<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best practice for logging in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/best-practice-for-logging/m-p/1495701#M923410</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. Level 3, 4(error, warnings) is the ideal. Levels 5-7 (notification, informational, debug) generate more logs and should be used in case you want to troubleshoot.&lt;/P&gt;&lt;P&gt;2. You should keep as long as possible depending on your policies. Most companies keep the logs for about 6-12 monhts, but it really depends on the company. If your log load is not too much you can keep them for even more.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 07 Jul 2010 17:51:29 GMT</pubDate>
    <dc:creator>Panos Kampanakis</dc:creator>
    <dc:date>2010-07-07T17:51:29Z</dc:date>
    <item>
      <title>Best practice for logging</title>
      <link>https://community.cisco.com/t5/network-security/best-practice-for-logging/m-p/1495699#M923408</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to know if there is any best practice document for Firewall logging. This would include&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. What level of logging is ideal&lt;/P&gt;&lt;P&gt;2. If a log is stored in a logging server, how long is it best to store the logs and retain the logs by a backup tape etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This can include for various industries like IT, Banking etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any document pertaining to these would be helpful. Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Manoj&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:00:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/best-practice-for-logging/m-p/1495699#M923408</guid>
      <dc:creator>manoj-wadhwa</dc:creator>
      <dc:date>2020-02-21T12:00:18Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice for logging</title>
      <link>https://community.cisco.com/t5/network-security/best-practice-for-logging/m-p/1495700#M923409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to know if there is any best practice document for Firewall logging. This would include&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. What level of logging is ideal&lt;/P&gt;&lt;P&gt;2. If a log is stored in a logging server, how long is it best to store the logs and retain the logs by a backup tape etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This can include for various industries like IT, Banking etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any document pertaining to these would be helpful. Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Manoj&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;Manoj,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check out the below link for best practice for logging and prerequiste in cisco devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a0080120f48.shtml#logbest"&gt;http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a0080120f48.shtml#logbest&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.ciscopartner.biz/en/US/docs/security/asa/asa82/configuration/guide/monitor_syslog.html#wp1110908"&gt;http://www.ciscopartner.biz/en/US/docs/security/asa/asa82/configuration/guide/monitor_syslog.html#wp1110908&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope to Help !!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ganesh.H&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate the helpful post&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jun 2010 05:53:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/best-practice-for-logging/m-p/1495700#M923409</guid>
      <dc:creator>Ganesh Hariharan</dc:creator>
      <dc:date>2010-06-28T05:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice for logging</title>
      <link>https://community.cisco.com/t5/network-security/best-practice-for-logging/m-p/1495701#M923410</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. Level 3, 4(error, warnings) is the ideal. Levels 5-7 (notification, informational, debug) generate more logs and should be used in case you want to troubleshoot.&lt;/P&gt;&lt;P&gt;2. You should keep as long as possible depending on your policies. Most companies keep the logs for about 6-12 monhts, but it really depends on the company. If your log load is not too much you can keep them for even more.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jul 2010 17:51:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/best-practice-for-logging/m-p/1495701#M923410</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-07-07T17:51:29Z</dc:date>
    </item>
    <item>
      <title>Re: Best practice for logging</title>
      <link>https://community.cisco.com/t5/network-security/best-practice-for-logging/m-p/1495702#M923411</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For a firewall it is better to have informational if you have a solution like MARS.&lt;/P&gt;&lt;P&gt;For the logging retention it depends on the country laws and the company policies.&lt;/P&gt;&lt;P&gt;I think 6 months is the least you should have.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Jul 2010 10:25:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/best-practice-for-logging/m-p/1495702#M923411</guid>
      <dc:creator>dvithoulkas</dc:creator>
      <dc:date>2010-07-15T10:25:05Z</dc:date>
    </item>
  </channel>
</rss>

