{"id":174,"date":"2014-07-30T13:35:09","date_gmt":"2014-07-30T17:35:09","guid":{"rendered":"http:\/\/jackhanington.com\/blog\/?p=174"},"modified":"2015-06-15T13:41:19","modified_gmt":"2015-06-15T17:41:19","slug":"sysloging-cisco-asa-firewall","status":"publish","type":"post","link":"https:\/\/jackhanington.com\/blog\/2014\/07\/30\/sysloging-cisco-asa-firewall\/","title":{"rendered":"Set up Syslogging on Cisco ASA Firewall"},"content":{"rendered":"<p>The purpose of this post is to guide you on how to set up syslogging on a Cisco ASA firewall so you can ship your logs to a centralized log server like the ELK stack (Elasticsearch, Logstash and Kibana). This configuration guide is done using the ASDM (GUI).<\/p>\n<p>Here is an example of what a Cisco syslog looks like&#8230;<\/p>\n<pre>%ASA-4-106023: Deny tcp src outside:109.230.217.95\/24069 dst inside:164.32.112.125\/25 by access-group \"PERMIT_IN\" [0x0, 0x0]\"\r\n<\/pre>\n<p>The Cisco message above shows that the IP of <a title=\"109.230.217.95\" href=\"http:\/\/www.geobytes.com\/IpLocator.htm?GetLocation&amp;IpAddress=109.230.217.95\" target=\"_blank\">109.230.217.95<\/a> was denied access to a blocked SMTP port based on the access group &#8220;PERMIT_IN&#8221; for the public IP address of\u00a0164.32.112.125.<\/p>\n<p>Here are the settings to tell our Firewall to send syslogs to our centralized log service. Open up your ASDM and log into your firewall.<\/p>\n<p><a href=\"\/\/jackhanington.com\/blog\/wp-content\/uploads\/2013\/09\/1-Cisco-Login.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-180\" src=\"\/\/jackhanington.com\/blog\/wp-content\/uploads\/2013\/09\/1-Cisco-Login.png\" alt=\"\" width=\"429\" height=\"271\" srcset=\"https:\/\/jackhanington.com\/blog\/wp-content\/uploads\/2013\/09\/1-Cisco-Login.png 429w, https:\/\/jackhanington.com\/blog\/wp-content\/uploads\/2013\/09\/1-Cisco-Login-300x189.png 300w\" sizes=\"auto, (max-width: 429px) 100vw, 429px\" \/><\/a><\/p>\n<p>Click the configuration button on the\u00a0top<br \/>\n<a href=\"\/\/jackhanington.com\/blog\/wp-content\/uploads\/2013\/09\/2-Configuration.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-181\" src=\"\/\/jackhanington.com\/blog\/wp-content\/uploads\/2013\/09\/2-Configuration.png\" alt=\"Configuration\" width=\"291\" height=\"126\" \/><\/a><\/p>\n<p>Click \u201cDevice Management&#8221;<br \/>\n<a href=\"\/\/jackhanington.com\/blog\/wp-content\/uploads\/2013\/09\/3-Device-Management.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-182\" src=\"\/\/jackhanington.com\/blog\/wp-content\/uploads\/2013\/09\/3-Device-Management.png\" alt=\"Device Management\" width=\"271\" height=\"213\" \/><\/a><\/p>\n<p>Expand \u201cLogging\u201d and click \u201cSyslog Servers\u201d<br \/>\n<a href=\"\/\/jackhanington.com\/blog\/wp-content\/uploads\/2013\/09\/4-Syslog-Servers.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-183\" src=\"\/\/jackhanington.com\/blog\/wp-content\/uploads\/2013\/09\/4-Syslog-Servers.png\" alt=\"Syslog Servers\" width=\"271\" height=\"422\" srcset=\"https:\/\/jackhanington.com\/blog\/wp-content\/uploads\/2013\/09\/4-Syslog-Servers.png 271w, https:\/\/jackhanington.com\/blog\/wp-content\/uploads\/2013\/09\/4-Syslog-Servers-192x300.png 192w\" sizes=\"auto, (max-width: 271px) 100vw, 271px\" \/><\/a><\/p>\n<p>On the right side click \u201cAdd\u201d, choose the inside interface, type in the IP of the machine you want to ship logs to, select UDP, type in your port and click OK.<br \/>\n<a href=\"\/\/jackhanington.com\/blog\/wp-content\/uploads\/2013\/09\/5-Add-Server.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-184\" src=\"\/\/jackhanington.com\/blog\/wp-content\/uploads\/2013\/09\/5-Add-Server.png\" alt=\"Add Server\" width=\"414\" height=\"271\" srcset=\"https:\/\/jackhanington.com\/blog\/wp-content\/uploads\/2013\/09\/5-Add-Server.png 414w, https:\/\/jackhanington.com\/blog\/wp-content\/uploads\/2013\/09\/5-Add-Server-300x196.png 300w\" sizes=\"auto, (max-width: 414px) 100vw, 414px\" \/><\/a><\/p>\n<p>Click \u201cLogging Setup\u201d, select \u201cEnable logging\u201d and click apply.<br \/>\n<a href=\"\/\/jackhanington.com\/blog\/wp-content\/uploads\/2013\/09\/6-Enable.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-187\" src=\"\/\/jackhanington.com\/blog\/wp-content\/uploads\/2013\/09\/6-Enable.png\" alt=\"Enable\" width=\"808\" height=\"289\" srcset=\"https:\/\/jackhanington.com\/blog\/wp-content\/uploads\/2013\/09\/6-Enable.png 808w, https:\/\/jackhanington.com\/blog\/wp-content\/uploads\/2013\/09\/6-Enable-300x107.png 300w, https:\/\/jackhanington.com\/blog\/wp-content\/uploads\/2013\/09\/6-Enable-500x178.png 500w\" sizes=\"auto, (max-width: 808px) 100vw, 808px\" \/><\/a><\/p>\n<p>Click \u201cLogging Filters\u201d, double click \u201cSyslog Servers\u201d, check \u201cFilter on severity\u201d, select the type of logs you want to receive and click OK.<br \/>\n<a href=\"\/\/jackhanington.com\/blog\/wp-content\/uploads\/2013\/09\/7-Logging-Filters.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-186\" src=\"\/\/jackhanington.com\/blog\/wp-content\/uploads\/2013\/09\/7-Logging-Filters.png\" alt=\"Logging Filters\" width=\"975\" height=\"503\" srcset=\"https:\/\/jackhanington.com\/blog\/wp-content\/uploads\/2013\/09\/7-Logging-Filters.png 975w, https:\/\/jackhanington.com\/blog\/wp-content\/uploads\/2013\/09\/7-Logging-Filters-300x154.png 300w, https:\/\/jackhanington.com\/blog\/wp-content\/uploads\/2013\/09\/7-Logging-Filters-500x257.png 500w\" sizes=\"auto, (max-width: 975px) 100vw, 975px\" \/><\/a><\/p>\n<p>Here is an explanation of the different logging levels with Cisco products.<br \/>\n<a href=\"\/\/jackhanington.com\/blog\/wp-content\/uploads\/2014\/04\/Severity.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-251\" src=\"\/\/jackhanington.com\/blog\/wp-content\/uploads\/2014\/04\/Severity.jpg\" alt=\"Cisco Severity\" width=\"1000\" height=\"765\" srcset=\"https:\/\/jackhanington.com\/blog\/wp-content\/uploads\/2014\/04\/Severity.jpg 1000w, https:\/\/jackhanington.com\/blog\/wp-content\/uploads\/2014\/04\/Severity-300x229.jpg 300w, https:\/\/jackhanington.com\/blog\/wp-content\/uploads\/2014\/04\/Severity-392x300.jpg 392w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/a><\/p>\n<p>Now just save your running config to the startup config and you will now start seeing your logs on your centralized log server.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The purpose of this post is to guide you on how to set up syslogging on a Cisco ASA firewall so you can ship your logs to a centralized log server like the ELK stack (Elasticsearch, Logstash and Kibana). This configuration guide is done using the ASDM (GUI). Here is an example of what a&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_exactmetrics_skip_tracking":false,"_exactmetrics_sitenote_active":false,"_exactmetrics_sitenote_note":"","_exactmetrics_sitenote_category":0,"footnotes":""},"categories":[20,3,40],"tags":[],"class_list":["post-174","post","type-post","status-publish","format-standard","hentry","category-blog","category-information-technology","category-networking"],"_links":{"self":[{"href":"https:\/\/jackhanington.com\/blog\/wp-json\/wp\/v2\/posts\/174","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jackhanington.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jackhanington.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jackhanington.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jackhanington.com\/blog\/wp-json\/wp\/v2\/comments?post=174"}],"version-history":[{"count":35,"href":"https:\/\/jackhanington.com\/blog\/wp-json\/wp\/v2\/posts\/174\/revisions"}],"predecessor-version":[{"id":299,"href":"https:\/\/jackhanington.com\/blog\/wp-json\/wp\/v2\/posts\/174\/revisions\/299"}],"wp:attachment":[{"href":"https:\/\/jackhanington.com\/blog\/wp-json\/wp\/v2\/media?parent=174"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jackhanington.com\/blog\/wp-json\/wp\/v2\/categories?post=174"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jackhanington.com\/blog\/wp-json\/wp\/v2\/tags?post=174"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}