cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
760
Views
6
Helpful
3
Replies

RSyslog cannot parse timestamps from ASA Syslog

We use Rsyslog and LogAnalyzer as our Syslog collector. All our routers/switches/firewalls send Syslogs to Rsyslog. We would like timestamps in the log payload and this works fine for routers and switches, but Rsyslog cannot recognise the timestamp of the logs sent by Cisco ASA.

Here's the difference

Router

Router logs with timestamps.png

Firewall

Firewall logs without timestamps.png

Using packet captures, we can see that the firewall is indeed sending timestamps in the UDP message, but the format is different from the router and that may explain why Rsyslog is not able to parse it.

Is this known behaviour? Any way to get the firewall to send the timestamps in the same format as the router?

1 Accepted Solution

Accepted Solutions

Yes, applying the command enables timestamps in the pcap, but they are still not recognisable by Rsyslog. The solution was to add "format emblem" at the end of each syslog host. Now the timestamps are recognisable by Rsyslog.

Emblem.PNG

 

View solution in original post

3 Replies 3

Did you apply the "logging timestamp" command on the ASA?

Yes, applying the command enables timestamps in the pcap, but they are still not recognisable by Rsyslog. The solution was to add "format emblem" at the end of each syslog host. Now the timestamps are recognisable by Rsyslog.

Emblem.PNG

 

Thanks for update us and share solution.

Review Cisco Networking for a $25 gift card