cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
415
Views
0
Helpful
1
Replies

Optimum levels for Logging?

ksarin123_2
Level 1
Level 1

Hello folks -

We have an ASA 5510 and a 5520 that are at the perimeter of our network. 5510 is the f/w and the 5520 is the VPN concentrator. I have configured both these hosts to send syslog messages to a Syslog server. I am logging at the warning level and above for both these devices. However, I am receiving almost like 5K-6K messages per hour from each one of these devices.

With such a high rate of logging, can I optimally configure logging to get the useful information I need from the logs?

Any strategy or best practices for logging would be appreciated!!

Thanks!

1 Reply 1

John Blakley
VIP Alumni
VIP Alumni

Well, you can filter your messages by doing a:

no logging message

This won't keep that message from being logged in the ASA, but it will keep it from being logged to the syslog. Then you can filter on your syslog on what you need.

HTH,

John

HTH, John *** Please rate all useful posts ***
Review Cisco Networking for a $25 gift card