Solved

cisco ASA syslog issue

Posted on 2014-01-27
5
610 Views
Last Modified: 2014-02-17
Hi,

 can we get history of users logged into cisco ASA including login period & logout time both

With out syslog server , can we see the history  in a firewall..
Is there any commands to see or any logging related configuration..?

regards
Ram
0
Comment
Question by:RAMU CH
  • 2
  • 2
5 Comments
 
LVL 57

Expert Comment

by:Pete Long
ID: 39811595
Ram

This is usually a feature of AAA rather than syslog?


Pete
0
 
LVL 8

Accepted Solution

by:
amatson78 earned 500 total points
ID: 39812440
The ASA does not have a long term log, anything including AAA and others. The default buffer for logging (Configuration > Device Management > Logging > Logging Setup is 4096 bytes. You can also save the buffer to FTP or email or send it via Syslog. This is the best way.

For the login messages you will want to look for any login messages in the logs such as below which depending on your syslog can be searched:

Logging
0
 
LVL 1

Author Comment

by:RAMU CH
ID: 39814491
Is there any free syslog toools available in internet market..

How about Kiwi?


1.What should be the system details generally required to store Log data in a server?

2. What should be the configuration for only monitoring for Login and logout sessions instead every traffic to prevent  server gets  overloaded?


Regards
Ramu
0
 
LVL 8

Expert Comment

by:amatson78
ID: 39816421
I use Splunk which is a free SIEM product that accepts syslog. Easy to search through and make custom filters. As far as system specs depends on the product. Configuration is all done via the Cisco ASA, you can enable what features you want to log and what you don't.
0
 
LVL 1

Author Closing Comment

by:RAMU CH
ID: 39864510
Tks
0

Featured Post

Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

Join & Write a Comment

In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
I recently had the displeasure of buying a new firewall at one of the buildings I play Sys Admin at. I had to get a better firewall than the cheap one that I had there since I was reconnecting the main office to the satellite office via point-to-poi…
This video discusses moving either the default database or any database to a new volume.
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now