<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Logging is incomplete in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-logging-is-incomplete/m-p/1300949#M780258</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your buffer logging is disabled. That's why you don't see anything from "show log".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Buffer logging: disabled "&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 08 Oct 2009 18:39:45 GMT</pubDate>
    <dc:creator>Yudong Wu</dc:creator>
    <dc:date>2009-10-08T18:39:45Z</dc:date>
    <item>
      <title>ASA Logging is incomplete</title>
      <link>https://community.cisco.com/t5/network-security/asa-logging-is-incomplete/m-p/1300948#M780256</link>
      <description>&lt;P&gt;In my ASA 8.2.1 ASDM 6.2.1 i see the hitcount for a "deny any any log" log increasing but i can not get the corresponding log entrys. Even marking the ACE and "show log" does not output a single line. &lt;/P&gt;&lt;P&gt;Getting the denied packet was only possible using packet capture and using Wireshark.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using the Realtime Log Filter and issuing a filter on the IP (which will hit - no names) does not get most of the log entries. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Logging setup:&lt;/P&gt;&lt;P&gt;"logging enable&lt;/P&gt;&lt;P&gt;logging timestamp&lt;/P&gt;&lt;P&gt;logging buffer-size 1000000&lt;/P&gt;&lt;P&gt;logging asdm-buffer-size 512&lt;/P&gt;&lt;P&gt;logging console debugging&lt;/P&gt;&lt;P&gt;logging trap informational&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;logging queue 8192&lt;/P&gt;&lt;P&gt;logging host Server Syslog_Host&lt;/P&gt;&lt;P&gt;logging debug-trace&lt;/P&gt;&lt;P&gt;logging permit-hostdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh logging&lt;/P&gt;&lt;P&gt;Syslog logging: enabled&lt;/P&gt;&lt;P&gt;    Facility: 20&lt;/P&gt;&lt;P&gt;    Timestamp logging: enabled&lt;/P&gt;&lt;P&gt;    Standby logging: disabled&lt;/P&gt;&lt;P&gt;    Debug-trace logging: enabled&lt;/P&gt;&lt;P&gt;    Console logging: level debugging, 1607454 messages logged&lt;/P&gt;&lt;P&gt;    Monitor logging: disabled&lt;/P&gt;&lt;P&gt;    Buffer logging: disabled&lt;/P&gt;&lt;P&gt;    Trap logging: level informational, facility 20, 319012 messages logged&lt;/P&gt;&lt;P&gt;        Logging to Server Syslog_Host errors: 2  dropped: 2&lt;/P&gt;&lt;P&gt;    History logging: disabled&lt;/P&gt;&lt;P&gt;    Device ID: disabled&lt;/P&gt;&lt;P&gt;    Mail logging: disabled&lt;/P&gt;&lt;P&gt;    ASDM logging: level informational, 35858704 messages logged"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the syslog server i do not get much more relevant log entries..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What could be wrong?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:24:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-logging-is-incomplete/m-p/1300948#M780256</guid>
      <dc:creator>Jan.Scholten</dc:creator>
      <dc:date>2019-03-11T16:24:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Logging is incomplete</title>
      <link>https://community.cisco.com/t5/network-security/asa-logging-is-incomplete/m-p/1300949#M780258</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your buffer logging is disabled. That's why you don't see anything from "show log".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Buffer logging: disabled "&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Oct 2009 18:39:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-logging-is-incomplete/m-p/1300949#M780258</guid>
      <dc:creator>Yudong Wu</dc:creator>
      <dc:date>2009-10-08T18:39:45Z</dc:date>
    </item>
  </channel>
</rss>

