Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

Why ASA is not sending admin logs to the syslog server

Hi ,

I have setup syslog server for my ASA 5520 logs. For ASDM and syslog server it is set from Informational level. But in my syslog server I am not able to find the "login details like which user access ASA on what time " etc. Is there any additional set up need to be done on the ASA ?

Thanks and regards

Deepak MK

  • Firewalling
23 REPLIES
VIP Green

Why ASA is not sending admin logs to the syslog server

Without seeing your configuration it is hard to tell if something is missing.

Have you configured accounting for the SSH/Telnet protocol?

aaa accounting ssh  console GROUP

Where GROUP is the TACACS or RADIUS group you have configured.

http://www.cisco.com/en/US/docs/security/asa/asa91/configuration/general/admin_management.html#wp1146262

-- Please remember to rate and select a correct answer
Cisco Employee

Why ASA is not sending admin logs to the syslog server

Please go through this link, it gives you options, like logging class or logging list, if you like you can configure the logging class just to see what logs are shown through ASDM real time log viewer with logging class auth:

logging class auth asdm debugging

Configure Syslog using ASDM

http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080b83d04.shtml

FYI: It is the same thing on 8.X or 9.X.

Value our effort and rate the assistance!

Why ASA is not sending admin logs to the syslog server

HI Guys,

Is it necessary that RADIUS and TACACS be configured as authentication servers to get the log ? I have only configured as local authentication. ASDM -logging level 6 and SNMP logging level 5.

Cisco Employee

Why ASA is not sending admin logs to the syslog server

no

Value our effort and rate the assistance!
Cisco Employee

Why ASA is not sending admin logs to the syslog server

Did you configure what I suggested and give it a try?

Value our effort and rate the assistance!

Why ASA is not sending admin logs to the syslog server

I tried that only, I can get other logs but not able to get admin access or any login info

VIP Green

Re: Why ASA is not sending admin logs to the syslog server

Do you have the command logging console informational configured on the ASA? Keep in mind that you need to be logging to the console and not the ASDM.

-- Please remember to rate and select a correct answer
Cisco Employee

Why ASA is not sending admin logs to the syslog server

Why would he need to do this over console??? he is just checking for user authentication.

can you get us a show run username?

If you are talking about console in any case then setting a timeout for console logging is necessary

console timeout 15

This will obligate user to authenticate when logging into the device

Value our effort and rate the assistance!

Why ASA is not sending admin logs to the syslog server

Hi Marius/Jumora,

Ya there is no console logging enabled. Below is the logging setting;

Syslog logging: enabled

    Facility: 23

    Timestamp logging: enabled

    Standby logging: disabled

    Debug-trace logging: disabled

    Console logging: disabled

    Monitor logging: disabled

    Buffer logging: disabled

    Trap logging: level notifications, facility 23, 81520865 messages logged

        Logging to Application XXXXX errors: 138897  dropped: 8890508

    History logging: level informational, 187638103 messages logged

    Device ID: disabled

    Mail logging: disabled

    ASDM logging: level informational, 188649338 messages logged

So Can you advise what are the changes need to be done ? Just console logging ? For SNMP poll to be added, is it necessary that monitor logging also enabled ?

610
Views
0
Helpful
23
Replies
This widget could not be displayed.