My log buffer is 300000 bytes and would like to know a good configuration so I can see logs from previous days (at least a week ago) however the problem is there is a lot of log events due to denied ACL hits. Anyone have a good reccomendation?
Hi
Unfortunately I think that is not possible unless you have a Syslog server or a Cisco ACS where the events are stored.
You'll need a seperate syslog server to do this.
Hi,
That info could be seen through the logging commands, also I always suggest configure the following commands on the devices to know who is configuring and what:
archive
log config
logging enable
logging size 300
notify syslog contenttype plaintext
hidekeys