4-6
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 4 Configuring Firewall Devices
Cisco Firewall Devices (PIX, ASA, and FWSM)
Device-Side Tuning for Cisco Firewall Device Syslogs
The default level for many of the events that are studied by MARS is the debug level, which can generate
a high volume of additional events that are not used by MARS. If you are experiencing an influx of these
other events, you can use the
logging message
command to either turn off events or change the severity
level of the event to a level that generates required messages but not as many as debug.
This topic identifies the commands to use to change the log level from the command line, as well as
identifies those messages consumed by MARS and their default severity level.
Logging Message Command
The following references provide details for using the logging message command on the appropriate
firewall device:
Cisco ASA and Cisco PIX
•
“Changing the Severity Level of a System Log Message” in
Cisco Security Appliance Command
Line Configuration Guide, Version 7.2
http://www.cisco.com/en/US/products/ps6120/products_configuration_guide_chapter09186a0080
63b3ff.html#wp1065731
•
“Disabling a System Log Message” in
Cisco Security Appliance Command Line Configuration
Guide, Version 7.2
http://www.cisco.com/en/US/products/ps6120/products_configuration_guide_chapter09186a0080
63b3ff.html#wp1065706
•
“Logging Message Command” in
Cisco Security Appliance System Log Messages, Version 7.2
http://www.cisco.com/en/US/products/ps6120/products_command_reference_chapter09186a0080
63f0f5.html#wp1683322
•
Cisco Security Appliance System Log Messages, Version 7.2
http://www.cisco.com/en/US/products/ps6120/products_system_message_guide_book09186a0080
610b8b.html
Cisco FWSM
•
“Changing the Severity Level of a System Log Message” in
Catalyst 6500 Series Switch and Cisco
7600 Series Router Firewall Services Module Configuration Guide, 3.1
http://www.cisco.com/en/US/products/hw/switches/ps708/products_module_configuration_guide_
chapter09186a0080577c3e.html#wp1099894
•
“Disabling a System Log Message” in
Catalyst 6500 Series Switch and Cisco 7600 Series Router
Firewall Services Module Configuration Guide, 3.1
http://www.cisco.com/en/US/products/hw/switches/ps708/products_module_configuration_guide_
chapter09186a0080577c3e.html#wp1099869
•
“Logging Message Command” in
Catalyst 6500 Series Switch and Cisco 7600 Series Router
Firewall Services Module Command Reference, 3.1
http://www.cisco.com/en/US/products/hw/switches/ps708/products_command_reference_chapter0
9186a008048e1f8.html#wp1565791
•
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Logging
Configuration and System Log Messages, 3.1