cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
998
Views
0
Helpful
1
Replies

Show logs generated by a rule

dgoswick
Level 1
Level 1

While using ASDM 5.2 for our PIX's and FWSM, I noticed that within the Access Rules, under Security Policy, right clicking on the Access Rule brought up the option to 'Show Log'. The pop up description of this function says "Show logs generated by this rule". If I click on it, it opens the Real-time Log Viewer with the ACL's unique identifier in the filter. It looks something like, '0x3ffd520f'. However, none of the events contain this identifier. This would be useful if we could turn it on. How do we include this identifier in our logs?

Many thanks.

1 Reply 1

ben.posner
Level 1
Level 1

I was confused by this as well but figured it out after some tinkering. the real-time log viewer isn't brining up a history, it's bringing up a viewer for any NEW hits for that particular rule. Try it with something like a rule for RDP and then initiate a connection and it should show in the window.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: