I'm generate to generate a report from our ASA SYSLOGs to find out how often our users have been logging in with there VPN client.
We have been recording the SYSLOGs from our ASA 5510 for months now but we are having difficulty sorting through it to generate a suitable report.
What I would like is a report that tells me when users authenticated to the firewall with there VPN client and when they disconnected,I would also like a similar report for the SSL VPN.
But the catch is I have no idea what SYSLOG events I should be looking for as I'm literally sorting through millions of events.
Does anyone know these events off hand?
Once I get that I can just setup the report filtering in our tool.