350</dc:creator>
      <dc:date>2013-04-29T17:26:46Z</dc:date>
    </item>
    <item>
      <title>ASA Log Entry Format</title>
      <link>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204903#M358221</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bro&lt;/P&gt;&lt;P&gt;All I see is teardown and build messages. I don't see the logs for permit and deny acl. Please kindly resend.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Apr 2013 05:46:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204903#M358221</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2013-04-30T05:46:07Z</dc:date>
    </item>
    <item>
      <title>ASA Log Entry Format</title>
      <link>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204904#M358222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Apr 30 2013 09:22:33: %ASA-2-106007: Deny inbound UDP from X.X.X.66/12981 to X.X.X.60/53 due to DNS Query&lt;/P&gt;&lt;P&gt;Apr 30 2013 09:22:38: %ASA-5-106100: access-list acl_in permitted tcp inside/X.X.X.16(2006) -&amp;gt; outside/X.X.X.89(2000) hit-cnt 1 first hit [0x71a87d94, 0x0]&lt;/P&gt;&lt;P&gt;Apr 30 2013 09:22:38: %ASA-5-106100: access-list acl_in permitted tcp inside/X.X.X.46(49734) -&amp;gt; outside/X.X.X.88(40443) hit-cnt 1 first hit [0x71a87d94, 0x0]&lt;/P&gt;&lt;P&gt;Apr 30 2013 09:22:39: %ASA-5-106100: access-list acl_in permitted tcp inside/X.X.X.46(49735) -&amp;gt; outside/X.X.X.88(40443) hit-cnt 1 first hit [0x71a87d94, 0x0]&lt;/P&gt;&lt;P&gt;Apr 30 2013 09:22:39: %ASA-5-106100: access-list acl_in permitted tcp inside/X.X.X.46(49736) -&amp;gt; outside/X.X.X.88(40443) hit-cnt 1 first hit [0x71a87d94, 0x0]&lt;/P&gt;&lt;P&gt;Apr 30 2013 09:22:39: %ASA-5-106100: access-list acl_in permitted tcp inside/X.X.X.46(49737) -&amp;gt; outside/X.X.X.88(40443) hit-cnt 1 first hit [0x71a87d94, 0x0]&lt;/P&gt;&lt;P&gt;Apr 30 2013 09:22:40: %ASA-5-106100: access-list acl_in permitted tcp inside/X.X.X.46(49738) -&amp;gt; outside/X.X.X.88(40443) hit-cnt 1 first hit [0x71a87d94, 0x0]&lt;/P&gt;&lt;P&gt;Apr 30 2013 09:22:41: %ASA-5-106100: access-list acl_in permitted tcp inside/X.X.X.46(49746) -&amp;gt; outside/X.X.X.88(40443) hit-cnt 1 first hit [0x71a87d94, 0x0]&lt;/P&gt;&lt;P&gt;Apr 30 2013 09:22:47: %ASA-5-106100: access-list acl_in permitted tcp inside/X.X.X.16(2007) -&amp;gt; outside/X.X.X.89(2000) hit-cnt 1 first hit [0x71a87d94, 0x0]&lt;/P&gt;&lt;P&gt;Apr 30 2013 09:22:48: %ASA-5-106100: access-list acl_in permitted tcp inside/X.X.X.13(43013) -&amp;gt; dmz/x.x.x.31(25) hit-cnt 1 first hit [0x71a87d94, 0x0]&lt;/P&gt;&lt;P&gt;Apr 30 2013 09:22:56: %ASA-5-106100: access-list acl_in permitted tcp inside/X.X.X.16(2008) -&amp;gt; outside/X.X.X.89(2000) hit-cnt 1 first hit [0x71a87d94, 0x0]&lt;/P&gt;&lt;P&gt;Apr 30 2013 09:23:02: %ASA-2-106006: Deny inbound UDP from X.X.X.66/137 to X.X.X.42/137 on interface inside&lt;/P&gt;&lt;P&gt;Apr 30 2013 09:23:03: %ASA-2-106007: Deny inbound UDP from X.X.X.66/12981 to X.X.X.60/53 due to DNS Query&lt;/P&gt;&lt;P&gt;Apr 30 2013 09:23:06: %ASA-5-106100: access-list acl_in permitted tcp inside/X.X.X.16(2009) -&amp;gt; outside/X.X.X.89(2000) hit-cnt 1 first hit [0x71a87d94, 0x0]&lt;/P&gt;&lt;P&gt;Apr 30 2013 09:23:08: %ASA-5-106100: access-list acl_in permitted tcp inside/X.X.X.46(49776) -&amp;gt; outside/X.X.X.88(40443) hit-cnt 1 first hit [0x71a87d94, 0x0]&lt;/P&gt;&lt;P&gt;Apr 30 2013 09:23:15: %ASA-5-106100: access-list acl_in permitted tcp inside/X.X.X.16(2010) -&amp;gt; outside/X.X.X.89(2000) hit-cnt 1 first hit [0x71a87d94, 0x0]&lt;/P&gt;&lt;P&gt;Apr 30 2013 09:23:24: %ASA-5-106100: access-list acl_in permitted tcp inside/X.X.X.16(2011) -&amp;gt; outside/X.X.X.89(2000) hit-cnt 1 first hit [0x71a87d94, 0x0]&lt;/P&gt;&lt;P&gt;Apr 30 2013 09:23:33: %ASA-2-106007: Deny inbound UDP from X.X.X.66/12981 to X.X.X.60/53 due to DNS Query&lt;/P&gt;&lt;P&gt;Apr 30 2013 09:23:34: %ASA-5-106100: access-list acl_in permitted tcp inside/X.X.X.16(2012) -&amp;gt; outside/X.X.X.89(2000) hit-cnt 1 first hit [0x71a87d94, 0x0]&lt;/P&gt;&lt;P&gt;Apr 30 2013 09:23:40: %ASA-4-106023: Deny tcp src outside:X.X.X.126/53638 dst inside:X.X.X.132/8111 by access-group "acl_out" [0x71761f18, 0x0]&lt;/P&gt;&lt;P&gt;Apr 30 2013 09:23:41: %ASA-4-106023: Deny tcp src outside:X.X.X.126/53638 dst inside:X.X.X.132/8111 by access-group "acl_out" [0x71761f18, 0x0]&lt;/P&gt;&lt;P&gt;Apr 30 2013 09:23:43: %ASA-5-106100: access-list acl_in permitted tcp inside/X.X.X.46(49840) -&amp;gt; outside/X.X.X.88(40443) hit-cnt 1 first hit [0x71a87d94, 0x0]&lt;/P&gt;&lt;P&gt;Apr 30 2013 09:23:43: %ASA-5-106100: access-list acl_in permitted tcp inside/X.X.X.16(2013) -&amp;gt; outside/X.X.X.89(2000) hit-cnt 1 first hit [0x71a87d94, 0x0]&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Apr 2013 13:26:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204904#M358222</guid>
      <dc:creator>schaef350</dc:creator>
      <dc:date>2013-04-30T13:26:34Z</dc:date>
    </item>
    <item>
      <title>ASA Log Entry Format</title>
      <link>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204905#M358223</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I suspect the issue is in part that my Deny events are 106007's and the permits are106100.&amp;nbsp; In your example they are both 106100's and also in the same format.&amp;nbsp; How do our configurations differ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Apr 2013 13:29:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204905#M358223</guid>
      <dc:creator>schaef350</dc:creator>
      <dc:date>2013-04-30T13:29:16Z</dc:date>
    </item>
    <item>
      <title>ASA Log Entry Format</title>
      <link>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204906#M358224</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bro&lt;/P&gt;&lt;P&gt;The syslog message 106007 isn’t ACL denies but 106100 is. Let me try to explain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Apr 30 2013 09:22:33: %ASA-2-106007: Deny inbound UDP from X.X.X.66/12981 to X.X.X.60/53 due to DNS Query&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is an error message that the FW is telling you, that you need to fix. This simply indicates that the FW is denying the communication from X.X.X.66/12981 to X.X.X.60/53 due to other reasons e.g. asymmetric routing, DNS server was probably too slow to respond etc. This is not ACL deny.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Apr 24 2013 16:00:27 INT-FW01 : %ASA-6-106100: access-list inside permitted udp inside/172.29.2.3(1065) -&amp;gt; outside/204.61.216.57(53) hit-cnt 144 300-second interval [0xe982c7a4, 0x0]&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is ACL deny. This is not an error message. This message indicates that the FW is dropping the communication between 172.29.2.3(1065) -&amp;gt; outside/204.61.216.57(53) because you’ve specified so, in your ACL. This behavior is correct. There’s nothing you need to look into or even fix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Conclusion : 106007 tells you something is wrong and you need to fix it, and 106100, tells you all are behaving as expected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ram&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Apr 2013 19:17:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204906#M358224</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2013-04-30T19:17:42Z</dc:date>
    </item>
    <item>
      <title>ASA Log Entry Format</title>
      <link>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204907#M358225</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, I see what your saying there.&amp;nbsp; I guess I ended up getting away from the origonal question...&amp;nbsp; How about the two permit / deny events listed at the very top of this discussion?&amp;nbsp;&amp;nbsp; I am still seeing a lot of them as well.&amp;nbsp; 106100 and 106023. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Apr 2013 19:47:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204907#M358225</guid>
      <dc:creator>schaef350</dc:creator>
      <dc:date>2013-04-30T19:47:04Z</dc:date>
    </item>
    <item>
      <title>ASA Log Entry Format</title>
      <link>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204908#M358226</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can't see anything at the top of the discussion... All I see is the scroll bar but empty.. Could you repaste again, please&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Apr 2013 20:22:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204908#M358226</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2013-04-30T20:22:45Z</dc:date>
    </item>
    <item>
      <title>ASA Log Entry Format</title>
      <link>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204909#M358227</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The two major types of events I am getting are these:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apr 15 2013 09:36:50: %ASA-4-106023: Deny tcp src dmz:X.X.X.30/63016 dst outside:X.X.X.8/53 by access-group "acl_dmz" [0xe3aab522, 0x0]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apr 15 09:34:34 EDT: %ASA-session-5-106100: access-list acl_in permitted tcp inside/X.X.X.16(2241) -&amp;gt; outside/X.X.X.89(2000) hit-cnt 1 first hit [0x71a87d94, 0x0]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you indicated you are getting a 106100 event for permit and denied events.&amp;nbsp;&amp;nbsp; My system, however gives the events as shown here.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 May 2013 15:26:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204909#M358227</guid>
      <dc:creator>schaef350</dc:creator>
      <dc:date>2013-05-02T15:26:10Z</dc:date>
    </item>
    <item>
      <title>ASA Log Entry Format</title>
      <link>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204910#M358228</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello by default you are not going to log the implicit deny at the end of an ACL, to log those events you MUST manually create that ACL line&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list test deny ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you will get the logs same to the permit ones,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Remember to rate all of the helpful posts &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio Carvajal &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 May 2013 21:07:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-log-entry-format/m-p/2204910#M358228</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-05-02T21:07:13Z</dc:date>
    </item>
  </channel>
</rss>

