Re: SYSLOG Question



Hi,

I posted that question on the cisco forum and apparently, this feature was
recently implemented, see the answer:

"
It has been the traditional answer that you could not do this directly from
IOS to syslog and if you wanted it you had to go through ACS to get
notification of login failure (or success). In release 12.3(4)T and 12.4
Cisco introduced a new feature where you can send directly to syslog for
login success or for login failure. You can use this command:
login on-failure log [every login]
and there is also a command to log successes.

For more information about this feature this link would be useful:
http://www.cisco.com/en/US/products/ps6350/products_configuration_guide_chapter09186a0080455b93.html
"

BR
Marc.


"Aaron Leonard" <Aaron@xxxxxxxxx> wrote in message
news:qhca83dopm6gl9cpqcml4dar8j5737kkhk@xxxxxxxxxx

~ We configured TACACS on our switches and we now would like to send
~ authentication related message to our syslog (eg: Authentication
~ successfull, or unsuccessfull etc...).
~
~ Is there a way to have this send to the syslog? I tested by putting the
~ logging trap to debug, but even in that case, i did not get anything
about
~ the authentication in the syslog.
~
~ Thank you for your help,
~ Marc.

Marc,

You can send aaa accounting records to your tacacs server but not, at
present,
in general, to a syslog server.

(Back in '98, I filed:

CSCdk43220 syslog method desired for AAA accounting

... this might be addressed some time this decade, or the next ...)

Aaron


.



Relevant Pages

  • Re: SYSLOG Question
    ... I appreciate the pointer to this "Cisco IOS Login Enhancements" feature - this was ... ~ IOS to syslog and if you wanted it you had to go through ACS to get ...
    (comp.dcom.sys.cisco)
  • RE: MBSA and MSs attempts at "security"
    ... >does not provide a syslog interface...the point is ... First, while I consider myself knowledgeable in Microsoft technologies, I ... while criticizing them for not including every possible feature on ... in WMI, that allows us to do whatever we want. ...
    (Focus-Microsoft)
  • forwarding syslog to remote machine, getting no hostname
    ... I have a Sparc 5 running Solaris 2.6 and sending syslog ... auth.notice] ROOT LOGIN /dev/pts/2 FROM 10.100.50.42 ... Notice in that packet that where there should normally be the hostname, ... # grep host /etc/nsswitch.conf ...
    (comp.unix.solaris)
  • Re: send kiwi log to access db
    ... > the syslog and rotate the files, but I saw problems similar to ... Service Manager, the program uses the permissions of the currently ... the program is using the Local System login. ...
    (comp.security.firewalls)
  • pros/cons to disabling msgid=0 / [ID 801593 mail.info] messages
    ... of syslog "message ID's," I couldn't find a *discussion about* them. ... Sun has new versions) we'd like to keep all systems configured (hence ... However if this "feature" ... warning that disabling it is "unstable and may be removed in a future ...
    (comp.unix.solaris)