cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2105
Views
5
Helpful
4
Replies

ASA5508 - Syslog ID 106100 not logging in remote server

BtkMan
Level 1
Level 1

Hello all,

 

I'm a beginner in firewall devices, and I hope you can assist me on this issue.

 

As you can see below, we have setup logging on both ASDM and a remote syslog server.

If I view in ASDM, I see that syslog ID 106100 is logging, along with other events.

 

However on the syslog server (a Loglogic appliance), syslog ID 106100 is not saved.

Only SIDs 733100 and 111007 are there. Is there something missing or incorrect in the config?

 

A handful of our devices are affected by this issue.

 

Thanks in advance!

 

FIREWALL # show run all logging
logging enable
logging hide username
logging buffer-size 4096
logging asdm-buffer-size 100
logging trap notifications
logging asdm debugging
logging host <INTERFACE> <IP>
logging flash-minimum-free 3076
logging flash-maximum-allocation 1024
no logging message 325007
logging message 302015 level debugging
logging message 302014 level debugging
logging message 302013 level debugging
logging message 304001 level debugging
logging message 302016 level debugging
logging rate-limit 1 10 message 779001
logging rate-limit 25 1 message 805001
logging rate-limit 1 10 message 801001
logging rate-limit 25 1 message 805002
logging rate-limit 1 10 message 801002
logging rate-limit 25 1 message 805003
logging rate-limit 1 10 message 801003
logging rate-limit 1 10 message 747001
logging rate-limit 1 1 message 402116
logging rate-limit 1 10 message 620002
logging rate-limit 100 1 message 802005
logging rate-limit 10 1 message 802006
logging rate-limit 1 3600 message 770003
logging rate-limit 1 10 message 717015
logging rate-limit 1 10 message 717018
logging rate-limit 1 10 message 201013
logging rate-limit 1 10 message 201012
logging rate-limit 1 1 message 313009
logging rate-limit 100 1 message 750003
logging rate-limit 100 1 message 750002
logging rate-limit 100 1 message 750004
logging rate-limit 1 10 message 419003
logging rate-limit 1 60 message 751027
logging rate-limit 1 10 message 405002
logging rate-limit 1 10 message 405003
logging rate-limit 1 10 message 421007
logging rate-limit 1 10 message 405001
logging rate-limit 1 10 message 421001
logging rate-limit 1 10 message 421002
logging rate-limit 1 10 message 434007
logging rate-limit 1 10 message 325007
logging rate-limit 1 60 message 199020
logging rate-limit 2 5 message 199011
logging rate-limit 1 10 message 199010
logging rate-limit 2 5 message 199012
logging rate-limit 1 10 message 710002
logging rate-limit 100 1 message 753001
logging rate-limit 1 10 message 209003
logging rate-limit 1 10 message 209004
logging rate-limit 1 10 message 209005
logging rate-limit 1 10 message 778008
logging rate-limit 1 10 message 778007
logging rate-limit 1 10 message 778006
logging rate-limit 1 10 message 431002
logging rate-limit 1 10 message 778005
logging rate-limit 1 10 message 431001
logging rate-limit 1 10 message 778004
logging rate-limit 1 1 message 447001
logging rate-limit 1 10 message 778003
logging rate-limit 1 10 message 778002
logging rate-limit 1 10 message 778001
logging rate-limit 1 100 message 110004
logging rate-limit 1 10 message 110003
logging rate-limit 1 10 message 110002
logging rate-limit 1 10 message 429007
logging rate-limit 1 10 message 216004
logging rate-limit 25 1 message 618001
logging rate-limit 1 10 message 450001
logging rate-limit 1 10 message 450002

 

FIREWALL # show ver

Cisco Adaptive Security Appliance Software Version 9.9(2)
Firepower Extensible Operating System Version 2.3(1.84)
Device Manager Version 7.9(2)152

 

Compiled on Sun 25-Mar-18 17:29 PDT by builders
System image file is "xxxxxxx"
Config file at boot was "startup-config"

FIREWALL up 82 days 1 hour

Hardware: ASA5508, 8192 MB RAM, CPU Atom C2000 series 2000 MHz, 1 CPU (8 cores)
Internal ATA Compact Flash, 8000MB
BIOS Flash xxxxxxxx

4 Replies 4

Seb Rupik
VIP Alumni
VIP Alumni

Hi there,

What is the output of sh logging

 

cheers,

Seb.

Seb Rupik
VIP Alumni
VIP Alumni

Actually you are sending syslog traps a level 5 (notification), but the log entry you want to see is level 6 (informational):

https://www.cisco.com/c/en/us/td/docs/security/asa/syslog/b_syslog/syslogs1.html#con_4769049

 

Change the config to:

!
logging trap informational
!

cheers,

Seb.

All other devices we have are on level 5, and most of them are working. Weird.
I will test and let you know how it turns out. Thanks, Seb.

That did not work. :(
Checking the logs, the 106100 was set for severity level 5, so that should have logged the messages.

What *did* work, however, was when I removed the 'logging host' and 'logging trap' commands, and re-issued them again.

I guess it sort of reset the connection to the appliance. :/

Thanks, Seb.
Review Cisco Networking for a $25 gift card