Cisco pix logging to linux

I have cisco pix firewall and RH 7.2 linux. I need to configure syslog on linux. Everything I did in pix but logging is not working
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Setting up the PIX is half of the solution. You also need to create syslog.conf entries to recieve and process the data. I'm not at work now and can't look at my PIX and syslog setup, but I'll do that tomorrow and tell you how mine is configured.
Okay, I'm back...

My setup for logging PIX data to a RedHat server is as follows:

1. The server is at and I have:

      logging on
      logging monitor debugging
      logging buffered debugging
      logging trap debugging
      logging host inside

    in my PIX configuration.

2. On the RedHat box I have the following in my syslogd.conf:

   # PIX additions
   local4.emerg                      /dev/console
   local4.alert                      /dev/console
   local4.crit                       /dev/console
   local4.err                        /dev/console
   local4.debug                      /var/pix/activity

   You way want to direct some of those to to different
   places or files.

3. To get syslogd to listen on a network socket you need to include the '-r' option. I run mine as 'syslogd -r -m 0'.

If you have a busy PIX you'll want to have plenty of room for the log file and you'll want to rotate it regularly. I roll my PIX log daily.
arvindSR Manager OperationCommented:
jlevie is right.

In RH 7.2 - U need to change syslog option in /etc/sysconfig/syslog put -r and in /etc/syslog.conf
local4.*                  /var/log/pixlog(or whatever file)

in the last and then restart the syslog daemon /etc/rc.d/init.d/syslog restart.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
OWASP: Avoiding Hacker Tricks

Learn to build secure applications from the mindset of the hacker and avoid being exploited.


Before any one else fusses at you you should know that you ought not to propose an answer unless what you have entered  as the answer hasn't already been touched on in a previous comment and you are certain that the comment will solve the problem. In this case your proposed answer is just a slight variation of my previous comment. I'm not overly concerned about in this case but other experts consider actions like this to be extremely rude and will complain, and rightly so.
arvindSR Manager OperationCommented:
Sorry for I'd forget to click on comments -How do i withdraw ???
arvindSR Manager OperationCommented:
Sorry for I'd forget to click on comments -How do i withdraw ???
sapientAuthor Commented:
jlevie - I'd already fix all the pix command, but I'm doing wrong in syslog start file. Finally arvind suggest in /etc/sysconfig/syslog. previously I did on /etc/rc.d/init.d/syslog.

It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.