<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: capture circular-buffering to syslog server in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/capture-circular-buffering-to-syslog-server/m-p/1410992#M720487</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;example:&lt;/P&gt;&lt;P&gt;If you want to capture your inside host's internet browsing traffic, you can issue the following with a circular-buffer command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cap capin int inside match tcp host 10.10.10.1 any eq 80 circular-buffer buffer 10000000&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will create a 10MB capture file and continue collecting fresh packets after the 10MB buffer gets full.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure what you mean by send it to syslog server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have to issue "sh cap capin" or save the capture using tftp or http&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://"&gt;https://&lt;/A&gt;&lt;SPAN&gt;&lt;IP_ADDRESS&gt;/capture/capin/pcap&lt;/IP_ADDRESS&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;capture command reference: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/c1.html#wp2129312"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/c1.html#wp2129312&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Mar 2010 03:34:10 GMT</pubDate>
    <dc:creator>Kureli Sankar</dc:creator>
    <dc:date>2010-03-16T03:34:10Z</dc:date>
    <item>
      <title>capture circular-buffering to syslog server</title>
      <link>https://community.cisco.com/t5/network-security/capture-circular-buffering-to-syslog-server/m-p/1410991#M720486</link>
      <description>&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;HI&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;I'm running 8.0.5 and want to setup capture with “circular-buffer” and log it to my syslog server. Can I do this and if so, how?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;Will this have a huge effect on my cpu/mem assuming default buffer at 512?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:21:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/capture-circular-buffering-to-syslog-server/m-p/1410991#M720486</guid>
      <dc:creator>aamercado</dc:creator>
      <dc:date>2019-03-11T17:21:59Z</dc:date>
    </item>
    <item>
      <title>Re: capture circular-buffering to syslog server</title>
      <link>https://community.cisco.com/t5/network-security/capture-circular-buffering-to-syslog-server/m-p/1410992#M720487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;example:&lt;/P&gt;&lt;P&gt;If you want to capture your inside host's internet browsing traffic, you can issue the following with a circular-buffer command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cap capin int inside match tcp host 10.10.10.1 any eq 80 circular-buffer buffer 10000000&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will create a 10MB capture file and continue collecting fresh packets after the 10MB buffer gets full.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure what you mean by send it to syslog server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have to issue "sh cap capin" or save the capture using tftp or http&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://"&gt;https://&lt;/A&gt;&lt;SPAN&gt;&lt;IP_ADDRESS&gt;/capture/capin/pcap&lt;/IP_ADDRESS&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;capture command reference: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/c1.html#wp2129312"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/c1.html#wp2129312&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Mar 2010 03:34:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/capture-circular-buffering-to-syslog-server/m-p/1410992#M720487</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-03-16T03:34:10Z</dc:date>
    </item>
  </channel>
</rss>

