<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA - HTTP POST LOGGING in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-http-post-logging/m-p/2154244#M387005</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunetely the log keyword used there will only tell you that a match has been done, it will no go any further by specifing the variables used&amp;nbsp; in the HTTP POST.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as I know there is no such command to accomplish that on the ASA, You could try with an AIP-SSM in conjuction with the ASA and besides genering an alert also generating a packet-capture so you could analize each of the POST TCP HTTP to your server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio Carvajal &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 05 Mar 2013 01:50:35 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2013-03-05T01:50:35Z</dc:date>
    <item>
      <title>ASA - HTTP POST LOGGING</title>
      <link>https://community.cisco.com/t5/network-security/asa-http-post-logging/m-p/2154243#M387003</link>
      <description>&lt;P&gt;Hello dear all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to log HTTP post request to webserver standing behind asa firewall, BUT I need to log variables that are inside the post request. I am able to match method post and request body that contains the request and the variables itself but the log file only shows the message about the match not the request body itself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;regex matchall "."&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map type regex match-any Logregex&lt;/P&gt;&lt;P&gt; match regex matchall&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map type inspect http match-all Loginspect&lt;/P&gt;&lt;P&gt; match request body regex class Logregex&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;policy-map type inspect http HTTP_POST_GET&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt; match request method post&lt;/P&gt;&lt;P&gt;&amp;nbsp; log&lt;/P&gt;&lt;P&gt; match request method get&lt;/P&gt;&lt;P&gt;&amp;nbsp; log&lt;/P&gt;&lt;P&gt; class Loginspect&lt;/P&gt;&lt;P&gt;&amp;nbsp; log&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This config produces fllowing syslog messages:&lt;/P&gt;&lt;P&gt;for post&lt;/P&gt;&lt;P&gt;%ASA-5-415009: HTTP - matched request method post in policy-map HTTP_POST_GET, method matched from&lt;/P&gt;&lt;P&gt;same for get and body&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any advise would be very welcome, including just a link to a material to read.&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:50:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-http-post-logging/m-p/2154243#M387003</guid>
      <dc:creator>David Tsulaia</dc:creator>
      <dc:date>2019-03-26T00:50:18Z</dc:date>
    </item>
    <item>
      <title>ASA - HTTP POST LOGGING</title>
      <link>https://community.cisco.com/t5/network-security/asa-http-post-logging/m-p/2154244#M387005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunetely the log keyword used there will only tell you that a match has been done, it will no go any further by specifing the variables used&amp;nbsp; in the HTTP POST.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as I know there is no such command to accomplish that on the ASA, You could try with an AIP-SSM in conjuction with the ASA and besides genering an alert also generating a packet-capture so you could analize each of the POST TCP HTTP to your server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio Carvajal &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Mar 2013 01:50:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-http-post-logging/m-p/2154244#M387005</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-03-05T01:50:35Z</dc:date>
    </item>
    <item>
      <title>ASA - HTTP POST LOGGING</title>
      <link>https://community.cisco.com/t5/network-security/asa-http-post-logging/m-p/2154245#M387007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Unfortunately packet capture is not the option, because it requires more resuources than available on the receiving end and the POST caputure/analysis is not one-time thing. Plus we have no AIP-SSM at our disposal =)))&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thanks for the reply.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Mar 2013 09:13:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-http-post-logging/m-p/2154245#M387007</guid>
      <dc:creator>David Tsulaia</dc:creator>
      <dc:date>2013-03-06T09:13:43Z</dc:date>
    </item>
    <item>
      <title>ASA - HTTP POST LOGGING</title>
      <link>https://community.cisco.com/t5/network-security/asa-http-post-logging/m-p/2154246#M387008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, then I do not see a way to do this &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hey man my pleasure to help,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Mar 2013 16:32:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-http-post-logging/m-p/2154246#M387008</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-03-06T16:32:21Z</dc:date>
    </item>
  </channel>
</rss>

