Cisco Systems Re: Viewing Cisco ACL logs

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Re: Viewing Cisco ACL logs BernieM 08-29-06
Posted by BernieM on August 29, 2006, 3:10 am
Please log in for more thread options

> On 28 Aug 2006, K.J. 44 wrote:
>
>> Where do I view my router's ACL logs? Is there a way to write a script
>> to have them sent to a network location (like a directory on my file
>> server) so i can view them?
>>
>> Thanks.
>>
> You can have your router forward the log messages to a syslog server.
> Use 'logging <ip-adddress>'
>
> Doan
>

and to the same location if it's a syslog server using

"logging facility syslog"

BernieM



Posted by BernieM on August 29, 2006, 3:11 am
Please log in for more thread options

>
>> On 28 Aug 2006, K.J. 44 wrote:
>>
>>> Where do I view my router's ACL logs? Is there a way to write a script
>>> to have them sent to a network location (like a directory on my file
>>> server) so i can view them?
>>>
>>> Thanks.
>>>
>> You can have your router forward the log messages to a syslog server.
>> Use 'logging <ip-adddress>'
>>
>> Doan
>>
>
> and to the same location if it's a syslog server using
>
> "logging facility syslog"
>
> BernieM
>

what I meant to add was that Doan's example sends snmp-traps.



Posted by BernieM on August 29, 2006, 3:50 am
Please log in for more thread options

>
>>
>>> On 28 Aug 2006, K.J. 44 wrote:
>>>
>>>> Where do I view my router's ACL logs? Is there a way to write a script
>>>> to have them sent to a network location (like a directory on my file
>>>> server) so i can view them?
>>>>
>>>> Thanks.
>>>>
>>> You can have your router forward the log messages to a syslog server.
>>> Use 'logging <ip-adddress>'
>>>
>>> Doan
>>>
>>
>> and to the same location if it's a syslog server using
>>
>> "logging facility syslog"
>>
>> BernieM
>>
>
> what I meant to add was that Doan's example sends snmp-traps.
>

I was wrong. I now don't understand exactly what "logging facility syslog"
actually does.

BernieM



Posted by on August 29, 2006, 8:45 am
Please log in for more thread options

BernieM wrote:
> >
> >>
> >>> On 28 Aug 2006, K.J. 44 wrote:
> >>>
> >>>> Where do I view my router's ACL logs? Is there a way to write a script
> >>>> to have them sent to a network location (like a directory on my file
> >>>> server) so i can view them?
> >>>>
> >>>> Thanks.
> >>>>
> >>> You can have your router forward the log messages to a syslog server.
> >>> Use 'logging <ip-adddress>'
> >>>
> >>> Doan
> >>>
> >>
> >> and to the same location if it's a syslog server using
> >>
> >> "logging facility syslog"
> >>
> >> BernieM
> >>
> >
> > what I meant to add was that Doan's example sends snmp-traps.
> >
>
> I was wrong. I now don't understand exactly what "logging facility syslog"
> actually does.

Damn, I was getting excited there, I though that I
was going to find out something.


Back to the original question

>From reading cco :-

snmp-server enable traps syslog
- enable the transmission of snmp traps of syslog messages

Then you can set the level of events that are sent with

logg history [level]

Presumably if "log history level" is greater than "logg trap level"
then since the messages have not been through syslog they won't
get to the snmp server? Who knows?

Configuring System Message Logging
http://www.cisco.com/en/US/products/hw/switches/ps5213/products_configuration_guide_chapter09186a00801ce00c.html


http://www.cisco.com/en/US/tech/tk648/tk362/technologies_tech_note09186a008021de3e.shtml
The Traps Sent with SNMP-Server Enabled Traps Configured


Similar ThreadsPosted
Re: Viewing Cisco ACL logs August 29, 2006, 3:10 am
Viewing Cisco ACL logs August 28, 2006, 5:58 pm
Logs button not opening Logs GUI June 29, 2009, 6:44 am
cisco 4900 shows right time but not in sh logs August 18, 2009, 9:48 am
Viewing and filtering a router log for GET/ January 3, 2006, 1:50 pm
Viewing content flash on PIX. June 17, 2005, 2:50 pm
PIX 515 Command for viewing realtime connections February 3, 2006, 11:24 pm
pix logs May 16, 2006, 6:07 am
PIX, two weird logs September 8, 2005, 8:48 am
Help on security logs December 20, 2005, 11:22 am
Router logs March 21, 2006, 2:58 pm
KIWI logs September 18, 2009, 10:41 am
IOS and Rommon updates - change logs? March 19, 2006, 10:00 am
Apache server behind PIX logs all incoming IPs as 0.0.0.0. April 20, 2007, 10:52 am
NEWBIE- 800 Series / Soho 97 firewall logs - how do i see them? February 11, 2005, 12:54 am
Residential Cabling Guide

Home Cabling Guide

Finally, an instantly downloadable book that saves you thousands in home improvement dollars! Enjoy living in 21st century technology-advanced home while increasing its selling value and competitive advantage on the real estate market. Whether your cabling is for home office or high-tech leisure, you can wire your home yourself or learn "wirish" to speak with your cabling contractors in their language!

Learn More