cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1192
Views
0
Helpful
1
Replies

PIX/ASA disable "name" lookup in syslog.

ckeladis
Level 1
Level 1

Is it possible to disable "name" lookups for PIX/ASA syslogs?

The PIX/ASAs seem to be converting certain fields in the syslog, from IPs to hostnames that are defined locally on the PIX/ASA.

Is there any way to disable this resolution specifically for syslog's, as it's confusing my SIEM?

I've had a look around but cant find a way to disable this (other than dropping the local hostname definition entirely which will impact rule readibility).

Is there any way to acheive this?

Thanks!

1 Reply 1

Julio Carvajal
VIP Alumni
VIP Alumni

Hello Chris,

The only way would be to disable the local name database configured on the Pix/ASA with the command:

     -No names

But it will affect all the other features that use the name database.

Regards,

Do please rate helpful posts

Julio

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card