Create a Remote Log Source - Cisco ASA

 

Topics Discussed

 

You can use this document to send Cisco Adaptive Secure Appliance (ASA) logs to Armor's Security Information & Event Management (SIEM).

This document only applies to:

  • Cisco Adaptive Secure Appliance (ASA) 8.X

  • Cisco Adaptive Secure Appliance (ASA) 9.X


Pre-Deployment Considerations


To create a remote Log Relay, you must already have:


Update your Cisco ASA device


  1. Log into your Cisco ASA device.

  2. Access the privileged EXEC mode:

    hostname> enable
  3. Access the global configuration mode:

    hostname# configure terminal
  4. Enable logging:

    hostname(config)# logging enable
  5. Configure the global logging settings:

  6. Configure logs to be sent to a designated Armor Log Relay device:

  7. To ensure that the log messages use the IP address and not the object names, disable the output object name option:

  8. Exit the configuration:

  9. Save the changes:

  10. Review the logging configuration:

Troubleshooting

Verify that logs are formatted correctly, similar to the following example: