<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Logging Configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-logging-configuration/m-p/1700574#M536513</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jeff,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;question 1: Syslogs are useful to find out why a connection did not get built, why the device rebooted, was there any attack, etc. For troubleshooting an issue, syslogs are very important. So, disable the messages according to your own discretion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;question 2: You can disable some very general syslogs messages like built and teardown connection messages. The command is "no logging message &lt;MSG number=""&gt;".&lt;/MSG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;question 3:&amp;nbsp; Enabling or disabling syslogs is completely your call. You can disable the syslog messages you don't need.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this is clear. Here is a document that might help:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/web/about/security/intelligence/identify-incidents-via-syslog.html#9"&gt;http://www.cisco.com/web/about/security/intelligence/identify-incidents-via-syslog.html#9&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anu&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S. Please mark this question as answered if it has been resolved. Do rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Jul 2011 13:21:14 GMT</pubDate>
    <dc:creator>Anu M Chacko</dc:creator>
    <dc:date>2011-07-06T13:21:14Z</dc:date>
    <item>
      <title>ASA Logging Configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-logging-configuration/m-p/1700573#M536512</link>
      <description>&lt;P&gt;Hi Group,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I currently have an ASA configured in production within my network that is set a bit high (200K msg per/hr) in respect to logging.&amp;nbsp; My issue with this is that it pretty much has rendered our syslog server useless...too many messages...sorting through the 500MB log file = double fail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was wondering if anyone from the group could share their insights on some of the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- What should a firewall generate a syslog message for?&lt;/P&gt;&lt;P&gt;- Best practices for ASA syslog configuration&lt;/P&gt;&lt;P&gt;- Templates anyone uses for ASA syslog configuration&lt;/P&gt;&lt;P&gt;- Thoughts and insights &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:55:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-logging-configuration/m-p/1700573#M536512</guid>
      <dc:creator>jc84_</dc:creator>
      <dc:date>2019-03-11T20:55:18Z</dc:date>
    </item>
    <item>
      <title>ASA Logging Configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-logging-configuration/m-p/1700574#M536513</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jeff,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;question 1: Syslogs are useful to find out why a connection did not get built, why the device rebooted, was there any attack, etc. For troubleshooting an issue, syslogs are very important. So, disable the messages according to your own discretion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;question 2: You can disable some very general syslogs messages like built and teardown connection messages. The command is "no logging message &lt;MSG number=""&gt;".&lt;/MSG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;question 3:&amp;nbsp; Enabling or disabling syslogs is completely your call. You can disable the syslog messages you don't need.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this is clear. Here is a document that might help:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/web/about/security/intelligence/identify-incidents-via-syslog.html#9"&gt;http://www.cisco.com/web/about/security/intelligence/identify-incidents-via-syslog.html#9&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anu&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S. Please mark this question as answered if it has been resolved. Do rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jul 2011 13:21:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-logging-configuration/m-p/1700574#M536513</guid>
      <dc:creator>Anu M Chacko</dc:creator>
      <dc:date>2011-07-06T13:21:14Z</dc:date>
    </item>
  </channel>
</rss>

