52-5
User Guide for Cisco Security Manager 4.4
OL-28826-01
Chapter 52 Configuring Logging Policies on Firewall Devices
Event Lists Page
Add/Edit Event List Dialog Box
The Add/Edit Event List dialog box lets you create or edit an event list, and specify which syslog
messages to include in the event list filter.
You can use the following criteria to define an event list:
• Class and Severity
• Message ID
Class represents specific types of related syslog messages. For example, the class
auth represents all
syslog messages related to user authentication.
Severity classifies syslogs based on the relative importance of the event in the normal functioning of the
network. The highest severity is Emergency, which means the resource is no longer available. The lowest
severity is Debugging, which provides detailed information about every network event.
The message ID is a numeric value that uniquely identifies each individual message. You can specify a
single message ID, or a range of IDs, in an event list.
Navigation Path
You can access the Add/Edit Event List dialog box from the Event Lists Page, page 52-4.
Related Topics
• Chapter 52, “Configuring Logging Policies on Firewall Devices”
Field Reference
rm Resource Manager 321
session User Session 106, 108, 201, 202, 204, 302, 303, 304, 305, 314, 405,
406, 407, 500, 502, 607, 608, 609, 616, 620, 703, 710
snmp SNMP 212
sys System 199, 211, 214, 216, 306, 307, 315, 414, 604, 605, 606,
610, 612, 614, 615,701, 711
vpdn PPTP and L2TP Sessions 213, 403, 603
vpn IKE and IPsec 316, 320, 402, 404, 501, 602, 702, 713, 714, 715
vpnc VPN Client 611
vpnfo VPN Failover 720
vpnlb VPN Load Balancing 718
webvpn Web-based VPN 716
Table 52-5 Message Classes and Associated Message ID Numbers (Continued)
Class Definition Message ID Numbers
Table 52-6 Add/Edit Event List Dialog Box
Element Description
Event List Name Enter a name that uniquely identifies this event list.