cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4901
Views
0
Helpful
23
Replies

Why ASA is not sending admin logs to the syslog server

Seeker369
Level 1
Level 1

Hi ,

I have setup syslog server for my ASA 5520 logs. For ASDM and syslog server it is set from Informational level. But in my syslog server I am not able to find the "login details like which user access ASA on what time " etc. Is there any additional set up need to be done on the ASA ?

Thanks and regards

Deepak MK

23 Replies 23

Without seeing your configuration it is hard to tell if something is missing.

Have you configured accounting for the SSH/Telnet protocol?

aaa accounting ssh  console GROUP

Where GROUP is the TACACS or RADIUS group you have configured.

http://www.cisco.com/en/US/docs/security/asa/asa91/configuration/general/admin_management.html#wp1146262

--
Please remember to select a correct answer and rate helpful posts

Please go through this link, it gives you options, like logging class or logging list, if you like you can configure the logging class just to see what logs are shown through ASDM real time log viewer with logging class auth:

logging class auth asdm debugging

Configure Syslog using ASDM

http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080b83d04.shtml

FYI: It is the same thing on 8.X or 9.X.

Value our effort and rate the assistance!

HI Guys,

Is it necessary that RADIUS and TACACS be configured as authentication servers to get the log ? I have only configured as local authentication. ASDM -logging level 6 and SNMP logging level 5.

no

Value our effort and rate the assistance!

Did you configure what I suggested and give it a try?

Value our effort and rate the assistance!

I tried that only, I can get other logs but not able to get admin access or any login info

Do you have the command logging console informational configured on the ASA? Keep in mind that you need to be logging to the console and not the ASDM.

--
Please remember to select a correct answer and rate helpful posts

Why would he need to do this over console??? he is just checking for user authentication.

can you get us a show run username?

If you are talking about console in any case then setting a timeout for console logging is necessary

console timeout 15

This will obligate user to authenticate when logging into the device

Value our effort and rate the assistance!

Hi Marius/Jumora,

Ya there is no console logging enabled. Below is the logging setting;

Syslog logging: enabled

    Facility: 23

    Timestamp logging: enabled

    Standby logging: disabled

    Debug-trace logging: disabled

    Console logging: disabled

    Monitor logging: disabled

    Buffer logging: disabled

    Trap logging: level notifications, facility 23, 81520865 messages logged

        Logging to Application XXXXX errors: 138897  dropped: 8890508

    History logging: level informational, 187638103 messages logged

    Device ID: disabled

    Mail logging: disabled

    ASDM logging: level informational, 188649338 messages logged

So Can you advise what are the changes need to be done ? Just console logging ? For SNMP poll to be added, is it necessary that monitor logging also enabled ?

Sorry, my bad.  If you are not logging to console then do not add that command.

try adding the command:

logging class auth trap debugging

If that doesn't work, then check if syslog ID 605004 and 605005 are set to informational level.

http://www.cisco.com/en/US/docs/security/asa/syslog-guide/logmsgs.html#wp6732707

--
Please remember to select a correct answer and rate helpful posts

We need to understand what the problem is before talking about any other topic, the ticket is for logging and I need you to test what I am saying and clarify what you refer to as admin user. are you talking about a user configured on the ASA's local database.

Value our effort and rate the assistance!

Do you still need assistance???

Value our effort and rate the assistance!

HI Guys,

Thanks for the advise. I will try put in the command as Marius suggested. The account is local. I also not able to find any where in the ASA 5520 , how to change the username as well.

If you did what I explained you should not have any problem viewing when you log in, if it does not work then I would need to see it with my own eyes, in that case I would suggest or either webex with me or open a TAC case, I´m from TAC.

Value our effort and rate the assistance!
Review Cisco Networking products for a $25 gift card