Cisco ASA Syslog Messages

We recently purchased a piece of software that is going to inspect our syslog log files and alert us based on specific queries. The software however was not written to read Cisco syslog specifically so we have to define pretty tightly what we want to alert on. I have been reviewing the documentation regarding the ASA/PIX syslog format and it seems helpful except there are so many damn messages and message types.

Does anyone have any suggestions regarding what things to specifically look for in the logs. I know this is a very vague question and I know a lot of it is based on the position and functionality of our ASAs, but what I am really more looking for perhaps are some guidelines or perhaps a sample of what others are doing. Perhaps there is some documentation other than the massive list of all messages that might lend some guidance?

The problem in theory of course is that I can look through our current logs and identify items to be alerted against, but how does one anticipate what is going to be in the logs when an actual security attack/emergency occurs.

Any help is greatly appreciated.

Reply to
phir0002
Loading thread data ...

take a look at some of the PIX syslog tools at

formatting link

Reply to
Merv

I'm still trying to get my syslog to log ssh attempts and i have everything on debug and i still dont see these attempts in syslog. :- ( what software are you using?

GNY

Reply to
Lenny

We are using a product called EventTracker. It has a Cisco syslog feature built in but the licensing for it was additional to the standard license and the bosses did not want to shell out the cash. So instead we are trying to use the flat file read feature of the software to read the Kiwi syslog file and alert against adverse messages within.

Reply to
phir0002

Thanks for the link, although some of those tools appear to be helpful, I have been tasked with making the software we already have work, which is why I am soliciting examples for configuration or perhaps sample policies.

Thanks again though.

Reply to
phir0002

Hi,

Perhaps it will be interesting. You can try Syslog Watcher by SnmpSoft (

formatting link
). It can interpret messages from Cisco IOS and CatOS devices (if you install Vendor Pack addon). Vendor has promised to add support for ASA/PIX soon.

/Edward

Reply to
edward.petercon

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.