<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Changing syslog message 106100 severity level in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/changing-syslog-message-106100-severity-level/m-p/1897801#M458472</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm fine tuning some of our ASA logging config, and am having an issue with one particular syslog ID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The message is: &lt;/P&gt;&lt;P&gt;syslog 106100: default-level informational (enabled)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and the log settings are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syslog logging: enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Facility: 20&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Timestamp logging: enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Standby logging: disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Debug-trace logging: disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Console logging: level errors, 2389314 messages logged&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Monitor logging: disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Buffer logging: level notifications, 100889 messages logged&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Trap logging: level informational, facility 20, 1080679 messages logged&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Logging to 10.1.1.1 errors: 1&amp;nbsp; dropped: 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; History logging: level warnings, 83057 messages logged&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Device ID: disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Mail logging: disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ASDM logging: level informational, 2571771 messages logged&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This ACE log entry is generated by explicit deny any any statements at the end of all the ACLs, e.g.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended deny ip any any log interval 600&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on the config, I would expect to see this being logged to the syslog server, but not to the local buffer, but am still seeing them locally in the buffer:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Feb 22 2012 10:58:20: %ASA-4-106100: access-list inside_access_in denied udp INSIDE/HOSTABC(52629) -&amp;gt; OUTSIDE/HOSTXXX(162) hit-cnt 5 300-second interval [0x3baecf1e, 0x0]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It also still shows these as level "warning", %ASA-4-106100, instead of the default %ASA-6-106100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I've tried removing and re-applying the config at different levels but it still reports in the buffer log as level "warning", %ASA-4-106100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This also doesnt affect every 106100 log that is generated. Most messages are generated at the correct level 6 severity but some seem to randomly log at level 4. There doesn't seem to be any pattern to this. The same access-list line can produce severity level 4 and 6 106100 messages.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Karl &lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 22:38:35 GMT</pubDate>
    <dc:creator>karlchatterton</dc:creator>
    <dc:date>2019-03-11T22:38:35Z</dc:date>
    <item>
      <title>Changing syslog message 106100 severity level</title>
      <link>https://community.cisco.com/t5/network-security/changing-syslog-message-106100-severity-level/m-p/1897801#M458472</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm fine tuning some of our ASA logging config, and am having an issue with one particular syslog ID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The message is: &lt;/P&gt;&lt;P&gt;syslog 106100: default-level informational (enabled)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and the log settings are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syslog logging: enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Facility: 20&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Timestamp logging: enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Standby logging: disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Debug-trace logging: disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Console logging: level errors, 2389314 messages logged&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Monitor logging: disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Buffer logging: level notifications, 100889 messages logged&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Trap logging: level informational, facility 20, 1080679 messages logged&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Logging to 10.1.1.1 errors: 1&amp;nbsp; dropped: 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; History logging: level warnings, 83057 messages logged&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Device ID: disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Mail logging: disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ASDM logging: level informational, 2571771 messages logged&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This ACE log entry is generated by explicit deny any any statements at the end of all the ACLs, e.g.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended deny ip any any log interval 600&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on the config, I would expect to see this being logged to the syslog server, but not to the local buffer, but am still seeing them locally in the buffer:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Feb 22 2012 10:58:20: %ASA-4-106100: access-list inside_access_in denied udp INSIDE/HOSTABC(52629) -&amp;gt; OUTSIDE/HOSTXXX(162) hit-cnt 5 300-second interval [0x3baecf1e, 0x0]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It also still shows these as level "warning", %ASA-4-106100, instead of the default %ASA-6-106100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I've tried removing and re-applying the config at different levels but it still reports in the buffer log as level "warning", %ASA-4-106100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This also doesnt affect every 106100 log that is generated. Most messages are generated at the correct level 6 severity but some seem to randomly log at level 4. There doesn't seem to be any pattern to this. The same access-list line can produce severity level 4 and 6 106100 messages.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Karl &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:38:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/changing-syslog-message-106100-severity-level/m-p/1897801#M458472</guid>
      <dc:creator>karlchatterton</dc:creator>
      <dc:date>2019-03-11T22:38:35Z</dc:date>
    </item>
    <item>
      <title>Re: Changing syslog message 106100 severity level</title>
      <link>https://community.cisco.com/t5/network-security/changing-syslog-message-106100-severity-level/m-p/1897802#M458473</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Karl,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Came across your post, when looking up my own ACL specific logging wasn't working at all. Found out I was hitting a bug - CSCsz73284. Upgraded any I got many, many 106100 logs at the "error" level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure if this is still relevant for you, or if you have found your answer yet, but it could be that you've got some particular access-list entry in the config that is getting hit, where the "log warnings" is configured at the end like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list &lt;ACL-NAME&gt; extended deny &lt;PROTOCOL&gt; &lt;SOURCE&gt; &lt;DESTINATION&gt; log warnings&lt;/DESTINATION&gt;&lt;/SOURCE&gt;&lt;/PROTOCOL&gt;&lt;/ACL-NAME&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The log level for 106100 can differ depending on the log level of a particular access-list entry, and it cannot be changed globally. e.g.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA(config)# logging message 106100 level errors&lt;/P&gt;&lt;P&gt;INFO: Please use the access-list command to change the severity level of this syslog&lt;/P&gt;&lt;P&gt;ASA(config)#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Oct 2012 03:10:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/changing-syslog-message-106100-severity-level/m-p/1897802#M458473</guid>
      <dc:creator>begomez</dc:creator>
      <dc:date>2012-10-11T03:10:22Z</dc:date>
    </item>
    <item>
      <title>Changing syslog message 106100 severity level</title>
      <link>https://community.cisco.com/t5/network-security/changing-syslog-message-106100-severity-level/m-p/1897803#M458475</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Karl,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do see a small difference in those 2 different level of errors %ASA-4-106100 &amp;amp; %ASA-6-106100. In this level 4 is generated by ASA and Level 6 is triggered for Syslogging.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So which ever ACL you have pointed with log is triggered with level 6 &amp;amp; wherevr you have the plain deny rule will have the logs triggered with level 4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For %ASA-6-106100&lt;/P&gt;&lt;P&gt;================&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa70/system/message/logmsgs.html#wp1279924"&gt;http://www.cisco.com/en/US/docs/security/asa/asa70/system/message/logmsgs.html#wp1279924&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%ASA-4-106100&lt;/P&gt;&lt;P&gt;=============&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa83/system/message/logmsgs.html#wp4769049"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/system/message/logmsgs.html#wp4769049&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please do rate if the given information helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Oct 2012 07:51:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/changing-syslog-message-106100-severity-level/m-p/1897803#M458475</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2012-10-11T07:51:30Z</dc:date>
    </item>
  </channel>
</rss>

