cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
393
Views
0
Helpful
1
Replies

Analyzing threat-detection - who did what when?!

pdub206
Level 1
Level 1

Hi,

I'm trying to identify who is the source of several 733100 messages in my syslogs on an ASA 5520.  I have the following threat-detection configurations enabled:

 

threat-detection basic-threat
threat-detection statistics
threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200
  subscribe-to-alert-group threat

However, when the 733100 syslogs come in, they do not say the source or destination ip address.  I am able to look at the statistics for each of these detected threats, but I am not sure how to correlate the syslog message to a host in the list.  For example,

Apr 16 2015 10:44:05 ASA-1 : %ASA-4-733100: [ Scanning] drop rate-1 exceeded. Current burst rate is 18 per second, max configured rate is 10; Current average rate is 38 per second, max configured rate is 5; Cumulative total count is 23268

I then issue the following:

show threat-detection statistics top rate-1

And I see several hosts, but there doesn't seem to be an easy way to say "syslog @ 10:44:05 was host 8.8.8.8" (or whatever the source would be).  Is there a document that helped you figure this out? Any advice?

We don't want to shun any hosts, but we do want to know who is doing what and when, so we can talk to the internal user and tell them to stop.

 

Throwing packets since 2012
1 Accepted Solution

Accepted Solutions

Vibhor Amrodia
Cisco Employee
Cisco Employee

Hi,

I don't think you would be able to get more information from these syslog.

As you have Statistics Threat Detection enabled , I would recommend enabling other commands and then you would be able to find out more information on them.

Refer:-

http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113685-asa-threat-detection.html

These command you would be able to use:-

show threat-detection statistics host
show threat-detection statistics port
show threat-detection statistics protocol
show threat-detection statistics top


Also , ASDM graphs would be helpful.

http://www.cisco.com/c/en/us/td/docs/security/asa/asa80/asdm60/user/guide/usrguide/intro.html#wp1044840

Thanks and Regards,

Vibhor Amrodia

View solution in original post

1 Reply 1

Vibhor Amrodia
Cisco Employee
Cisco Employee

Hi,

I don't think you would be able to get more information from these syslog.

As you have Statistics Threat Detection enabled , I would recommend enabling other commands and then you would be able to find out more information on them.

Refer:-

http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113685-asa-threat-detection.html

These command you would be able to use:-

show threat-detection statistics host
show threat-detection statistics port
show threat-detection statistics protocol
show threat-detection statistics top


Also , ASDM graphs would be helpful.

http://www.cisco.com/c/en/us/td/docs/security/asa/asa80/asdm60/user/guide/usrguide/intro.html#wp1044840

Thanks and Regards,

Vibhor Amrodia

Review Cisco Networking for a $25 gift card