11-12-2013 11:40 PM - edited 03-11-2019 08:04 PM
Hi ,
I have setup syslog server for my ASA 5520 logs. For ASDM and syslog server it is set from Informational level. But in my syslog server I am not able to find the "login details like which user access ASA on what time " etc. Is there any additional set up need to be done on the ASA ?
Thanks and regards
Deepak MK
11-18-2013 08:12 PM
HI Jumora,
From the debugging I cant see that , Because setting is to go to SYSLOG server. Real time I am Unable to see it. May be I need to see it on logs after couple of days.
I could have logged a case with Cisco TAC but the issue is the support contract already expired.
I have inserted the image of the logging settings for your review.
11-18-2013 08:16 PM
what version are you at on the ASA
11-18-2013 09:51 PM
8.0(4)
11-18-2013 10:27 PM
This are the kind of logs you should look for:
%ASA-7-609001: Built local-host identity:1.1.1.2
%ASA-6-302013: Built inbound TCP connection 5 for inside:1.1.1.1/57227 (1.1.1.1/57227) to identity:1.1.1.2/23 (1.1.1.2/23)
%ASA-6-113012: AAA user authentication Successful : local database : user = cisco
%ASA-6-113008: AAA transaction status ACCEPT : user = cisco
%ASA-6-611101: User authentication succeeded: Uname: cisco
%ASA-6-605005: Login permitted from 1.1.1.1/57227 to inside:1.1.1.2/telnet for user "cisco"
I know you are not trying to make this happen locally but in a Syslog server with a Syslog trap but what happens if you do it locally?? Do u see those logs?
Rate all of the helpful posts!!!
Regards,
Jcarvaja
Follow me on http://laguiadelnetworking.com
11-19-2013 12:06 AM
The ASDM is set to log informational too. You could go to Monitor > Logging in the ASDM and click View and you should be able to see real time logs there.
The account is local. I also not able to find any where in the ASA 5520 , how to change the username as well.
To change or add a user account in ASDM go to Configuration > Device Management and there should be a selection called AAA / users or similar on the left side pane.
11-19-2013 03:22 PM
I did not check are you logging over UDP or TCP???
11-19-2013 06:26 PM
The real time monitoring is also not getting the login information. Also the user I can add but there is no option to rename it. I will be away to another site for next 2 weeks . So I might not be able to make necessary change. So is this discussion thread need to be closed ?
11-19-2013 11:25 PM
That is correct, you can not rename a user. If you want to give a user a different name you would need to remove the local user account and then add it back with a different username.
Please rate and close this discussion and open a new one when you are able to continue with the troubleshooting.
Regards,
11-20-2013 09:00 AM
I think I never saw your configuration so it might be that have a command that disables the log message.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide