<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Multiple Syslog Servers in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/multiple-syslog-servers/m-p/1361727#M923800</link>
    <description>&lt;P&gt;I know in the ASA5520 we use, i can created multiple syslog servers to send syslogs to. However, I am&lt;/P&gt;&lt;P&gt; wondering, is there a way to segment the data?&amp;nbsp; IE - We have a "generic" syslog server that gets all the syslog data (ncluding Informational), but I would like to create a second syslog entry on the ASA (pointing to a different IP address) and have it ONLY send specific message types.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically, I am wanting to have the messages related to the Botnet filtering send to a differnt syslog server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this possible?&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 11:53:11 GMT</pubDate>
    <dc:creator>don.click1</dc:creator>
    <dc:date>2020-02-21T11:53:11Z</dc:date>
    <item>
      <title>Multiple Syslog Servers</title>
      <link>https://community.cisco.com/t5/network-security/multiple-syslog-servers/m-p/1361727#M923800</link>
      <description>&lt;P&gt;I know in the ASA5520 we use, i can created multiple syslog servers to send syslogs to. However, I am&lt;/P&gt;&lt;P&gt; wondering, is there a way to segment the data?&amp;nbsp; IE - We have a "generic" syslog server that gets all the syslog data (ncluding Informational), but I would like to create a second syslog entry on the ASA (pointing to a different IP address) and have it ONLY send specific message types.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically, I am wanting to have the messages related to the Botnet filtering send to a differnt syslog server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this possible?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:53:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-syslog-servers/m-p/1361727#M923800</guid>
      <dc:creator>don.click1</dc:creator>
      <dc:date>2020-02-21T11:53:11Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Syslog Servers</title>
      <link>https://community.cisco.com/t5/network-security/multiple-syslog-servers/m-p/1361728#M923801</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately, that cannot be configured.&lt;/P&gt;&lt;P&gt;The syslogs sent will be the same to all syslog servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/monitor.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/monitor.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Feb 2010 22:23:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-syslog-servers/m-p/1361728#M923801</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-02-23T22:23:41Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Syslog Servers</title>
      <link>https://community.cisco.com/t5/network-security/multiple-syslog-servers/m-p/1361729#M923802</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is a thought may be this might work for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Refer this link for botnet:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-8782"&gt;https://supportforums.cisco.com/docs/DOC-8782&lt;/A&gt;&lt;/P&gt;&lt;P&gt;botnet syslogs&lt;/P&gt;&lt;P&gt;338001 - 338004&lt;/P&gt;&lt;P&gt;338101 - 338104&lt;/P&gt;&lt;P&gt;338201 - 338204&lt;/P&gt;&lt;P&gt;338301 - 338310&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Refer this link for logging commands:&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/l2.html#wp1772272"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/l2.html#wp1772272&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="cExBold"&gt;1. configure a logging list and send it to buffer and wrap that to ftp server&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="cExBold"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="pEx1_Example1"&gt;&lt;PRE&gt;hostname(config)#&lt;SPAN class="cExBold"&gt; logging list my-list &lt;/SPAN&gt;338001 - 338004&lt;BR /&gt;&lt;SPAN class="content"&gt;&lt;PRE&gt;hostname(config)#&lt;SPAN class="cExBold"&gt; logging list my-list &lt;/SPAN&gt;338101 - 338104&lt;/PRE&gt;
&lt;/SPAN&gt;hostname(config)#&lt;SPAN class="cExBold"&gt; logging list my-list &lt;/SPAN&gt;338201 - 338204&lt;BR /&gt;hostname(config)# &lt;SPAN class="cExBold"&gt;logging list my-list &lt;/SPAN&gt;338301 - 33831&lt;SPAN class="content"&gt;&lt;BR /&gt;
&lt;PRE&gt;&lt;SPAN class="content"&gt;&lt;PRE&gt;&lt;SPAN class="content"&gt;&lt;PRE&gt;hostname(config)#&lt;SPAN style="font-style: normal; font-weight: bold; color: black;"&gt; &lt;/SPAN&gt;&lt;SPAN class="cExBold"&gt;logging buffered my-list&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="content"&gt;&lt;DIV class="pEx1_Example1"&gt;hostname(config)# &lt;STRONG class="cBold"&gt;logging ftp-server 10.10.10.1 /syslogs userid password&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV class="pEx1_Example1"&gt;hostname(config)# &lt;SPAN class="cExBold"&gt;logging ftp-bufferwrap&lt;BR /&gt;&lt;BR /&gt;2 Then you can send other syslogs to another syslog server&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="content"&gt;&lt;PRE&gt;&lt;SPAN class="content"&gt;&lt;PRE&gt;&lt;SPAN class="content"&gt;&lt;PRE&gt;&lt;SPAN class="content"&gt;&lt;PRE&gt;&lt;SPAN class="content"&gt;hostname(config)# logging trap 3&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN class="content"&gt;&lt;PRE&gt;&lt;SPAN class="content"&gt;&lt;PRE&gt;&lt;SPAN class="content"&gt;&lt;PRE&gt;&lt;SPAN class="content"&gt;&lt;PRE&gt;&lt;SPAN class="content"&gt;hostname(config)# logging host inside 10.10.10.2&lt;BR /&gt;&lt;BR /&gt;-KS&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/DIV&gt;
&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/PRE&gt;
&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;BR /&gt;&lt;DIV class="pEx1_Example1"&gt; &lt;/DIV&gt;&lt;BR /&gt;&lt;DIV class="pEx1_Example1"&gt; &lt;/DIV&gt;&lt;BR /&gt;&lt;DIV class="pEx1_Example1"&gt;&lt;PRE&gt;&lt;SPAN class="cExBold"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 14 Mar 2010 22:46:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-syslog-servers/m-p/1361729#M923802</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-03-14T22:46:43Z</dc:date>
    </item>
    <item>
      <title>Multiple Syslog Servers</title>
      <link>https://community.cisco.com/t5/network-security/multiple-syslog-servers/m-p/1361730#M923803</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was wondering also if there is a way to send only specific log messages (defined by the logging list) to one server while still sending the rest to another syslog server? &lt;SPAN __jive_emoticon_name="confused" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Nov 2013 17:54:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-syslog-servers/m-p/1361730#M923803</guid>
      <dc:creator>dartgenov</dc:creator>
      <dc:date>2013-11-21T17:54:40Z</dc:date>
    </item>
  </channel>
</rss>

