cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
314
Views
0
Helpful
2
Replies

"SGACLHIT" switches logs in SNA

Antonio Macia
Level 3
Level 3

Hi,

We are running a SDA fabric with Trustsec-based enforcement and SGT in place. Our edge nodes generate logs for all the traffic blocked by the TrustSec matrix. Those logs contain src and dst IP + port information. Is it possible to ingest those logs into SNA so we have a central log repository and can filter in a much more easier way?

Thanks.

2 Replies 2

dcavalla
Cisco Employee
Cisco Employee

Hello! If you are talking about SGACL logging: https://www.cisco.com/c/en/us/td/docs/switches/lan/cisco_ie3X00/software/17_3/b_security_17-3_iot_switch_cg/m_sgacl-logging.html, these have no bytes or packet counters. I am assuming only storage and visualization was of interest? Is that right?

Hi @dcavalla  ,

Correct. I would like to have all the trustsec logs for all our SDA edge switch stored on SNA and be capable of perform queires based on src/dst IP, port, etc. Like a regular fw log search.

Thanks,