<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Encrypted Syslog in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363710#M945220</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The command preview is: "logging host inside 1.2.3.4 6/1470 secure", and it will apply. Sitting on the syslog server, I get one message that appears to be the initial handshake for a TLS connection and then nothing. I just need the documentation on setting this up such as: where do you configure the TLS settings for syslog? It doesn't appear Cisco has ANY documentation regarding this from my two+ hours of searching...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 03 Feb 2010 19:44:18 GMT</pubDate>
    <dc:creator>rondcisco</dc:creator>
    <dc:date>2010-02-03T19:44:18Z</dc:date>
    <item>
      <title>Encrypted Syslog</title>
      <link>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363702#M945212</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where can I find info/documentation regarding the "enable secure syslog using SSL/TLS" capability of the ASA? Are there any syslog servers out there that support this? I've been researching this for a while now...it appears there's not much documentation regarding this feature (or at least regarding its setup).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm aware that you can build IPSEC tunnels to encrypt plaintext syslog, but&amp;nbsp; SSL/TLS encrypted syslog is a very attractive option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone doing this?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:51:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363702#M945212</guid>
      <dc:creator>rondcisco</dc:creator>
      <dc:date>2020-02-21T11:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: Encrypted Syslog</title>
      <link>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363703#M945213</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You cannot encrypt syslogs. You have 2 options though:&lt;/P&gt;&lt;P&gt;- Send them over a tunnel like you are saying&lt;/P&gt;&lt;P&gt;- send them with snmp traps and use the community string to encrypt snmp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 31 Jan 2010 16:35:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363703#M945213</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-01-31T16:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: Encrypted Syslog</title>
      <link>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363704#M945214</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;If this is true, why does does the ASA have "Enable secure syslog using SSL/TLS" as an option?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Feb 2010 15:58:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363704#M945214</guid>
      <dc:creator>rondcisco</dc:creator>
      <dc:date>2010-02-03T15:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: Encrypted Syslog</title>
      <link>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363705#M945215</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is that a doc you are referring to?&lt;/P&gt;&lt;P&gt;Panos&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Feb 2010 16:57:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363705#M945215</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-02-03T16:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: Encrypted Syslog</title>
      <link>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363706#M945216</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not so much a doc as the ASDM interface I'm looking at right now... ASA version 8+ and ASDM 6.2. Configuration &amp;gt; Device Management &amp;gt; Logging &amp;gt; Syslog Server &amp;gt; Add &amp;gt; Choose TCP.... look for check box "Enable secure syslog using SSL/TLS"... &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Feb 2010 17:03:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363706#M945216</guid>
      <dc:creator>rondcisco</dc:creator>
      <dc:date>2010-02-03T17:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: Encrypted Syslog</title>
      <link>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363707#M945217</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I see.&lt;/P&gt;&lt;P&gt;That chcekbox is greyed out when there is no VPN configured. If there is VPN then it will just match the syslog traffic in the crypto ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it makes sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Feb 2010 18:52:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363707#M945217</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-02-03T18:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: Encrypted Syslog</title>
      <link>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363708#M945218</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That appears to be incorrect. You need to choose TCP syslog for the "enable secure syslog using SSL/TLS" option to become available. I just disabled IPSEC on all interfaces and verified the tunnels are no longer avaiable, yet this option still exists. I'm fairly certain syslog with the SSL/TLS option and what IPSEC tunnels are present on the device are completely unrelated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Feb 2010 19:11:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363708#M945218</guid>
      <dc:creator>rondcisco</dc:creator>
      <dc:date>2010-02-03T19:11:11Z</dc:date>
    </item>
    <item>
      <title>Re: Encrypted Syslog</title>
      <link>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363709#M945219</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It will not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tested on my ASDM, without any VPN config it is grayed out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enable preview commands on ASDM and check that checkbox and see what command ASDM will push, that will tell you what that checkbox does and will clarify it for you.&lt;/P&gt;&lt;P&gt;Please do post a reply if I am mistaken.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Panos&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Feb 2010 19:33:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363709#M945219</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-02-03T19:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: Encrypted Syslog</title>
      <link>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363710#M945220</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The command preview is: "logging host inside 1.2.3.4 6/1470 secure", and it will apply. Sitting on the syslog server, I get one message that appears to be the initial handshake for a TLS connection and then nothing. I just need the documentation on setting this up such as: where do you configure the TLS settings for syslog? It doesn't appear Cisco has ANY documentation regarding this from my two+ hours of searching...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Feb 2010 19:44:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363710#M945220</guid>
      <dc:creator>rondcisco</dc:creator>
      <dc:date>2010-02-03T19:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: Encrypted Syslog</title>
      <link>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363711#M945221</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, it ends up that you are right, it has been addede in 8.0.2 and later.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Explained here &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/l2.html#wp1772754"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/l2.html#wp1772754&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The secure keyword specifies that the connection to the remote logging host should use SSL/TLS. This option is valid only if the protocol selected is TCP. &lt;SPAN class="content"&gt; &lt;A name="wp1772782"&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="pNT_NoteTable"&gt;&lt;STRONG&gt;Note &lt;/STRONG&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="1" /&gt;A secure logging connection can only be established with a SSL/TLS- capable syslog server. If a SSL/TLS connection cannot be established, all new connections will be denied. You may change this default behavior by entering the &lt;STRONG class="cBold"&gt;logging permit-hostdown&lt;/STRONG&gt; command.&lt;/P&gt;&lt;P class="pNT_NoteTable"&gt;&lt;/P&gt;&lt;P class="pNT_NoteTable"&gt;I believe it is clear now.&lt;/P&gt;&lt;P class="pNT_NoteTable"&gt;&lt;/P&gt;&lt;P class="pNT_NoteTable"&gt;PK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Feb 2010 20:14:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363711#M945221</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-02-03T20:14:12Z</dc:date>
    </item>
    <item>
      <title>Re: Encrypted Syslog</title>
      <link>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363712#M945222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you know of any SSL/TLS capable log servers? Anyone know of any configuration examples for doing this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Feb 2010 20:55:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363712#M945222</guid>
      <dc:creator>rondcisco</dc:creator>
      <dc:date>2010-02-03T20:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: Encrypted Syslog</title>
      <link>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363713#M945223</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am Rainer Gerhards, author of rsyslog [1]. I guess Cisco has implemented RFC5424/5425. Rsyslog served as test bed during standard definition. It has a fairly decent implementation of TLS syslog, but I did not yet have any chance to do any interop testing. It may work out of the box, but (likely) it may also require some code changes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If someone here has the necessary equipment, I would appreciate if you could give rsyslog a try. I will try my best to solve any issues as quickly as possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You can also contact me at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:rgerhards@adiscon.com"&gt;rgerhards@adiscon.com&lt;/A&gt;&lt;SPAN&gt; - I dont' know if I will receive automatic notifications of any replies here (I just registered for this posting &lt;/SPAN&gt;&lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/wink.gif"&gt;&lt;/SPAN&gt;).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Rainer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[1] &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.rsyslog.com"&gt;http://www.rsyslog.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Feb 2010 14:15:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363713#M945223</guid>
      <dc:creator>rgerhards</dc:creator>
      <dc:date>2010-02-04T14:15:24Z</dc:date>
    </item>
    <item>
      <title>I believe you can use an ACS</title>
      <link>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363714#M945224</link>
      <description>&lt;P&gt;I believe you can use an ACS server to encrypt syslog.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2016 20:20:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363714#M945224</guid>
      <dc:creator>hammack.ryan</dc:creator>
      <dc:date>2016-02-09T20:20:16Z</dc:date>
    </item>
    <item>
      <title>Well I have the same problem.</title>
      <link>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363715#M945225</link>
      <description>&lt;P&gt;Well I have the same problem. The syslog server I use is logstash. Problem is that I use SSL to send the logs from other hosts over the INET. I would need to upload my cert to ASA and tell ASA to use it when logs are sent to logstash.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately there is not such option or I cannot see it.&amp;nbsp;ASA 5520 9.1(5)&lt;/P&gt;
&lt;P&gt;Anybody found solution?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2017 10:35:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363715#M945225</guid>
      <dc:creator>patrykkandziora</dc:creator>
      <dc:date>2017-04-20T10:35:24Z</dc:date>
    </item>
    <item>
      <title>Hi All,</title>
      <link>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363716#M945226</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;I know this is quiet old &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;but as it appear in search, I used syslog-ng on linux and it is working fine&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2017 08:15:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/1363716#M945226</guid>
      <dc:creator>IBMintdev</dc:creator>
      <dc:date>2017-06-01T08:15:54Z</dc:date>
    </item>
    <item>
      <title>Re: Hi All,</title>
      <link>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/3706954#M945227</link>
      <description>&lt;P&gt;Hello everybody&lt;/P&gt;
&lt;P&gt;I know this is an old post, but i'm trying to implement this.&lt;/P&gt;
&lt;P&gt;Could anybody tell me if this can be done?&lt;/P&gt;
&lt;P&gt;I added a cert (syslog's cert) as a trustpoint, but don't know hot to associate to logg configuration.&lt;/P&gt;
&lt;P&gt;It asks for a "reference identity".&lt;/P&gt;
&lt;P&gt;Does anybody has any configuraion guide?????&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 08:41:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/encrypted-syslog/m-p/3706954#M945227</guid>
      <dc:creator>p.juarezponte</dc:creator>
      <dc:date>2018-09-14T08:41:57Z</dc:date>
    </item>
  </channel>
</rss>

