Duplicate Syslog messages - ASAs in Active/Standby config

Hello,

I have two Cisco ASA 5520s in Active/Standby configuration. I have a syslog server and the following config on the ASAs :

logging enable
logging timestamp
logging standby
logging console emergencies
logging monitor alerts
logging buffered debugging
logging trap informational
logging history notifications
logging asdm informational
logging facility 22
logging host <dest vlan> <Dest ip address>

Open in new window


now.. on my syslog server, I get duplicate entries for most items. one showing the host IP as the Active firewall, and one showing the host IP as the Standby firewall. Is there a way to get only one of these? Right now we're getting about 600MB of logs daily, and cutting it into half would be great.. I've looked through Cisco's documentation and am at a loss.

as info, I am using Splunk with the Cisco Security Suite add-on installed as my syslog server
Robin_OttawaAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

IronmannenCommented:
Hello
Disable logging to the standby device
no logging standby
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
IronmannenCommented:
sorry, did a typo, I mean "logging from the standby device" but the same command still applies
0
Robin_OttawaAuthor Commented:
The config is replicated to the standby device automatically. How do I remove it?
0
Ultimate Tool Kit for Technology Solution Provider

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy now.

Robin_OttawaAuthor Commented:
Nevermind, got it.. Question though. If the switch fails over, the Standby becomes active. Will syslog messages then come from the 'old' standby? or will they just stop?
0
IronmannenCommented:
no logging standby
wr standby
0
IronmannenCommented:
the new active will send the syslogs with the active ip (so you will no see that it is the former standby unit that is sending the syslogs)
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Cisco

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.