Forum Discussion
Cisco ASA log entries duplicated in CommonSecurityLog and Syslog
They should not be sent to syslog. Did you use the configuration script for configuring CEF collector???
- AdiGrioNov 18, 2019Brass Contributor
Nicholas DiCola (SECURITY JEDI)
Thanks for your reply and yes, the instructions to configure the log collection for ASA were followed as I mentioned in my original post and we are getting the log entries parsed in CommonSecurityLog. Would we get them if the CEF collector was not configured properly? I have this happening in two Sentinel instances. One has a low volume of ASA logs so the effect was negligible but the other one cannot be ignored. The volume of data ingested per day for the two logs is almost the same:
Regards,
Adrian
- Nicholas DiCola (SECURITY JEDI)Nov 19, 2019Former Employee
yes its possible misconfiguration. can you share what steps you followed and the config files you are using? they should be generic configs.
- a_kefallonitisOct 13, 2020Copper Contributor
Did you find any solution on this AdiGrio? i have the same issue with the default installation.
Also do you know if there is a way for syslog not written in /var/log/messages ?