[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Duplicate Syslog messages - ASAs in Active/Standby config

Posted on 2011-10-19
6
Medium Priority
?
1,738 Views
Last Modified: 2012-05-12
Hello,

I have two Cisco ASA 5520s in Active/Standby configuration. I have a syslog server and the following config on the ASAs :

logging enable
logging timestamp
logging standby
logging console emergencies
logging monitor alerts
logging buffered debugging
logging trap informational
logging history notifications
logging asdm informational
logging facility 22
logging host <dest vlan> <Dest ip address>

Open in new window


now.. on my syslog server, I get duplicate entries for most items. one showing the host IP as the Active firewall, and one showing the host IP as the Standby firewall. Is there a way to get only one of these? Right now we're getting about 600MB of logs daily, and cutting it into half would be great.. I've looked through Cisco's documentation and am at a loss.

as info, I am using Splunk with the Cisco Security Suite add-on installed as my syslog server
0
Comment
Question by:Robin_Ottawa
  • 4
  • 2
6 Comments
 
LVL 7

Accepted Solution

by:
Ironmannen earned 2000 total points
ID: 36998036
Hello
Disable logging to the standby device
no logging standby
0
 
LVL 7

Expert Comment

by:Ironmannen
ID: 36998042
sorry, did a typo, I mean "logging from the standby device" but the same command still applies
0
 

Author Comment

by:Robin_Ottawa
ID: 36999761
The config is replicated to the standby device automatically. How do I remove it?
0
Rewarding opportunities for women in IT

Across the nation, technology jobs are vacant because there aren’t enough qualified professionals to fill them. With a degree from WGU, you can get the credentials it takes to become an in-demand IT professional. Plus, WGU’s IT programs include industry certifications.

 

Author Comment

by:Robin_Ottawa
ID: 36999783
Nevermind, got it.. Question though. If the switch fails over, the Standby becomes active. Will syslog messages then come from the 'old' standby? or will they just stop?
0
 
LVL 7

Expert Comment

by:Ironmannen
ID: 36999791
no logging standby
wr standby
0
 
LVL 7

Expert Comment

by:Ironmannen
ID: 36999803
the new active will send the syslogs with the active ip (so you will no see that it is the former standby unit that is sending the syslogs)
0

Featured Post

Exciting career futures for women in IT

Education has the power to transform lives and open the door to new career opportunities. By earning an IT degree from WGU, you can become a highly skilled IT professional. Get the credentials and certifications you need to become a leader in this rewarding field.  

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
Powerful tools can do wonders, but only in the right hands.  Nowhere is this more obvious than with the cloud.
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

872 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question