cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6149
Views
0
Helpful
23
Replies

Why ASA is not sending admin logs to the syslog server

Seeker369
Level 1
Level 1

Hi ,

I have setup syslog server for my ASA 5520 logs. For ASDM and syslog server it is set from Informational level. But in my syslog server I am not able to find the "login details like which user access ASA on what time " etc. Is there any additional set up need to be done on the ASA ?

Thanks and regards

Deepak MK

23 Replies 23

HI Jumora,

From the debugging I cant see that , Because setting is to go to SYSLOG server. Real time I am Unable to see it. May be I  need to see it on logs after couple of days.

I could have logged a case with Cisco TAC but the issue is the support contract already expired.

I have inserted the image of the logging settings for your review.

what version are you at on the ASA

Value our effort and rate the assistance!

8.0(4)

This are the kind of logs you should look for:

%ASA-7-609001: Built local-host identity:1.1.1.2

%ASA-6-302013: Built inbound TCP connection 5 for inside:1.1.1.1/57227 (1.1.1.1/57227) to identity:1.1.1.2/23 (1.1.1.2/23)

%ASA-6-113012: AAA user authentication Successful : local database : user = cisco

%ASA-6-113008: AAA transaction status ACCEPT : user = cisco

%ASA-6-611101: User authentication succeeded: Uname: cisco

%ASA-6-605005: Login permitted from 1.1.1.1/57227 to inside:1.1.1.2/telnet for user "cisco"

I know you are not trying to make this happen locally but in a Syslog server with a Syslog trap but what happens if you do it locally?? Do u see those logs?

Rate all of the helpful posts!!!

Regards,

Jcarvaja

Follow me on http://laguiadelnetworking.com

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

The ASDM is set to log informational too.  You could go to Monitor > Logging in the ASDM and click View and you should be able to see real time logs there.

The account is local. I also not able to find any where in the ASA 5520 , how to change the username as well.

To change or add a user account in ASDM go to Configuration > Device Management and there should be a selection called AAA / users or similar on the left side pane.

--
Please remember to select a correct answer and rate helpful posts

I did not check are you logging over UDP or TCP???

Value our effort and rate the assistance!

The real time monitoring is also not getting the login information. Also the user I can add but there is no option to rename it. I will be away to another site for next 2 weeks . So I might not be able to make necessary change. So is this discussion thread need to be closed ?

That is correct, you can not rename a user.  If you want to give a user a different name you would need to remove the local user account and then add it back with a different username.

Please rate and close this discussion and open a new one when you are able to continue with the troubleshooting.

Regards,

--
Please remember to select a correct answer and rate helpful posts

I think I never saw your configuration so it might be that have a command that disables the log message.

Value our effort and rate the assistance!
Review Cisco Networking for a $25 gift card