CISCO ASA SYSLOG
Use the logging list command in order to capture the syslog for LAN-to-LAN and Remote access
IPsecVPN messages alone.
This example captures all VPN (IKE and IPsec) class system log messages with debugging level or higher.
Example:
hostname(config)#logging enable
hostname(config)#logging timestamp
hostname(config)#logging list my-list level debugging class vpn
hostname(config)#logging trap my-list
hostname(config)#logging host inside 192.168.1.1
Troubleshoot
If you do not receive the syslog 304001 messages, then make sure that the
inspect http command is enabled on the ASA.
If you want to deny a specific syslog message to be sent to syslog server,
then you must use the command as shown.
hostname(config)#no logging message <syslog_id>
Usage Guidelines
If you are using TCP as the logging transport protocol for sending messages to a
syslog server, the security appliance denies new network access sessions as a security
measure if the security appliance is unable to reach the syslog server.
You can use the logging permit-hostdown command to remove this restriction.
Examples
The following example makes the status of TCP-based syslog servers irrelevant to whether
the security appliance permits new sessions. When the logging permit-hostdown command
includes in its output the show running-config logging command, the status of TCP-based
syslog servers is irrelevant to new network access sessions.
hostname(config)# logging permit-hostdown
hostname(config)# show running-config logging
logging enable
logging trap errors
logging host infrastructure 10.1.2.3 6/1470
logging permit-hostdown