<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5510 Real Time Log Viewer Delay, Slow in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-real-time-log-viewer-delay-slow/m-p/1834443#M459257</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Disabled logging as suggested, requested outputs below:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;byasa01# sh logging queue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Logging Queue length limit : 512 msg(s)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 14307737 msg(s) discarded due to queue overflow&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 msg(s) discarded due to memory allocation failure&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Current 0 msg on queue, 512 msgs most on queue&lt;/P&gt;&lt;P&gt;byasa01# sh logging mess&lt;BR /&gt;byasa01# sh logging message&lt;BR /&gt;syslog 304002: default-level notifications (disabled)&lt;BR /&gt;syslog 304001: default-level notifications (disabled)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not tried changing the ACL log interval yet as running out of time for today, but will try it over the weekend if I get time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate prompt repsonses, thanks &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" height="16" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif" width="16"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Simon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 17 Feb 2012 17:07:57 GMT</pubDate>
    <dc:creator>simonbilton</dc:creator>
    <dc:date>2012-02-17T17:07:57Z</dc:date>
    <item>
      <title>ASA 5510 Real Time Log Viewer Delay, Slow</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-real-time-log-viewer-delay-slow/m-p/1834439#M459239</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a new ASA 5510 running 8.3(1) and ASDM 6.4(5)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to use the real time log viewer to help troubleshoot some access issues, but I am getting delays of up to 30 seconds or more between my client conecting to the ASA and the corresponding events showing in the RT Log viewer. I am using a simple filter&amp;nbsp; for source IP as it's quite a busy device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've seen an article that says to turn off certain logging IDs (such as 304001 from memory, but don't quote me!) which I have done, but no different.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions please?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Simon&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:30:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-real-time-log-viewer-delay-slow/m-p/1834439#M459239</guid>
      <dc:creator>simonbilton</dc:creator>
      <dc:date>2019-03-11T22:30:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Real Time Log Viewer Delay, Slow</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-real-time-log-viewer-delay-slow/m-p/1834440#M459244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Hi Simon,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Can you share an output of show run logging from the ASA?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;and&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;show access-list | include cache&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Varun&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Feb 2012 14:31:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-real-time-log-viewer-delay-slow/m-p/1834440#M459244</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-02-17T14:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Real Time Log Viewer Delay, Slow</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-real-time-log-viewer-delay-slow/m-p/1834441#M459250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Varun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for coming back .... here's the two outputs you asked for.&lt;/P&gt;&lt;P&gt;I've previoulsy tried disabling as much logging as possible (e.g. only to ASDM) but nothing seems to have any effect.&lt;BR /&gt;You will see the two specific syslog IDs that I disabled after reading another post somewhere, but don't think this is relevant to our situation. (I think I saw another post suggesting a further four or five similar IDs to turn off as well, but not got round to that yet.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could really do with getting this sorted as it's causing me loads of stress from the site admins, who keep reminding me that their previous Linux-based firewall "never had all these problems" - I am fighting for credibility here &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;byasa01# sh run logging&lt;BR /&gt;logging enable&lt;BR /&gt;logging console informational&lt;BR /&gt;logging buffered informational&lt;BR /&gt;logging trap informational&lt;BR /&gt;logging asdm informational&lt;BR /&gt;logging host inside 192.168.20.50&lt;BR /&gt;no logging message 304002&lt;BR /&gt;no logging message 304001&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;byasa01# show access-list | include cache&lt;BR /&gt;access-list cached ACL log flows: total 100, denied 0 (deny-flow-max 4096)&lt;BR /&gt;byasa01#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Feb 2012 16:34:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-real-time-log-viewer-delay-slow/m-p/1834441#M459250</guid>
      <dc:creator>simonbilton</dc:creator>
      <dc:date>2012-02-17T16:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Real Time Log Viewer Delay, Slow</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-real-time-log-viewer-delay-slow/m-p/1834442#M459254</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Simon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can understand what you are fighting against, but the real time log viewer is a convinient tool but not the best method i would say. The ASA also has to prioritize tasks to manage everything, the priority for it is inspecting traffic and logging is not a pririty task for it. If you're firewall is generating high amount of traffic then I would expect there might e some delay, although we can use bare minimum things to reduce this delay.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest you disable the following logging first:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging console informational&lt;/P&gt;&lt;P&gt;logging buffered informational&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and then, reduce the time interval of the acl log as well, for that lets take an example that, you are logging the following acl:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_in deny ip any any log interval 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;make the interval as 1sec, whihc means it would send the log after every 1 sec, default is 300.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and also can you provide this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show logging queue&lt;/P&gt;&lt;P&gt;show logging message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Feb 2012 16:57:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-real-time-log-viewer-delay-slow/m-p/1834442#M459254</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-02-17T16:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Real Time Log Viewer Delay, Slow</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-real-time-log-viewer-delay-slow/m-p/1834443#M459257</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Disabled logging as suggested, requested outputs below:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;byasa01# sh logging queue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Logging Queue length limit : 512 msg(s)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 14307737 msg(s) discarded due to queue overflow&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 msg(s) discarded due to memory allocation failure&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Current 0 msg on queue, 512 msgs most on queue&lt;/P&gt;&lt;P&gt;byasa01# sh logging mess&lt;BR /&gt;byasa01# sh logging message&lt;BR /&gt;syslog 304002: default-level notifications (disabled)&lt;BR /&gt;syslog 304001: default-level notifications (disabled)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not tried changing the ACL log interval yet as running out of time for today, but will try it over the weekend if I get time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate prompt repsonses, thanks &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" height="16" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif" width="16"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Simon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Feb 2012 17:07:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-real-time-log-viewer-delay-slow/m-p/1834443#M459257</guid>
      <dc:creator>simonbilton</dc:creator>
      <dc:date>2012-02-17T17:07:57Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 Real Time Log Viewer Delay, Slow</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-real-time-log-viewer-delay-slow/m-p/1834444#M459259</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can see it here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 14307737 msg(s) discarded due to queue overflow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which means its quite a busy firewall &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;let me know how it goes, i am on the forum this weekend.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Feb 2012 17:11:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-real-time-log-viewer-delay-slow/m-p/1834444#M459259</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-02-17T17:11:23Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 Real Time Log Viewer Delay, Slow</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-real-time-log-viewer-delay-slow/m-p/1834445#M459260</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks once again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While your statement about a busy firewall and the number of discarded messages makes sense in some respects, I'd appreciate a bit of an insight as to "what" is so busy.&lt;/P&gt;&lt;P&gt;This is a relatively small site - maybe 100 users - but with a proportionately high throughput to be honest - but do these numbers suggest a lot of stuff hitting the firewall and being rejected, hence blocking / delaying real traffic ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wouldn't mind a subjective opinion if you can spare some time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Simon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Feb 2012 22:35:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-real-time-log-viewer-delay-slow/m-p/1834445#M459260</guid>
      <dc:creator>simonbilton</dc:creator>
      <dc:date>2012-02-17T22:35:02Z</dc:date>
    </item>
  </channel>
</rss>

