<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Syslog config question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-syslog-config-question/m-p/1491782#M613258</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't seem to get ASA authentication request, or config changes alerts to be forwarded to our syslog server.&amp;nbsp; I'm able to see all normal ASA messages, blocked messages, VPN authenications, etc, but if I fail a login, or make config changes it does not show up in our syslog server.&amp;nbsp; Here is the logging config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging list Failover level errors class ha&lt;BR /&gt;logging buffered informational&lt;BR /&gt;logging trap informational&lt;BR /&gt;logging asdm informational&lt;BR /&gt;&lt;SPAN&gt;logging from-address &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:reports@company.com" target="_blank"&gt;reports@company.com&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;logging recipient-address &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:sjaggers@company.com" target="_blank"&gt;sjaggers@company.com&lt;/A&gt;&lt;SPAN&gt; level critical&lt;/SPAN&gt;&lt;BR /&gt;logging device-id hostname&lt;BR /&gt;logging host inside NAC-Syslog&lt;/P&gt;&lt;P&gt;logging class auth console notifications trap informational asdm notifications&lt;BR /&gt;logging class config console notifications trap informational asdm notifications&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've turned up every level I could think of to informational, done multiple google searches and I am at a loss.&amp;nbsp; This is something we have to show for compliance, and is one of my last open issues so any help is greatly appreciated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shawn&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 18:31:37 GMT</pubDate>
    <dc:creator>smjaggers</dc:creator>
    <dc:date>2019-03-11T18:31:37Z</dc:date>
    <item>
      <title>ASA Syslog config question</title>
      <link>https://community.cisco.com/t5/network-security/asa-syslog-config-question/m-p/1491782#M613258</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't seem to get ASA authentication request, or config changes alerts to be forwarded to our syslog server.&amp;nbsp; I'm able to see all normal ASA messages, blocked messages, VPN authenications, etc, but if I fail a login, or make config changes it does not show up in our syslog server.&amp;nbsp; Here is the logging config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging enable&lt;BR /&gt;logging timestamp&lt;BR /&gt;logging list Failover level errors class ha&lt;BR /&gt;logging buffered informational&lt;BR /&gt;logging trap informational&lt;BR /&gt;logging asdm informational&lt;BR /&gt;&lt;SPAN&gt;logging from-address &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:reports@company.com" target="_blank"&gt;reports@company.com&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;logging recipient-address &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:sjaggers@company.com" target="_blank"&gt;sjaggers@company.com&lt;/A&gt;&lt;SPAN&gt; level critical&lt;/SPAN&gt;&lt;BR /&gt;logging device-id hostname&lt;BR /&gt;logging host inside NAC-Syslog&lt;/P&gt;&lt;P&gt;logging class auth console notifications trap informational asdm notifications&lt;BR /&gt;logging class config console notifications trap informational asdm notifications&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've turned up every level I could think of to informational, done multiple google searches and I am at a loss.&amp;nbsp; This is something we have to show for compliance, and is one of my last open issues so any help is greatly appreciated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shawn&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:31:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-syslog-config-question/m-p/1491782#M613258</guid>
      <dc:creator>smjaggers</dc:creator>
      <dc:date>2019-03-11T18:31:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Syslog config question</title>
      <link>https://community.cisco.com/t5/network-security/asa-syslog-config-question/m-p/1491783#M613261</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Shawn,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your configuration looks correct to be sending the syslogs.&amp;nbsp; I ran a few quick tests here and these are the specific syslogs you should be on the lookout for.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuration Changes&lt;/P&gt;&lt;P&gt;===================&lt;/P&gt;&lt;P&gt;%ASA-5-111008: User 'enable_15' executed the 'class-map test' command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/system/message/logmsgs.html#wp4769400"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/system/message/logmsgs.html#wp4769400&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This notification level syslog will be issued whenever someone issues a command on the ASA.&amp;nbsp; Note that if you are logging in and then using the enable command the username will always show up as enable_15.&amp;nbsp; Users must use the "login" command and authenticate again to retain their username.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Failed Logins&lt;/P&gt;&lt;P&gt;====================&lt;/P&gt;&lt;P&gt;%ASA-6-113015: AAA user authentication Rejected : reason = Invalid password : local database : user = scott&lt;BR /&gt;%ASA-6-611102: User authentication failed: Uname: scott&lt;BR /&gt;%ASA-6-611102: User authentication failed: Uname: scott&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/system/message/logmsgs.html#wp4774576"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/system/message/logmsgs.html#wp4774576&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;611102 identifies when an authentication for connections to the ASA fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps in tracking down those syslogs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Aug 2010 15:22:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-syslog-config-question/m-p/1491783#M613261</guid>
      <dc:creator>scbrinke</dc:creator>
      <dc:date>2010-08-27T15:22:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Syslog config question</title>
      <link>https://community.cisco.com/t5/network-security/asa-syslog-config-question/m-p/1491784#M613264</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks!&amp;nbsp; I guess I wasn't formatting my queries to the syslog serv&lt;SPAN style="background-color: #f8fafd;"&gt;er right, our solution is not the most user friendly.&amp;nbsp; I was able to find each of the classes I needed, starting with the 111008 message you specified below.&amp;nbsp; Thanks for the help.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Shawn&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Aug 2010 16:03:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-syslog-config-question/m-p/1491784#M613264</guid>
      <dc:creator>smjaggers</dc:creator>
      <dc:date>2010-08-27T16:03:48Z</dc:date>
    </item>
  </channel>
</rss>

