cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
957
Views
0
Helpful
2
Replies

Output modifiers on FWSM logs

Colin Higgins
Level 2
Level 2

I am trying to search through some extensive FWSM logs from a SSH session for a specific IP address

What kind of output modifiers can I use to include or exclude IP addresses when viewing the log?

I am trying show logg I i 172.20.1.5

but it won't take it.

2 Accepted Solutions

Accepted Solutions

Julio Carvajal
VIP Alumni
VIP Alumni

Hello Colin,

what about


logging enable

logging buffer 7

Show logging | include 172.20.1.5

You should see something, if that is not showing there well that could mean the FWSM is not seeing the traffic at all

We can do a capture to confirm the traffic is getting into the FWSM,

Regards,

Julio

CSC it's a free support community take your time to rate all the engineer's responses that help you resolving your problems.

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

View solution in original post

just to add on to Julio's comments, please do ensure the logging buffer-size is big e.g. 10000

Warm regards,
Ramraj Sivagnanam Sivajanam

View solution in original post

2 Replies 2

Julio Carvajal
VIP Alumni
VIP Alumni

Hello Colin,

what about


logging enable

logging buffer 7

Show logging | include 172.20.1.5

You should see something, if that is not showing there well that could mean the FWSM is not seeing the traffic at all

We can do a capture to confirm the traffic is getting into the FWSM,

Regards,

Julio

CSC it's a free support community take your time to rate all the engineer's responses that help you resolving your problems.

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

just to add on to Julio's comments, please do ensure the logging buffer-size is big e.g. 10000

Warm regards,
Ramraj Sivagnanam Sivajanam
Review Cisco Networking for a $25 gift card