Logging login events

Jun 24, 2005 4 Replies

I have a PIX 515 running 6.3(3) and sending events to a remote syslog server. I am trying to setup a log monitor (SEC) on my syslog host and would like to watch the PIX entries for login attempts and any time a configuration is changed (using write memory). However, no matter what level I set my logging trap to, I don't see any events for those cases in my syslog stream. I saw some sample configs for SEC that watch for those events, so that suggests that it should be do-able, but I just can't find out how.



Any ideas?



Thanks in advance Steve



logging on logging timestamp logging trap debugging logging history errors logging queue 0 logging host inside 10.42.52.15 logging host inside 10.76.0.250

works for me, of course you have to have the syslog server setup to receive, but it sounds like you have that part

regards,

-charlie

snipped-for-privacy@yahoo.com wrote:

Thanks charlie,

Turns out that my issue was that I wasn't running my logging trap in debug level. Unfortunately, I really don't want to run a production system in debug just to get login details. Bummer - hopefully cisco will recognize that login tracking is more important for things than just debugging and change that in the future.

Cheers. Steve

In article , wrote: :Turns out that my issue was that I wasn't running my logging trap in :debug level. Unfortunately, I really don't want to run a production :system in debug just to get login details. Bummer - hopefully cisco :will recognize that login tracking is more important for things than :just debugging and change that in the future.

Note the newish 'level' keyword:

formatting link

Hi Steve,

You might want to look into setting up AAA on your PIX. Using RADIUS (or TACACS if you're inclined) and AAA Authorization you can get login attempts and even track each command entered. There are quite a few freeware RADIUS suites available or you could try TAC+ (freeware TACACS).

TACACS vs. RADIUS:

formatting link
Old but still good document > Thanks charlie,

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required