cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
905
Views
0
Helpful
4
Replies

Hide lines in log messages with 'aaa-acl'

alina.sidorova
Level 1
Level 1

Hello!

 

Problem:

When connecting users via VPN and using the ISE as a radius server, DACLs are applied.

This generates a message to the ASA which is sent to the syslog server:

%ASA-5-111008: User 'aaa-acl' executed the 'access-list #ACSACL#***' command.

 

Is there any way to hide only messages/lines with the user "aaa-all"?

4 Replies 4

@alina.sidorova you are best off configuring a list of syslog message IDs you do want to send to the SYSLOG server.

https://www.cisco.com/c/en/us/support/docs/security/pix-500-series-security-appliances/63884-config-asa-00.html

 

Hello, Rob!

 

The problem is that I want to send messages with id 111008, but only those that don't contain aaa-acl.

@alina.sidorova possibly not that from the ASA, that message is variable.

111008

Error Message %ASA-5-111008: User user executed the command string

Explanation The user entered any command, with the exception of a show command.

Recommended Action None required.

 

https://www.cisco.com/c/en/us/td/docs/security/asa/syslog/b_syslog/syslogs1.html#con_8587071

 

Perhaps whatever SYSLOG system you have can filter messages with "aaa-acl" in?

 

This option is possible, but we are concerned about possible overload, given the large infrastructure.

 

Thanks for the answer!

Review Cisco Networking for a $25 gift card