<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic firewall notifications and alarms based on syslog keywords in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-notifications-and-alarms-based-on-syslog-keywords/m-p/1813385#M489880</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Ronni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Security Appliance will send email notifications due to any events you have configured based on a logging level or a logging list you have configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is one document I used before to know a little bit more about the email notifications feature.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://community.spiceworks.com/how_to/show/388"&gt;http://community.spiceworks.com/how_to/show/388&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other way you can send the logging messages is using a logging class.&lt;/P&gt;&lt;P&gt;For example lets say you just want to send events related to failover and webvpn.&lt;/P&gt;&lt;P&gt;logging class ha mail 7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging class webvpn mail 7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps, any other question let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do please rate helpful posts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 28 Dec 2011 19:11:25 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2011-12-28T19:11:25Z</dc:date>
    <item>
      <title>firewall notifications and alarms based on syslog keywords</title>
      <link>https://community.cisco.com/t5/network-security/firewall-notifications-and-alarms-based-on-syslog-keywords/m-p/1813384#M489878</link>
      <description>&lt;P&gt;HI, I have an ASA and we now have a requirement that we need to be notified in case of a security concern.&amp;nbsp; I have the firewall sending syslog messages to a central syslog server but I would like to know based on what syslog keywords should I be sending out email notifications.&amp;nbsp; For ex : if I get a syslog with a keyword "SYN ATTACK" (if there is such a syslog message) I will be sending out an alarm to the security team.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there another way of doing this? Another ex is if we have too many dropped packets or something of this type, then I need to be notified?&amp;nbsp; Does the asdm have such a feature?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any recommendations?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:07:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-notifications-and-alarms-based-on-syslog-keywords/m-p/1813384#M489878</guid>
      <dc:creator>network770</dc:creator>
      <dc:date>2019-03-11T22:07:28Z</dc:date>
    </item>
    <item>
      <title>firewall notifications and alarms based on syslog keywords</title>
      <link>https://community.cisco.com/t5/network-security/firewall-notifications-and-alarms-based-on-syslog-keywords/m-p/1813385#M489880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Ronni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Security Appliance will send email notifications due to any events you have configured based on a logging level or a logging list you have configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is one document I used before to know a little bit more about the email notifications feature.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://community.spiceworks.com/how_to/show/388"&gt;http://community.spiceworks.com/how_to/show/388&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other way you can send the logging messages is using a logging class.&lt;/P&gt;&lt;P&gt;For example lets say you just want to send events related to failover and webvpn.&lt;/P&gt;&lt;P&gt;logging class ha mail 7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging class webvpn mail 7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps, any other question let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do please rate helpful posts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Dec 2011 19:11:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-notifications-and-alarms-based-on-syslog-keywords/m-p/1813385#M489880</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-12-28T19:11:25Z</dc:date>
    </item>
  </channel>
</rss>

