?
Solved

Firewall Syslogs Needed!

Posted on 2007-03-24
4
Medium Priority
?
654 Views
Last Modified: 2012-05-05
I'm comparing syslog structure among popular firewall appliances for a high school project.

I would like samples of syslog logs (please change the IP's for security sake) and I only need a few lines.

I'm trying to prove or disprove if there is indeed an industry standard syslog format or if different mfg's customize thier own.

Also wondering if a Mfg will have different syslog structures among it's different models.

I've already proved that Netgear firewall appliances have varying syslog same structures.

Help a student please...
0
Comment
Question by:kvnsdr
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 32

Assisted Solution

by:rsivanandan
rsivanandan earned 400 total points
ID: 18787208
Go to www.cisco.com and search for 'syslog', you'll get a lot of entries for both routers and firewalls

Go to www.juniper.net and search for 'syslog' again.

Cheers,
Rajesh
0
 
LVL 1

Accepted Solution

by:
HarrisRP earned 1600 total points
ID: 18805152
<163>%PIX-3-106011: Deny inbound (No xlate) icmp src outside:PublicNAT dst outside:1.2.3.4 (type 8, code 0)

<165>%PIX-5-304001: 1.2.3.4 Accessed URL 1.2.3.4:/index.cfm?md=game&tmp=detail&navID=14&gameid=401

<189>38: 12w5d: %SYS-5-CONFIG_I: Configured from console by vty0 (1.2.3.4)

<187>21908: 13w5d: %SNMP-3-AUTHFAIL: Authentication failure for SNMP req from host 1.2.3.4

To account for word wrap, I put an extra line between the four lines I posted. If you need more, let me know.

--richard
0
 
LVL 1

Assisted Solution

by:HarrisRP
HarrisRP earned 1600 total points
ID: 18805187
Thought you might like to know what devices the messages came from:

1 & 2:  cisco PIX 501 firewall
3: HP 8150 printer
4: Cisco 3640 router

And here is one from a 3-com switch:
<191>community=monitor enterprise=1.3.6.1.2.1.11 enterprise_mib_name=snmp uptime=284925094 agent_ip=1.2.3.4 generic_num=2 specific_num=0 version=Ver1 generic_name="Link down" var01_oid=1.3.6.1.2.1.2.2.1.1.215 var01_value=215 var01_mib_name=ifIndex.215 var01_value=215 var02_oid=1.3.6.1.2.1.2.2.1.7.215 var02_value=1 var02_mib_name=ifAdminStatus.215 var02_mib_value=up var03_oid=1.3.6.1.2.1.2.2.1.8.215 var03_value=2 var03_mib_name=ifOperStatus.215 var03_mib_value=down

--richard
0
 
LVL 1

Author Comment

by:kvnsdr
ID: 18805447
I have a Cisco PIX myself.

I would like something from other mfg's if possible, like SonicWall, etc...

Thanks for the help so far.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Occasionally, we encounter connectivity issues that appear to be isolated to cable internet service.  The issues we typically encountered were reset errors within Internet Explorer when accessing web sites or continually dropped or failing VPN conne…
Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
Monitoring a network: how to monitor network services and why? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the philosophy behind service monitoring and why a handshake validation is critical in network monitoring. Software utilized …
Suggested Courses

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question