cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1720
Views
0
Helpful
1
Replies

ASA5505 how to record the traffic log

aizuodream1
Level 1
Level 1

Hello, everyone,

I want to analysis the log from asa5505,

I have configured the device to send the log to a syslog server.

but I found the log seems like event log, it's format like below :

6|Nov 11 2010|18:07:33|302014|192.168.2.22|192.168.1.2|Teardown TCP connection 986 for outside:218.30.82.201/80 to inside:192.168.1.2/1764 duration 0:10:01 bytes 619 FIN Timeout

I want to obtain the traffic log, it may contains each connection record  information, including send bytes and receive bytes,  URL and so on...

but I can't find out how to setup the device to let the asa5505 record the traffic log,

someone can give some tips, thanks in advanced.

1 Reply 1

garapoglou
Level 3
Level 3

Hi,

You need to enable the Netflow protocol.

Here are two documents related to Netflow for Cisco ASA:

https://supportforums.cisco.com/docs/DOC-6114

https://supportforums.cisco.com/docs/DOC-6113

Best regards,

Giorgos

Review Cisco Networking for a $25 gift card