Skip to main content

Set up

  1. Follow the shared Log Forwarders guide to add Cisco ASA and open Forwarder Details (or ask Chat for the listener ip:port)
  2. On the ASA, point syslog at the Wirespeed listener. Use udp or tcp to match the transport shown in Forwarder Details:
  3. When using TCP, also run logging permit-hostdown. Without it, the ASA stops passing new connections while the TCP syslog server is unreachable
  4. Save the configuration with write memory
  5. Events will begin showing up shortly
If Forwarder Details shows TLS: Enabled, the ASA must trust Wirespeed’s certificate before it can connect. Import the root CA as a trustpoint by following Syslog over TLS.

Time zones

logging timestamp rfc5424 sends timestamps with their time zone. Without it, the ASA sends local time with no time zone, and Wirespeed reads it as UTC. If the ASA clock is not set to UTC, event times will be off by the ASA’s UTC offset.

Parsed events

Wirespeed parses connection builds and teardowns, NAT translations, access-list and access-group denies, device logins, AAA results, AnyConnect and WebVPN sessions, configuration commands, FQDN object resolution, and threat-detection events into dedicated fields. Every other message is stored with its message ID and text.