76-24
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter76 Configuring Logging
Monitoring the Logs
To monitor the logs in the log buffer or in real-time and assist in monitoring the system performance, see
the following panes:
Filtering Syslog Messages Through the Log Viewers
You can filter syslog messages based on one or multiple values that correspond to any column of the
Real-Time Log Viewer and the Log Buffer Viewer.
To filter syslog messages through one of the log viewers, perform the following steps:
Step1 Choose one of the following:
Monitoring > Logging > Real-Time Log Viewer > View
Monitoring > Logging > Log Buffer > View
Step2 In either the Real-Time Log Viewer or the Log Buffer Viewer dialog box, click Build Filter on the
toolbar.
Step3 In the Build Filter dialog box, specify the filtering criteria to apply to syslog messages:
a. In the Date and Time area, choose one of the following three options: real-time, a specific time, or
a time range. If you chose a specific time, indicate the time by entering the number and choosing
hours or minutes from the drop-down list. If you chose a time range, in the Start Time field, click
the drop-down arrow to display a calendar. Choose a start date and a start time from the drop-down
list, then click OK. In the End Time field, click the drop-down arrow to display a calendar. Choose
an end date and an end time from the drop-down list, then click OK.
Path Purpose
Choose one of the following:
Monitoring > Logging > Log Buffer > View
Monitoring > Logging > Real-Time Log Viewer >
View
Shows syslog messages, including the severity level.
Note The maximum number of syslog messages that are
available to view is 1000, which is the default setting.
The maximum number of syslog messages that are
available to view is 2000.
Displays the message explanations, additional details, and
recommended actions to take, if necessary, to resolve an error
in a separate window. Provides text search within messages
and message filtering. Allows creation of a reverse access
control rule that performs the opposite action of the access
control rule that originally generated the syslog message.
Reverse access control rules can be applied only to syslog
messages 106100, 106023, 338001 through 338004, 338201,
and 338202. Provides the ability to use the following options
in the log viewers from the Tools menu: Ping, Traceroute,
Whois, and DNS Lookup. Provides sorting of messages in
each column shown. Allows detailed message filtering based
on the syslog ID, date and time, severity level, source and
destination IP addresses, source and destination ports, and
description listed. Displays popup help in the Build Filter
dialog box.