The Cisco ASA Firewall Insight Pack gives operational administrators and users the ability to use IBM Operations Analytics – Log Analysis to analyze traffic on their installed Cisco ASA devices. This includes using dynamic dashboards to view the rate of critical messages with the ability to drill down into messages needing attention.
The following Dashboard charts depict Cisco ASA devices error log messages based on Severity, Source and MsgType fields of the ingested log records. The default time to capture the dashboard data is set to 1 day and can be configured as needed.
The charts reflect the following:
With the included Quick Search feature, users can create saved searches for a keyword or a series of keywords. The searches are added to the saved searches pane for running at a later time. All the Quick Searches in the ASA Firewall Insight pack are based on the Cisco ASA log message severity and action. The quick searches are provided for the top 3 severity like alerts, critical, error and for actions like denied/blocked.
The following quick searches are provided with the default Insight Pack:
Reference the Insight Pack User’s Guide for adjusting the dynamic dashboards and quick searches to reflect additional data elements.
The log file is used to capture messages and events generated by the ASA devices during Network operations. Administrators use this log to troubleshoot issues raised by the ASA devices. Cisco ASA Log files are retrieved as syslog messages to a syslog server, the log file naming convention can be configurable.
Note that the messages syslog should be a syslog standalone message file for the Cisco ASA messages. It should not be combined with syslog messages from other sources. If other messages are found in the log file, the Insight Pack processing will ignored the none Cisco ASA messages. For more information on setting up the Cisco ASA log file please refer to the Data Loading Best Practices section of the users guide.
Review the following video for information on using and setting up the Insight Pack.
Training and overview presentation used in the training video.
IBM Operations Analytics-Log Analysis Insight Packs for Networks- Standard Install License
Product Information
Product Documentation
Documentation
Forum
This package is subject to the License terms included with the Insight Pack, along with those displayed upon download.
To report a problem with deploying this entry, entitled customers may contact the country specific IBM support channel, reference the IBM Worldwide Directory. Also use the “Support” link to access the support site for IBM Operations Analytics – Log Analysis information.