Chapter 8 Syslog Logging Configuration Scenario

Format of Syslog Messages in ACS Reports

Step 6 Click Submit.

Step 7 Repeat the process for any additional reports for which you want to enable syslog reporting.

Format of Syslog Messages in ACS Reports

Syslog messages included in ACS reports have the following format:

<n> mmm dd hh:mm:ss XX:XX:XX:XX TAG msg_id total_seg seg# A1=V1

The elements of the message are:

n—The Priority value of the message; it is a combination of facility and severity of the syslog message, which is calculated according to RFC 3164, by first multiplying the facility value by 8 and then adding the severity value.

mmm dd hh:mm:ss—Date and time of the message.

XX:XX:XX:XX—IP Address of the machine generating this syslog message.

TAG—One of the following values, depending on the application name.

CisACS_01_PassedAuth—Cisco ACS passed authentications.

CisACS_02_FailedAuth—Cisco ACS failed attempts.

CisACS_03_RADIUSAcc—Cisco ACS RADIUS accounting.

CisACS_04_TACACSAcc—Cisco ACS TACACS+ accounting.

CisACS_05_TACACSAdmin—Cisco ACS TACACS+ administration.

CisACS_06_VoIPAcc—Cisco ACS VoIP accounting.

CisACS_11_BackRestore—ACS backup and restore log messages.

CisACS_12_Replication—ACS database replication log messages.

CisACS_13_AdminAudit—ACS administration audit log messages.

CisACS_14_PassChanges—ACS user password changes log messages.

CisACS_15_ServiceMon—ACS service monitoring log messages.

CisACS_16_ApplAdmin—ACS appliance administration audit log messages.

msg_id —Unique message id. All segments of one message share the same message ID.

total_seg —Total number of segments in this message.

seg# -Segment sequence number within this message segmentation.

A1=V1—Attribute-value pairs delimited by a comma (,) for Cisco ACS log messages and the message itself.

Facility Codes

ACS syslog messages use the following facility values:

4—Security and authorization messages. This value is used for all AAA related messages (failed attempts, passed attempts, accounting, and so on).

13—Log audit. This value is used for all other ACS report messages.

Configuration Guide for Cisco Secure ACS 4.2

8-4

OL-14390-02

 

 

Page 120
Image 120
Cisco Systems 4.2 manual Format of Syslog Messages in ACS Reports, Facility Codes

4.2 specifications

Cisco Systems, a global leader in IT and networking solutions, has consistently evolved to meet the demands of modern enterprises. One of its noteworthy offerings is Cisco Systems 4.2, a version that embodies a significant leap in networking technology and capability. With its rich set of features, Cisco Systems 4.2 caters to a wide range of industries, facilitating enhanced performance and security.

One of the main features of Cisco Systems 4.2 is its improved scalability. The architecture has been designed to support an ever-increasing number of devices and users, making it ideal for growing enterprises. The enhanced scalability allows organizations to expand their network capacities without compromising performance, ensuring seamless integration of new technologies and devices.

Another critical aspect of Cisco Systems 4.2 is its advanced security protocols. With cyber threats constantly evolving, Cisco prioritizes security in this version by offering robust features such as end-to-end encryption, improved firewall capabilities, and enhanced intrusion detection systems. These security enhancements provide organizations with peace of mind, knowing that their sensitive data and networks are well-protected from unauthorized access and potential threats.

Cisco Systems 4.2 also introduces intelligent automation features, which significantly streamline network management. Through the use of artificial intelligence and machine learning, Cisco enables organizations to automate routine tasks, reduce human error, and optimize performance. This automation not only enhances efficiency but also allows IT teams to focus on strategic initiatives rather than day-to-day maintenance.

Moreover, Cisco Systems 4.2 emphasizes infrastructure flexibility. The new architecture supports various deployment models, including on-premises, cloud, and hybrid environments. This flexibility enables organizations to adapt their networking strategies according to their specific needs and operational requirements, facilitating a more tailored approach to IT infrastructure.

Collaboration tools have also been enhanced in this version. Cisco Systems 4.2 integrates advanced communication solutions that empower teams to collaborate in real time, regardless of their geographical location. Features such as high-definition video conferencing, secure messaging, and file sharing enhance productivity and foster innovation across teams.

In summary, Cisco Systems 4.2 stands out as a forward-thinking networking solution with key features such as scalability, advanced security, intelligent automation, flexible infrastructure, and enhanced collaboration tools. These characteristics position Cisco Systems 4.2 as an invaluable asset for enterprises striving for digital transformation in an increasingly interconnected world. The ongoing innovation reflects Cisco's commitment to delivering cutting-edge technology solutions that drive business success and resilience.