Cisco Security Cloud Control: Secure Firewall ASA Management

PDF

Cisco Security Cloud Control: Secure Firewall ASA Management

Export the change log

Want to summarize with AI?

Log in

Configure the export of all or selected change log data to a CSV file so you can filter, sort, and retain change records for reporting or analysis.


Export change log data to a comma-separated value (.CSV) file to enable filtering, sorting, and analysis of change records outside of the system.

You can export all or a subset of the Security Cloud Control change log to a comma-separated value (.CSV) file so that you can filter and sort the information, as required.

To export the change log to a .CSV file, follow this procedure:

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the left pane, click Events & Logs > Logs > Change Log.

3.

Find the changes you want to export by doing one of the following tasks:

  • Use the filter (The image illustrates the process of filtering and searching within a change log to export specific changes related to selected devices.) and the search field to find what you want to export. For example, filter by device to see only the changes for your selected device or devices.

  • Clear all the filters and search criteria in the change log. This allows you to export the entire change log.

Note

Security Cloud Control retains 1 year of change log data. It is recommended to filter the change log contents and download the results to a .CSV file rather than downloading the entire change log history for a year.

4.

Click the export The image illustrates the process of exporting the change log, highlighting the option to clear filters and search criteria for a complete export. icon at the top right corner of the page.

5.

Save the .CSV file to your local file system, with a descriptive name.

The change log data is exported to a CSV file on your local system, allowing you to perform additional filtering, sorting, and analysis as needed.


Differences between change log capacity in Security Cloud Control and size of an exported change log

Change log capacity differences are data storage variations that

  • distinguish between the complete change log information stored in Security Cloud Control's database and the subset of information included in exported files

  • result from different storage requirements for database operations versus export functionality, and

  • affect file sizes when users export change log data.

Change log storage structure

For every change log, Security Cloud Control stores two copies of the device's configuration–the starting configuration and either the ending configuration in the case of a closed change log or the current configuration in the case of an open change log. This allows Security Cloud Control to display configuration differences side by side. In addition, Security Cloud Control tracks and stores every step (change event) with the username that made the change, the time the change was made, and other details.

However, when you export the change log, the export does not include the two complete copies of the configuration. It only includes the change events, which makes the export file much smaller than the change log that Security Cloud Control stores.

Security Cloud Control stores change log information for a year. This includes two copies of the configuration.