Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Cisco ASA and syslog severity levels

$
0
0

There are some messages only logged at higher levels (max = 7) that CAN be useful, so based on experience with a lot of customers that's where the initial recommendation got set. Starting at one step down (6) will get you almost everything and I think if you back down from there, you'll get less and less. (Cisco ASA 5500 Series Configuration Guide using the CLI, 8.2 - Configuring Logging [Cisco ASA 5500-X Series Firewalls] -…)

 

If you're looking at the message reference, the severity # is indicated in the log message - e.g. ASA-6-XXXXX - so you could spot check for those messages you know are most useful and work back from that. If there's nothing in severity 6 that is useful except for a single message, you can also adjust/promote the severity of a message.For example, if level 5 looks good but you really need ASA-6-123456, you can change 123456 to a 5 and leave your syslog levels at 5 (Cisco ASA 5500 Series Configuration Guide using the CLI, 8.2 - Configuring Logging [Cisco ASA 5500-X Series Firewalls] -… )

 

Good place to start would be syslog messages by severity: Cisco ASA Series Syslog Messages - Cisco


Viewing all articles
Browse latest Browse all 5385

Trending Articles