cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
462
Views
0
Helpful
2
Replies

ACL with "log" set is not appearing on Syslog server

jwilliams
Level 1
Level 1

I created a deny ACL that we would like to track on our Syslog server. I entered the "Log" option and set it to level 3.

I set "logging trap 3" and my syslog server is receiving messages. However the message from my ACL does not appear.

If I turn on Term Mon, I can see the message appear as ASA-3-106100, but that message never shows up on my server.

Anyone have any thoughts why this message is not being sent?

Thanks.

2 Replies 2

whisperwind
Level 1
Level 1

Perhaps some config of the relevant logging andthe output of a sh log command.

Is your syslog server getting any messages or is just ths one that is never arriving?

The syslog server is getting plenty of other messages from this ASA, it's just this one that won't come through if I mess with the severity level.

If I leave it at its default, which is level 4/warnings, it comes through. However, I don't want to log warnings, that's why I was trying to elevate this one ACL message.

Thanks.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: