<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: logs for a specific access-list in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/logs-for-a-specific-access-list/m-p/1133328#M896764</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Celso,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only way I can think of to do this would be to set the specific access-list you want to send to your syslog server to level 0 (emergencies). Then, you would log at the emergencies level for your syslog server. Since this level does not generate any syslogs normally, you would only see syslogs generated by your ACL. So, the configuration would look something like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list permit ip any any log emergencies&lt;/P&gt;&lt;P&gt;logging trap emergencies&lt;/P&gt;&lt;P&gt;logging host inside 10.1.1.1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other than that, there is no direct way to do this with the logging commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 08 Sep 2008 00:53:12 GMT</pubDate>
    <dc:creator>robertson.michael</dc:creator>
    <dc:date>2008-09-08T00:53:12Z</dc:date>
    <item>
      <title>logs for a specific access-list</title>
      <link>https://community.cisco.com/t5/network-security/logs-for-a-specific-access-list/m-p/1133327#M896763</link>
      <description>&lt;P&gt;hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is there any way to send logs to a syslog server for only a specific access-list?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:40:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/logs-for-a-specific-access-list/m-p/1133327#M896763</guid>
      <dc:creator>cfajardo1_2</dc:creator>
      <dc:date>2019-03-11T13:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: logs for a specific access-list</title>
      <link>https://community.cisco.com/t5/network-security/logs-for-a-specific-access-list/m-p/1133328#M896764</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Celso,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only way I can think of to do this would be to set the specific access-list you want to send to your syslog server to level 0 (emergencies). Then, you would log at the emergencies level for your syslog server. Since this level does not generate any syslogs normally, you would only see syslogs generated by your ACL. So, the configuration would look something like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list permit ip any any log emergencies&lt;/P&gt;&lt;P&gt;logging trap emergencies&lt;/P&gt;&lt;P&gt;logging host inside 10.1.1.1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other than that, there is no direct way to do this with the logging commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Sep 2008 00:53:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/logs-for-a-specific-access-list/m-p/1133328#M896764</guid>
      <dc:creator>robertson.michael</dc:creator>
      <dc:date>2008-09-08T00:53:12Z</dc:date>
    </item>
  </channel>
</rss>

