<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA logging queue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-logging-queue/m-p/1572655#M739056</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Corey,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; To follow up on what Kureli mentioned, the biggest issue will be the console logging. When you enable console logging you force the syslog process to rate-limit the generation of syslogs such that they would not overwhelm the slow Serial link (console). Depending on the rate of syslogs generated by your ASA, the scant 9200 baud rate of the console gets overrun quickly and as a result logs have to be queued up and subsequently dropped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The only time you should be using console logging is if you have a host connected to the console and require seeing syslogs on that serial link. Even then, you must make sure the syslog rate is very low otherwise logs will be dropped by design.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Magnus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 12 Nov 2010 03:10:14 GMT</pubDate>
    <dc:creator>Magnus Mortensen</dc:creator>
    <dc:date>2010-11-12T03:10:14Z</dc:date>
    <item>
      <title>ASA logging queue</title>
      <link>https://community.cisco.com/t5/network-security/asa-logging-queue/m-p/1572653#M739043</link>
      <description>&lt;P&gt;I'm having an issue where our syslog server does not appear to be getting all of the data that we expect it to get from a couple of our ASA's.&amp;nbsp; The ASA's that are syslogging properly show "Current 0 msg on queue, 512 msgs most on queue" while the problematic ones usually have 300-400 "msg on queue".&amp;nbsp; I have tried to raise the "logging queue length limit" to 1024 on the problem ASA's, but that didn't help.&amp;nbsp; I also toned down the logging levels, as they were all at "debugging" but that did not help either.&amp;nbsp; These are very high traffic internal firewalls, so they are a lot busier than the 0 msg firewalls, but I'm thinking 300-400 messages in queue sounds too high.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's the output of a show logging settings:&lt;/P&gt;&lt;P&gt;Syslog logging: enabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Facility: 20&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Timestamp logging: disabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Standby logging: enabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Debug-trace logging: disabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Console logging: level notifications, 86410176 messages logged&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Monitor logging: level notifications, 86410174 messages logged&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Buffer logging: level notifications, 86410176 messages logged&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Trap logging: level debugging, facility 20, 86485505 messages logged&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Logging to prodinside-v364 syslogserver errors: 52467&amp;nbsp; dropped: 2382326&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; History logging: disabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Device ID: disabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Mail logging: disabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ASDM logging: level informational, 86472362 messages logged&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas as to what I can do to lower the size of my message queues? &lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:08:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-logging-queue/m-p/1572653#M739043</guid>
      <dc:creator>corey</dc:creator>
      <dc:date>2019-03-11T19:08:12Z</dc:date>
    </item>
    <item>
      <title>Re: ASA logging queue</title>
      <link>https://community.cisco.com/t5/network-security/asa-logging-queue/m-p/1572654#M739048</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pls. remove console logging.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue "sh run logg"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can remove monitor and console logg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;conf t&lt;/P&gt;&lt;P&gt;no logging monitor&lt;/P&gt;&lt;P&gt;no logging console&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;once done check it again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Nov 2010 23:45:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-logging-queue/m-p/1572654#M739048</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-11-11T23:45:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA logging queue</title>
      <link>https://community.cisco.com/t5/network-security/asa-logging-queue/m-p/1572655#M739056</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Corey,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; To follow up on what Kureli mentioned, the biggest issue will be the console logging. When you enable console logging you force the syslog process to rate-limit the generation of syslogs such that they would not overwhelm the slow Serial link (console). Depending on the rate of syslogs generated by your ASA, the scant 9200 baud rate of the console gets overrun quickly and as a result logs have to be queued up and subsequently dropped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The only time you should be using console logging is if you have a host connected to the console and require seeing syslogs on that serial link. Even then, you must make sure the syslog rate is very low otherwise logs will be dropped by design.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Magnus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Nov 2010 03:10:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-logging-queue/m-p/1572655#M739056</guid>
      <dc:creator>Magnus Mortensen</dc:creator>
      <dc:date>2010-11-12T03:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: ASA logging queue</title>
      <link>https://community.cisco.com/t5/network-security/asa-logging-queue/m-p/1572656#M739066</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the replies.&amp;nbsp; I have removed the console and monitor logging, but the issue still persists.&amp;nbsp; Here's the output of "sh run logg" after I removed console/monitor logging:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging enable&lt;BR /&gt;logging standby&lt;BR /&gt;logging console notifications&lt;BR /&gt;logging monitor notifications&lt;BR /&gt;logging buffered notifications&lt;BR /&gt;logging trap debugging&lt;BR /&gt;logging asdm debugging&lt;BR /&gt;logging queue 1024&lt;BR /&gt;logging host prodinside-v364 syslogserver1&lt;BR /&gt;logging host prodinside-v364 syslogserver2&lt;BR /&gt;logging host prodinside-v364 syslogserver3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I issued a "no logging enable", waited for the queue to hit zero, then "logging enable" and the queue immediately started to grow and was up to around 300 again within about 20 seconds.&amp;nbsp; So I removed a few other settings, now it looks like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging enable&lt;BR /&gt;logging buffered notifications&lt;BR /&gt;logging trap debugging&lt;BR /&gt;logging asdm debugging&lt;BR /&gt;logging queue 1024&lt;BR /&gt;logging host prodinside-v364 syslogserver1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and I still have over 300 messages queued (after disabling and enabling logging). Any other ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is part of a failover/dual-context pair if that matters.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Nov 2010 14:56:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-logging-queue/m-p/1572656#M739066</guid>
      <dc:creator>corey</dc:creator>
      <dc:date>2010-11-12T14:56:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA logging queue</title>
      <link>https://community.cisco.com/t5/network-security/asa-logging-queue/m-p/1572657#M739072</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just figured it out...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I removed the "logging standby" on the paired ASA and the queue on both immediately dropped to zero.&amp;nbsp; What will I be missing out on by not doing logging to the standby context/asa?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Nov 2010 14:59:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-logging-queue/m-p/1572657#M739072</guid>
      <dc:creator>corey</dc:creator>
      <dc:date>2010-11-12T14:59:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA logging queue</title>
      <link>https://community.cisco.com/t5/network-security/asa-logging-queue/m-p/1572658#M739086</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Logging standby causes the standby unit also to send syslogs to the syslog server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will almost double the amount of syslogs that the syslog server will see as both units will send logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We do this for troubleshooting purpose just to see what the sec/standby unit sent to the syslog server during the time of the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is not on by default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Nov 2010 15:51:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-logging-queue/m-p/1572658#M739086</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-11-12T15:51:47Z</dc:date>
    </item>
  </channel>
</rss>

