Chapter 19 Understanding Logging

About Logging

When you configure a critical log target, and a message is sent to that critical log target, the message is also sent to the configured noncritical log target on a best-effort basis.

When you configure a critical log target, and a message does not log to that critical log target, the message is also not sent to the configured noncritical log.

When you do not configure a critical log target, a message is sent to a configured noncritical log target on a best-effort basis.

Select System Administration > Configuration > Log Configuration > Logging Categories > Global

>log_category, where log_category, is a specific logging category to configure the critical log target for the logging categories.

Note Critical logging is applicable for accounting and AAA audit (passed authentications) categories only. You cannot configure critical logging for the following categories: AAA diagnostics, system diagnostics, and system statistics.

Remote Syslog Server Target

You can use the web interface to configure logging category messages so that they are sent to remote syslog server targets. Log messages are sent to the remote syslog server targets in accordance with the syslog protocol standard (see RFC-3164). The syslog protocol is an unsecure UDP.

Log messages are sent to the remote syslog server with this syslog message header format, which precedes the local store syslog message format (see Table 19-2):

pri_num YYYY Mmm DD hh:mm:ss xx:xx:xx:xx/host_name cat_name msg_id total_seg seg_num

Table 19-3describes the content of the remote syslog message header format.

 

User Guide for Cisco Secure Access Control System 5.3

19-8

OL-24201-01

Page 564
Image 564
Cisco Systems OL-24201-01 manual Remote Syslog Server Target, 19-8