Quantcast
Channel: THWACK: Message List - Kiwi Syslog
Viewing all articles
Browse latest Browse all 2141

Re: How to get Cisco ASA to send only DNS trafic to KIWI syslog server

$
0
0

I'm thinking you want http/https traffic. DNS traffic from the firewall will tell you what your DNS servers are all day long, but unless you're capturing packets, that isn't going to tell you what hostnames you're trying to resolve.

 

But to answer your question, yes you can. it might depend on your software version though. I know you can do it in like ASA 8.0. If you're using ASDM, it would be under Configuration/Device Management/Event Lists. You can specify which message ID's you want to receive.

 

Now that will help you narrow it down some, but I beleive you will need to further narrow it down in Kiwi, and you could JUST narrow it down in Kiwi without changing your ASA configuration if you want.

 

Just find the messages you want, and filter on that text, excluding everything else.


Viewing all articles
Browse latest Browse all 2141

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>