cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
931
Views
2
Helpful
5
Replies

ASA Syslog not working

jf1134
Level 1
Level 1

I'm trying to setup Syslog so that I can see everyone that is logging into AnyConnect. I've set it up but we are not seeing any logs on the Syslog server. It shows that there are a couple in the queue. For the events list and message IDs I have 716001, 734001, 113038, 113039 and 722041-722051. 

Here's what the config shows for show logging
Syslog logging: enabled
Facility: 20
Timestamp logging: enabled
Timezone: enabled
Hide Username logging: disabled
Standby logging: disabled
Debug-trace logging: disabled
Console logging: disabled
Monitor logging: disabled
Buffer logging: disabled
Trap logging: list AnyConnect-Logins, class auth, facility 20, 3202281 messages logged
Logging to Internet 172.16.10.23, UDP TX:8856 errors: 7857 dropped: 23647
Global TCP syslog stats::
NOT_PUTABLE: 0, ALL_CHANNEL_DOWN: 0
CHANNEL_FLAP_CNT: 0, SYSLOG_PKT_LOSS: 0
PARTIAL_REWRITE_CNT: 0
Permit-hostdown logging: disabled
History logging: disabled
Device ID: disabled
Mail logging: disabled
ASDM logging: level informational, 12035854 messages logged

1 Accepted Solution
5 Replies 5

check below comment

Thanks. 

So would I just do logging monitor informational so that I can get the anyconnect login messages

Check below 

Ok thanks. So I added these and then logged into Anyconnect and did show logging queue and saw 1 message pop up in the queue and then it went away. It seem to be working now

AnyConnect(config)# logging list VPN-User message 746012
AnyConnect(config)# logging list VPN-User message 722051
AnyConnect(config)# logging list VPN-User message 746013
AnyConnect(config)# logging list VPN-User message 113019
AnyConnect(config)# logging list VPN-User-Login message 716001

Review Cisco Networking for a $25 gift card