This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

Kiwi Syslog not displaying Cisco ASA 5505 syslogs

I have a Cisco ASA 5505 that is setup to send syslogs to a remote syslog server.

I have kiwi syslog (free) installed on a Windows 2003 R2 Server and it is listening on UDP port 514. The syslog server also is my Ciscoworks v3.2 server.

I can ONLY see the Ciscoworks log files and not the ASA. I only want to display the ASA log files.

I have googled, read the user guide, and search the forum and cannot find any procedure that I can tweak Kiwi to log the syslog files from my ASA which is being used as a VPN concentrator.

Any ideas?

  • 1.) check local firewall, try deactivating it for the meantime

    2.) on the asa, check that syslog filters for syslog servers are set to the desired level (for you probably informational? (double checking the syslog server is entered and that logging is turned on i probably dont even need to mention)

    3.) if that does not work, install wireshark on the server and check that those syslogs actually arrive at the server

    4.) if syslogs arrive at the server, check kiwi syslog rules to make sure they are not being filtered out, if they are not open a case with solarwinds.

    if syslogs do not arrive you have to analyze your network on where those syslogs are being blocked

  • Ok... I can now see my ASA logs after inputting the following CLI:

    logging trap informational

    I am using the free version is there anyway to create a filter with just

    ASA to ease the burden of sifting through all other syslog messages?

    It appears the license version is needed to create a specific filter.

    And is there another way to create only a log specific to a single device and create a daily file for archiving purposes?

  • Hi,

    I am not familiar with the free version but with the paid version you can create rules to filter for just one device or also just create a daily file for each device that is logging to the syslogserver!

    PS: if any of my posts answered your question, please verify them :)

    thank you

  • Everything is working fine and the ASA is sending the information syslogs... but it appears the features

    I asked about are only for the licensed version.

    Thanks