I am trying to get my cisco pix firewall to write its logs to my linux rhes machine. Of the 7 syslog facility options, I tried LOCAL0(16), LOCAL7(23) and LOCAL4(20). I enabled trap logging at both informational and debugging levels. On "show logging" I can see that messages are being logged (313684 and counting), but I don't know where these messages are going.
My latest pix config file shows:
logging trap debugging
logging device-id hostname
logging host inside 10.0.1.103
When I select a facility other than LOCAL4(20), the config file also shows
logging facility 16 (or 23)
but this line does not appear in the config file if LOCAL4(20) is selected. It may not appear due to some system default, more on this below.
My syslogd.conf file had only these lines:
Title = "Syslogd"
LogFile = messages
*OnlyService = syslogd
So I added:
that's the latest - I also tried
local0.info, local7.debug, and with a destination of /var/log/cisco/route, a path/file I had created with 644 permissions.
I was careful to use no spaces, only tabs in this line of the syslogd.conf file, and restarted syslogd each time, looking for errors.
/var/log/messages shows no errors, but syslogd -d shows this error:
symbolic name: * ==> 255
symbolic name: LOCAL(4)20Called logerr, msg: unknown facility name "LOCAL(4)20"
logmsg: syslog.err<43>, flags 4, from alice, msg syslogd: unknown facility name "LOCAL(4)20"
The same error shows up regardless of what's in my syslogd.conf file and regardless of the facility selected on the pix! I have tried to sync changes to the syslogd file with changes to the pix as follows:
apply changes to pix, check running config and/or reboot
Pls explain these errors and how to fix them, thanks