02-01-2020 01:47 AM
HI Expert,
I have a query regarding syslog message. In my cisco ASA firewall 5585X (9.1) remote syslog server ip is configured. Regular basis syslog logs received by syslog server from ASA firewall aroung 3Lakh logs (level 6) per day but suddenly syslog msg count is increase to aroung 20 Lakh per day. Please guide how to troubleshoot the issue. And what are the common cause for this type of error.
Regards,
RB
02-01-2020 02:58 AM
Hi,
First step would be see if you the logging level for syslog (trap logging) has been changed (informational to debugging )
Secondly, any new ACLs implemented with log keyword (for which lot of hits are there)
Thirdly, check the syslog server to find any newer kind of logs you have started observing.
HTH
02-01-2020 03:55 AM
HI HTH,
Thakns for your reply.
I have checked step 1 and 2, both settings are looks good. Now i am waiting for all logs from the SOC team for troubleshooting.
One more query, is there any command for checking the count of syslog logs send to the remote syslog server in one day.
Regards,
RB
02-01-2020 07:24 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide