List Of Cisco Firewall Message Events Processed By Mars - Cisco CS-MARS-20-K9 - Security MARS 20 User Manual

Security mars local controller
Table of Contents

Advertisement

Chapter 4
Configuring Firewall Devices

List of Cisco Firewall Message Events Processed by MARS

The following list of events are processed by MARS. By changing the severity level for these events to
ensure they are within the logging level you have selected, you can typically reduce the load on your
firewall logging by 5-15%. However, the primary consumer of resources will remain the session detail
events, which are processed and analyzed by MARS.
Starting with MARS version, the system can correctly parse syslogs at customized logging levels.
Therefore, you can move the syslogs processed by MARS to a lower level and then set the log to that
level, for example logging level 6. Use the command logging message message-id level level on the
ASA, or PIX, to move a syslog message to a new level.
The following syslog message IDs are those required for proper sessionization. If you change the
logging level of the firewall, ensure that the following messages IDs are generated at the new level so
the MARS Appliance receives them.
The syslog message IDs listed below are required for sessionization. However, other logs at the debug
Note
or informational levels may exist that you may require for other purposes. for example, a specific URL
accessed by one user if you are doing URL filtering on the security appliance. Refer to the
Message Command, page 4-6
78-17020-01
http://www.cisco.com/en/US/products/hw/switches/ps708/products_system_message_guide_book
09186a00804d7356.html
logging message 106100
logging message 106001
logging message 106002
logging message 106006
logging message 106007
logging message 106010
logging message 106012
logging message 106013
logging message 106014
logging message 106015
logging message 106016
logging message 106017
logging message 106018
logging message 106019
logging message 106020
logging message 106021
logging message 106022
logging message 106023
logging message 302001
logging message 302003
for pointers to the full message list for each firewall device type.
User Guide for Cisco Security MARS Local Controller
Cisco Firewall Devices (PIX, ASA, and FWSM)
Logging
4-7

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mars 20Mars 50Mars 100Mars 200

Table of Contents