06-21-2023 07:01 AM
I'm trying to setup Syslog so that I can see everyone that is logging into AnyConnect. I've set it up but we are not seeing any logs on the Syslog server. It shows that there are a couple in the queue. For the events list and message IDs I have 716001, 734001, 113038, 113039 and 722041-722051.
Here's what the config shows for show logging
Syslog logging: enabled
Facility: 20
Timestamp logging: enabled
Timezone: enabled
Hide Username logging: disabled
Standby logging: disabled
Debug-trace logging: disabled
Console logging: disabled
Monitor logging: disabled
Buffer logging: disabled
Trap logging: list AnyConnect-Logins, class auth, facility 20, 3202281 messages logged
Logging to Internet 172.16.10.23, UDP TX:8856 errors: 7857 dropped: 23647
Global TCP syslog stats::
NOT_PUTABLE: 0, ALL_CHANNEL_DOWN: 0
CHANNEL_FLAP_CNT: 0, SYSLOG_PKT_LOSS: 0
PARTIAL_REWRITE_CNT: 0
Permit-hostdown logging: disabled
History logging: disabled
Device ID: disabled
Mail logging: disabled
ASDM logging: level informational, 12035854 messages logged
Solved! Go to Solution.
06-21-2023 08:02 AM
https://community.cisco.com/t5/vpn/how-to-log-anyconnect-sessions-in-syslog/td-p/2928030
in this post best answer ever
Thanks
MHM
06-21-2023 07:16 AM - edited 06-21-2023 07:32 AM
check below comment
06-21-2023 07:29 AM
Thanks.
So would I just do logging monitor informational so that I can get the anyconnect login messages
06-21-2023 07:43 AM - edited 06-21-2023 08:03 AM
Check below
06-21-2023 08:02 AM
https://community.cisco.com/t5/vpn/how-to-log-anyconnect-sessions-in-syslog/td-p/2928030
in this post best answer ever
Thanks
MHM
06-21-2023 09:34 AM
Ok thanks. So I added these and then logged into Anyconnect and did show logging queue and saw 1 message pop up in the queue and then it went away. It seem to be working now
AnyConnect(config)# logging list VPN-User message 746012
AnyConnect(config)# logging list VPN-User message 722051
AnyConnect(config)# logging list VPN-User message 746013
AnyConnect(config)# logging list VPN-User message 113019
AnyConnect(config)# logging list VPN-User-Login message 716001
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: