Parsed ASA syslog events
Parsed ASA syslog events are specialized syslog messages that
-
contain more event attributes than other syslog events
-
let you search on any specific parsed field, and
-
are forwarded by the SEC to the Cisco cloud with italicized EventTypes for identification.
Parsed syslog event processing
The SEC forwards all ASA events you specify to the Cisco cloud but only specific syslog messages are parsed. All parsed Syslogs events are shown with their EvenTypes italicised to help you identify.
For detailed explanations of syslogs see, Cisco ASA Series Syslog Messages.
|
Syslog ID |
Syslog Category |
Purpose of syslog messge |
|---|---|---|
|
106015 |
Firewall |
Represents out of state TCP Deny |
|
106023 |
Firewall |
A real IP packet was denied by the ACL. This message appears even if you do not have the log option enabled for an ACL. |
|
106100 |
Access Lists/User Session |
Packet was permitted or denied by an ACL. |
|
113019 |
User Authentication |
Critical AnyConnect |
|
302013, 302015, 302017, 302020 |
User Session |
Connection start and end syslogs for TCP, UDP, GRE, and ICMP connection creation. |
|
302014, 302016, 302018, 302021 |
User Session |
Connection start and end syslogs for TCP, UDP, GRE, and ICMP connection creation. |
|
302020 - 302021 |
User Session |
ICMP session establishment and teardown. |
|
305006 |
User Session/NAT and PAT |
NAT connection failure |
|
305011-305014 |
User Session/NAT and PAT |
NAT Build/Teardown related |
|
313001, 313008 |
IP Stack |
Represents denied connections to the box. |
|
414004 |
System |
Critical AnyConnect |
|
609001 - 609002 |
Firewall |
A network state container was reserved/removed for host ip-address connected to a zone. |
|
710002,710004 710005 |
User Session |
To the box connections failures |
|
710003 |
User Session |
Represents denied connections to the box. |
|
746012, 746013 |
User Session |
Critical AnyConnect |
Related information: