<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Creating custom event lists to be sent to syslog server (ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/creating-custom-event-lists-to-be-sent-to-syslog-server-asa-5520/m-p/880859#M954769</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unless it's possible to create an access rule which includes my external web server IP range and if any thing is denied/triggered then log it to critical?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 19 Feb 2008 16:33:42 GMT</pubDate>
    <dc:creator>jamesgonzo</dc:creator>
    <dc:date>2008-02-19T16:33:42Z</dc:date>
    <item>
      <title>Creating custom event lists to be sent to syslog server (ASA 5520)</title>
      <link>https://community.cisco.com/t5/network-security/creating-custom-event-lists-to-be-sent-to-syslog-server-asa-5520/m-p/880853#M954763</link>
      <description>&lt;P&gt;Hi, I'm hoping this is possible.  I need to set the syslog ID of 106023 to error level (currently warning) only for about a dozen IP addresses only (as it generates millions of logs) can I do this, I can't see a way?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:04:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/creating-custom-event-lists-to-be-sent-to-syslog-server-asa-5520/m-p/880853#M954763</guid>
      <dc:creator>whiteford</dc:creator>
      <dc:date>2019-03-11T12:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: Creating custom event lists to be sent to syslog server (ASA</title>
      <link>https://community.cisco.com/t5/network-security/creating-custom-event-lists-to-be-sent-to-syslog-server-asa-5520/m-p/880854#M954764</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nopes&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Feb 2008 14:38:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/creating-custom-event-lists-to-be-sent-to-syslog-server-asa-5520/m-p/880854#M954764</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2008-02-19T14:38:49Z</dc:date>
    </item>
    <item>
      <title>Re: Creating custom event lists to be sent to syslog server (ASA</title>
      <link>https://community.cisco.com/t5/network-security/creating-custom-event-lists-to-be-sent-to-syslog-server-asa-5520/m-p/880855#M954765</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's all or nothing then?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to basically send alerts to my syslog server when my DMZ web servers (on my ASA) have denied access to Internet users attempting to hack.  106023 ID shows this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Feb 2008 15:44:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/creating-custom-event-lists-to-be-sent-to-syslog-server-asa-5520/m-p/880855#M954765</guid>
      <dc:creator>jamesgonzo</dc:creator>
      <dc:date>2008-02-19T15:44:59Z</dc:date>
    </item>
    <item>
      <title>Re: Creating custom event lists to be sent to syslog server (ASA</title>
      <link>https://community.cisco.com/t5/network-security/creating-custom-event-lists-to-be-sent-to-syslog-server-asa-5520/m-p/880856#M954766</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you can't lower the log level to a  specific message ID for few IPs..though you may filter it on KIWI log server&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Feb 2008 16:04:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/creating-custom-event-lists-to-be-sent-to-syslog-server-asa-5520/m-p/880856#M954766</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2008-02-19T16:04:45Z</dc:date>
    </item>
    <item>
      <title>Re: Creating custom event lists to be sent to syslog server (ASA</title>
      <link>https://community.cisco.com/t5/network-security/creating-custom-event-lists-to-be-sent-to-syslog-server-asa-5520/m-p/880857#M954767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I want to basically send alerts to my syslog server when my DMZ web servers (on my ASA) have denied access to Internet users attempting to hack. 106023 ID shows this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;106023 creates to many alerts on it's own for my database I think it will fill up fast.  What a shame. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Feb 2008 16:06:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/creating-custom-event-lists-to-be-sent-to-syslog-server-asa-5520/m-p/880857#M954767</guid>
      <dc:creator>jamesgonzo</dc:creator>
      <dc:date>2008-02-19T16:06:18Z</dc:date>
    </item>
    <item>
      <title>Re: Creating custom event lists to be sent to syslog server (ASA</title>
      <link>https://community.cisco.com/t5/network-security/creating-custom-event-lists-to-be-sent-to-syslog-server-asa-5520/m-p/880858#M954768</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;do you want to report all the traffic for 106023 to KIWI..well thats possible, however as whitefor asked, you can't point logs for this message ID for few IPS...either its all traffic or none at all&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Feb 2008 16:12:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/creating-custom-event-lists-to-be-sent-to-syslog-server-asa-5520/m-p/880858#M954768</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2008-02-19T16:12:32Z</dc:date>
    </item>
    <item>
      <title>Re: Creating custom event lists to be sent to syslog server (ASA</title>
      <link>https://community.cisco.com/t5/network-security/creating-custom-event-lists-to-be-sent-to-syslog-server-asa-5520/m-p/880859#M954769</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unless it's possible to create an access rule which includes my external web server IP range and if any thing is denied/triggered then log it to critical?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Feb 2008 16:33:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/creating-custom-event-lists-to-be-sent-to-syslog-server-asa-5520/m-p/880859#M954769</guid>
      <dc:creator>jamesgonzo</dc:creator>
      <dc:date>2008-02-19T16:33:42Z</dc:date>
    </item>
  </channel>
</rss>

