centos 7 configure rsyslog to receive cisco logs

mphillip85
mphillip85 used Ask the Experts™
on
I have not been able to verify that logs are being received on the centos 7 server using rsyslog

firewall has udp 514 open and listening same set on the cisco asa

cannot see why it is not working, I do sh logging and it shows how many TX are being sent via the trigger but cannot find on rsyslog server.
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Most Valuable Expert 2015
Commented:
In /etc/rsyslog.conf, uncomment these lines:

   $ModLoad imudp
   $UDPServerRun 514
   $IncludeConfig /etc/rsyslog.d/*.conf

In /etc/rsyslog.d create a file called asa.conf and add these lines where A.B.C.D is the IP of the asa:
    if $fromhost-ip startswith 'A.B.C.D' then /var/log/asa.log
    & ~

Restart syslog:
   systemctl restart rsyslog
Most Valuable Expert 2015

Commented:
And update logrotate:

   /etc/logrotate.d/syslog

Add /var/log/asa.log

Author

Commented:
did I give you all the information you needed to review?

because you gave me the only answer that worked, over all the documentation that I have read.

Thank you very much!
Most Valuable Expert 2015

Commented:
You did.  You were very clear.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial