- CheckMates
- :
- Products
- :
- General Topics
- :
- ASA Cisco Syslog to CP Issues
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ASA Cisco Syslog to CP Issues
Has anyone seen issues with this setup after applying a hotfix? We applied R81.10 take 150 to our management server which is out logging server about a month ago. We recently noticed our Cisco ASA syslogs we used to have showing up in SC have stopped. We tracked it back to the install of take 150 hotfix install.
Our personnel that set this up eventually is no longer on the team but when trying to troubleshoot I looked over sk55020 which looks to be the one needed for this setup to work. When looking in the $FWDIR/bin I don't find any .ini or .c files which show to be the location of the files needed for the syslog parsing.
I just wanted to post here to see if anyone has seen this in their environment. We double-checked and our Cisco ASA is still sending syslog messages to the server but these aren't getting parsed into the SC logs anymore.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Come to find out we had an issue with our syslog daemon starting on our CP Management/Logging server. Once that was tracked down and resolved via TAC ticket the Cisco ASA syslogs were parsed without any issue into SmartLog.
Cisco ASA syslog parsing is built-in.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Those files are definitely needed to turn the Cisco ASA logs into something meaningful in SmartView.
You may want to check a backup to see if those files still exist.
This might also require a TAC case: https://help.checkpoint.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Come to find out we had an issue with our syslog daemon starting on our CP Management/Logging server. Once that was tracked down and resolved via TAC ticket the Cisco ASA syslogs were parsed without any issue into SmartLog.
Cisco ASA syslog parsing is built-in.
