02-16-2022 08:56 PM
Hello,
We are trying to send Cisco ASA logs to Azure Sentinel. In Cisco ASA firewall logging level is set to 7 Debugging and Azure Sentinel couldn't process/read the logs hence Sentinel team is asking to change the logging level to 4 or 6... I would like to understand if I change the logging level to 4 will i lose potential information.
As best practice which logging level should be maintained in Cisco ASA. ?
02-17-2022 12:23 AM - edited 02-17-2022 12:40 AM
Sentinel is right you cant have 7 debugging. your best option is 4 or 6. In normal SIEM solution you enable the 4 or 6 logging to sent over to SIEMs.
As best practice which logging level should be maintained in Cisco ASA. ?
what you can do is enable the buffered-size debug 7 this will create a buffer here in flash order to keep your log when you want to view them this will not impact your ASA performance.
here this will help you what you can do to keep the Advance logs.
02-20-2022 04:17 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide