cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
628
Views
0
Helpful
4
Replies

Cisco Works 3.2 RME 4.3.1 - Botnet Traffic Filter

Tim Davies
Level 1
Level 1

Hi there

I have an ASA running the Botnet Traffic Filter, the ASA is configured to send notification syslog messages to Cisco Works RME, I can see that most syslog messages are being sent to RME however when I run a report to fillter on the botnet black listed syslog messages (338001 - 338004) these syslog events don't apear in the RME report. When I use the Real-Time Log Viewer on the ASA I can see these syslog messages are being generated.

Anyone any ideas?

Cheers

Tim

4 Replies 4

Joe Clarke
Cisco Employee
Cisco Employee

Are any syslog messages from the ASA being processed (i.e. do any messages show up in the RME Standard Report for this device)?  Post a screenshot of RME > Tools > Syslog > Message Filters.

Thanks for the reply, I have run a standard report and messages up to level 5 (Notifications) are shown.

I have attached the requested screen shot.

Thanks

Tim

I have found a work around, the issue is when logging in EMBLEM format from the ASA. I have disabled this and the Botnet Filter syslog messages now show up in RME.

Are you sure you don't mean the opposite?  RME wants EMBLEM formatted messages.  What do the messages look like now?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: