07-09-2019 10:20 AM - edited 02-21-2020 09:17 AM
Is there a way to send a notification to an email or something like that when "logging host management" and/or syslog or audit server goes down?
Also, what it the actual logging server number for just when the server is unreachable or however it detects when it is down?
07-09-2019 10:30 AM
07-09-2019 12:13 PM
07-09-2019 12:40 PM
07-09-2019 06:35 PM
07-09-2019 08:19 PM
Unless you are using the non-default TCP syslog option, syslog is normally connectionless (udp/514) and the ASA has no way of knowing if the syslog messages are arriving at their destination.
If you use tcp I believe a syslog message will be created for the tcp connection itself (assuming you have informational level 6 logging level).
You should also see one of the following level 3 messages:
References:
https://www.cisco.com/c/en/us/td/docs/security/asa/syslog/b_syslog/syslogs-sev-level.html
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide