Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

ASA - Syslog Message List by Event Class?

Hey gang:

I'm updating my logging lists and would like to know if there is a list of syslog messages by event class (I found the list by severity level).  If not, is there some way to identify the class by looking at the syslog message number?

Thanks.

Everyone's tags (4)
1 ACCEPTED SOLUTION

Accepted Solutions
Cisco Employee

Re: ASA - Syslog Message List by Event Class?

Here is the list of syslog messages by event class for your reference:

http://www.cisco.com/en/US/docs/security/asa/asa80/system/message/logmsgs.html#wp4768518

Hope that helps.

7 REPLIES
Cisco Employee

Re: ASA - Syslog Message List by Event Class?

Hello,

Here is a Cisco document on some of the built in logging classes.

http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/l2.html

#wp1749568

Hope this helps.

Regards,

NT

Community Member

Re: ASA - Syslog Message List by Event Class?

Unfortunately that doesn't really show us, for example, what class messsage ID# 730010 would fall under.  That's what I'm after.

Cisco Employee

Re: ASA - Syslog Message List by Event Class?

Hello,

Unfortunately, there does not seem to be any specific classification of

those individual message types. Typically you configure the message classes

based on your requirement i.e. if you are interested in seeing VPN related

messages, then you use "VPN" class and set appropriate severity. Here is a

document that outlines some additional information about the syslog

messages.

http://www.cisco.com/en/US/docs/security/asa/asa82/system/message/logsevp.ht

ml

Hope this helps.

Regards,

NT

Community Member

Re: ASA - Syslog Message List by Event Class?

Thanks for the replies.

I understand typical usage, but what if you don't know what class an individual message would fall under?  I can make a good guess at most, but I'd rather be certain.  This is what I cannot find in the Cisco documentation nor in 3rd party published material.

Another example:  I want to receieve emails for threat detection messages (733100 - 733105).  Because I'm not sure what class these are in (I'd guess IPS) I have to add them individually to my email logging list.  It'd be a heck of a lot easier to add the entire class that they belong to.

Cisco Employee

Re: ASA - Syslog Message List by Event Class?

Here is the list of syslog messages by event class for your reference:

http://www.cisco.com/en/US/docs/security/asa/asa80/system/message/logmsgs.html#wp4768518

Hope that helps.

Community Member

Re: ASA - Syslog Message List by Event Class?

I wish ASAs had some tool to filter syslog messages based on user defined patterns like logging discriminator or ESM in Cisco IOS.

Community Member

Re: ASA - Syslog Message List by Event Class?

Thanks, halijenn!  I totally skipped past that part when I was looking at the messages by severity.  d'oh! 

12982
Views
8
Helpful
7
Replies
CreatePlease to create content