ASA- Can I send differnet level log messages to two different sysl
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-08-2009 11:30 AM - edited 03-11-2019 08:53 AM
I have an ASA running 8.0(3). I have two syslog servers defined. Is there a way to send two different level messages to two different syslog servers? I see the "logging class"/"logging list" commands to alter differnet level messages to seperate output devices, a.k.a. TRAP; however, if I have two different host addresses (syslog servers) defined, can I send different levels to each, even though they are a subset of the same "output device"?
THANKS!
- Labels:
-
NGFW Firewalls
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-08-2009 11:54 AM
Hi Michael,
As far as I know, this cannot be done. According to the documentation for 'logging host':
"You can use multiple logging host commands to specify additional servers that would all receive the system log messages."
http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/l2.html#wp1751719
Hope that helps.
-Mike
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-08-2009 12:00 PM
Mike,
Thanks for replying. I ended up allowing setting my trap level to the most common "severe" level- in this case "4" for warnings. Then I created a "logging list" to allow the specified informational level messages to also be included. (The only undesired affect is that I send both syslog servers see the specific informational messages). But this way they both see the messages they NEED to see without hammering them with tons of notification messages.
