<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't see login or config messages in PIX syslog in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-t-see-login-or-config-messages-in-pix-syslog/m-p/153201#M607171</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check the following URL to get the meaning of all syslog messages.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_62/syslog/pixemsgs.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_62/syslog/pixemsgs.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some sample messages with meanings&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%PIX-5-111001: Begin configuration: IP_addr writing to device &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Explanation   This message is logged when you enter the write command to store your configuration on a device (either floppy, Flash memory, TFTP, the failover standby unit, or the console terminal). The IP_addr indicates whether the login was made at the console port or via a Telnet connection. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Action None required. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%PIX-5-111003: IP_addr Erase configuration &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Explanation   This is a PIX Firewall management message. This message is logged when you erase the contents of Flash memory by entering the write erase command at the console. The IP_addr indicates whether the login was made at the console port or via a Telnet connection&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 16 Apr 2003 14:27:29 GMT</pubDate>
    <dc:creator>hadbou</dc:creator>
    <dc:date>2003-04-16T14:27:29Z</dc:date>
    <item>
      <title>Can't see login or config messages in PIX syslog</title>
      <link>https://community.cisco.com/t5/network-security/can-t-see-login-or-config-messages-in-pix-syslog/m-p/153200#M607168</link>
      <description>&lt;P&gt;We have a pix 525 (v6.2.2).  Syslog messages are directed to a syslog server using the following config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging on&lt;/P&gt;&lt;P&gt;logging timestamp&lt;/P&gt;&lt;P&gt;logging trap debugging&lt;/P&gt;&lt;P&gt;logging host inside 10.0.0.4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Show logging give the following output:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syslog logging: enabled&lt;/P&gt;&lt;P&gt;    Facility: 20&lt;/P&gt;&lt;P&gt;    Timestamp logging: enabled&lt;/P&gt;&lt;P&gt;    Standby logging: disabled&lt;/P&gt;&lt;P&gt;    Console logging: disabled&lt;/P&gt;&lt;P&gt;    Monitor logging: disabled&lt;/P&gt;&lt;P&gt;    Buffer logging: disabled&lt;/P&gt;&lt;P&gt;    Trap logging: level debugging, 26644891 messages logged&lt;/P&gt;&lt;P&gt;        Logging to inside 10.0.0.4&lt;/P&gt;&lt;P&gt;    History logging: disabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our problem is that we can't see any messages with regards to who did what....e.g. console login, executing 'config t' etc.  We only get messages that show the various packets being passed through the pix.  There are no users defined on the pix box, it is strictly console only (no telnet).  Any chance you can help!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:40:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-see-login-or-config-messages-in-pix-syslog/m-p/153200#M607168</guid>
      <dc:creator>zabbas</dc:creator>
      <dc:date>2020-02-21T06:40:51Z</dc:date>
    </item>
    <item>
      <title>Re: Can't see login or config messages in PIX syslog</title>
      <link>https://community.cisco.com/t5/network-security/can-t-see-login-or-config-messages-in-pix-syslog/m-p/153201#M607171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check the following URL to get the meaning of all syslog messages.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_62/syslog/pixemsgs.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_62/syslog/pixemsgs.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some sample messages with meanings&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%PIX-5-111001: Begin configuration: IP_addr writing to device &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Explanation   This message is logged when you enter the write command to store your configuration on a device (either floppy, Flash memory, TFTP, the failover standby unit, or the console terminal). The IP_addr indicates whether the login was made at the console port or via a Telnet connection. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Action None required. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%PIX-5-111003: IP_addr Erase configuration &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Explanation   This is a PIX Firewall management message. This message is logged when you erase the contents of Flash memory by entering the write erase command at the console. The IP_addr indicates whether the login was made at the console port or via a Telnet connection&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Apr 2003 14:27:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-see-login-or-config-messages-in-pix-syslog/m-p/153201#M607171</guid>
      <dc:creator>hadbou</dc:creator>
      <dc:date>2003-04-16T14:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: Can't see login or config messages in PIX syslog</title>
      <link>https://community.cisco.com/t5/network-security/can-t-see-login-or-config-messages-in-pix-syslog/m-p/153202#M607172</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It sounds like you might be looking for version control?  If so , there are products that will let you do that, CiscoWorks being one of them.  Every time a change is made on a router, it is recorded in the CW database, and you can go back several different versions of the config (ie - back to last month's config).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other than those cryptic syslog messages, there is no real way to see exactly what commands were entered on the PIX...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Apr 2003 14:37:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-see-login-or-config-messages-in-pix-syslog/m-p/153202#M607172</guid>
      <dc:creator>robhorniachek</dc:creator>
      <dc:date>2003-04-16T14:37:46Z</dc:date>
    </item>
    <item>
      <title>Re: Can't see login or config messages in PIX syslog</title>
      <link>https://community.cisco.com/t5/network-security/can-t-see-login-or-config-messages-in-pix-syslog/m-p/153203#M607173</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you want to see who did what on the PIX, then you need to add authentication at the least.  See &lt;A class="jive-link-custom" href="http://www.cisco.com/warp/public/110/authtopix.shtml" target="_blank"&gt;http://www.cisco.com/warp/public/110/authtopix.shtml&lt;/A&gt; for details.  Note in 6.3 you can use the local user database, you don't have to use a TACACS/Radius server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Apr 2003 23:03:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-see-login-or-config-messages-in-pix-syslog/m-p/153203#M607173</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2003-04-16T23:03:08Z</dc:date>
    </item>
  </channel>
</rss>

