<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Where is the logging occuring? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/where-is-the-logging-occuring/m-p/1575741#M611943</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kevin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Take a look at the output of 'show run log' on the ASA. That should tell you the different logging destinations that are configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 09 Sep 2010 18:54:28 GMT</pubDate>
    <dc:creator>mirober2</dc:creator>
    <dc:date>2010-09-09T18:54:28Z</dc:date>
    <item>
      <title>Where is the logging occuring?</title>
      <link>https://community.cisco.com/t5/network-security/where-is-the-logging-occuring/m-p/1575740#M611942</link>
      <description>&lt;P&gt;CSC Forum&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am working on a client site today.&amp;nbsp; The client has an ACL applied to the WAN interface of their ASA in an inbound direction, which is not uncommon.&amp;nbsp; The last line of the ACL has an ACE that reads&lt;/P&gt;&lt;P&gt; "access-list WAN_access_in_1 line 45 extended permit ip any any log debugging interval 300"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I am unclear about is where the logging occurs.&amp;nbsp; I explained to the IT Admin on site that they may not want to have ip permit any any, and that if we figured out what that traffic that was matching that ACE was, we could just write a rule for it.&amp;nbsp; So I wanted to examine the logs since logging is enabled on that ACE so I could see where the traffic was coming from.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I looked at the log buffer, but there is not data in the log before with respect to the ACE.&amp;nbsp; Where would it be logging to based on the statement?&amp;nbsp; There is not a syslog server at this client, so it has to be either the log buffer or the ASDM log I think...?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also what does the interval 300 mean in the ACE?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Kevin&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:38:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/where-is-the-logging-occuring/m-p/1575740#M611942</guid>
      <dc:creator>Kevin Melton</dc:creator>
      <dc:date>2019-03-11T18:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: Where is the logging occuring?</title>
      <link>https://community.cisco.com/t5/network-security/where-is-the-logging-occuring/m-p/1575741#M611943</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kevin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Take a look at the output of 'show run log' on the ASA. That should tell you the different logging destinations that are configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Sep 2010 18:54:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/where-is-the-logging-occuring/m-p/1575741#M611943</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2010-09-09T18:54:28Z</dc:date>
    </item>
    <item>
      <title>Re: Where is the logging occuring?</title>
      <link>https://community.cisco.com/t5/network-security/where-is-the-logging-occuring/m-p/1575742#M611944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes Mike&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well I had done exactly that I I see the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging standby&lt;BR /&gt;logging buffer-size 16384&lt;BR /&gt;logging buffered debugging&lt;BR /&gt;logging trap debugging&lt;BR /&gt;logging asdm informational&lt;BR /&gt;logging host inside 192.168.1.146&lt;BR /&gt;logging host inside 172.16.32.157&lt;BR /&gt;snmp-server enable traps syslog&lt;/P&gt;&lt;P&gt;but this does not tell me which logging method that the ACE statement is writing to...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;STRONG&gt;&lt;EM&gt;access-list WAN_access_in_1 extended permit ip any any log debugging&lt;/EM&gt;&lt;/STRONG&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My assumption was that it should be in the log buffer, but I still need to verify this so I can extract the data that I need.&amp;nbsp; I do not see any "permit" activity in the log buffer.&amp;nbsp; Yet I can see hit counts on the ACE when I use ASDM.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Sep 2010 19:08:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/where-is-the-logging-occuring/m-p/1575742#M611944</guid>
      <dc:creator>Kevin Melton</dc:creator>
      <dc:date>2010-09-09T19:08:53Z</dc:date>
    </item>
    <item>
      <title>Re: Where is the logging occuring?</title>
      <link>https://community.cisco.com/t5/network-security/where-is-the-logging-occuring/m-p/1575743#M611945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kevin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should see the hits in the 'show log' output, and also in the syslogs saved to 192.168.1.146 and 172.16.32.157. The message you should see is %ASA-7-106100.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Sep 2010 19:17:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/where-is-the-logging-occuring/m-p/1575743#M611945</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2010-09-09T19:17:28Z</dc:date>
    </item>
  </channel>
</rss>

