Cisco Secure Access Help

PDF

Cisco Secure Access Help

About the Remote Access Log Report

Want to summarize with AI?

Log in

Describes About the Remote Access Log Report in Cisco Secure Access. The Remote Access Log report lists users that have remotely connected to Secure Access and requested access to destinations.


The Remote Access Log report lists users that have remotely connected to Secure Access and requested access to destinations. Some relevant fields to aid debugging and trouble-shooting remote access sessions include:

  • Display Username for Failed Events – Significantly improves how quickly issues can be tracked and addressed.

  • ASA Syslog Message ID Extraction Support – Offers detailed insights by identifying the specific sys-log messages used in the remote access logs.

  • Device ID – Includes the device ID with every event, providing critical help to network administrators in numerous ways.

  • Failed Events for Posture – Provides vital information for effective triage during failed connection attempts.

You can schedule automatic delivery of Remote Access Log reports or export them as CSV files for further analysis. For more information, see Schedule a Remote Access Log report and Export Report Data to CSV.

The exported CSV file of Remote Access Logs includes the following columns: Date, Time, User, Device Name, Connection Event, Event Details, Public IP, Internal IP, VPN Profile, Session Type, OS Type and Versions, Secure Client Version, Session Duration, and Region.

You can use filters to refine results and help identify security issues that require attention.


View the Remote Access Log Report

Before you begin

A minimum user role of Read-only. For more information, see Manage Accounts.

The Remote Access Log report lists users' connection events that are related to remote access, tracked over distinct time periods.

Procedure

  1. Navigate to Monitor > Reports > Remote Access Logs.

  2. Choose a time frame of remote access events.

  3. Use the search bar to find remote access events by identity or endpoint device OS version. Identity includes the columns User and Device Name.

    Note
    If you have configured rules to traffic originating from IP addresses in network segments that include Security Group Tags, then you can search for connection events by SGT. When present, SGTs will be appended to the User column value. For more information, see Integrate ISE with Secure Access and Integrate Catalyst SD-WAN with Secure Access.
  4. Refine your search using the following filters to help identify security issues that require attention.

    The filter menu can include the following filter types when they apply to the selected data:

    • AAA

    • Addr Assignment Fail

    • Access Allowed

    • Administrator Reset

    • Authentication Check

    • Authorization Check

    • Cert Auth Check

    • Certificate Expired

    • Client Type Not Supported

    • Connection Lost

    • Connection Preempted

    • DDNS Update Failed

    • Geocompliance Check

    • Geocompliance Service Unavailable

    • IKE Delete

    • IKEV2 Check

    • IPSec Error

    • Max Time Exceeded

    • Port Error

    • Posture Check

    • Posture Check Failed

    • SA Expired

    • Static IP Addr Assignment Fail

    • TLS Check

    • Unknown Disconnection Reason

    • Unknown Failed Reason

    • User Requested

    • Identities lets you filter by connection events with Security Group Tags (SGT) you have configured rules to traffic originating from IP addresses in network segments that include SGTs. When present, SGTs will be appended to the User column value. For more information, see Integrate ISE with Secure Access and Integrate Catalyst SD-WAN with Secure Access.

    Note
    Each filter is dynamic, except for Identities, and will only display filter option values that are present in the connection data. If no option values are present in the data for a filter, that filter remains hidden.
  5. The table includes the following categories:

    • User—The name of the user in Secure Access.

    • Device Name—The name of the device in Secure Access.

    • Connection Event—The identity used to determine which policy applied to this activity

    • Event Details— The category of activity or action committed. Hover over this column to view the Reason Code and any syslog info related to the event.

    • Public IPv4 Address— The public-facing IPv4 address configured in the VPN profile.

    • Assigned IPv4 Address— The internal IPv4 address configured in the VPN profile.

    • Assigned IPv6 Address—The internal IPv6 address configured for the VPN profile.

    • VPN Profile— The name of the VPN profile associated with the event.

    • OS Type and Versions— The OS type and software version of the machine associated with the event.

    • Secure Client Version— The version of the Secure Client.

    • Session Duration— Duration of the session, if terminated.

    • Region— The region configured in the VPN profile that is associated with the event.

    • Event Time— The day, year, and timestamp of the event.


View Event Details

To view details of an event, perform the following steps:

Procedure

  1. Option 1: Click the View Details icon (the blue ellipsis at the right end of each row).

    The View Event Details interface.
  2. Option 2: Hover over an Event Details field in any row, then click Read More below the ASA syslog message ID.



What to do next

Result: The Event Details drawer displays detailed information about an individual event.

Extra information is available in the Event Details window:

  • Last Connected— The timestamp when this users was last connected to the machine.

  • Posture profile information— The posture profile associated with the event. Click the link to view the posture associated with the event.

  • Reason Code— The reason code for VPN incompatibilities.

  • Syslog Information—Syslog information related to the event you are examiningwith timestamps, syslog server IP, and indication of a logging message

At the bottom of the Event Details window click View More Details to view VPN specific event details. The following categories is displayed:

  • Duration— The duration of the event.

  • Machine ID— The unique identifier assigned to the client machine.

  • Redirect ACL— The redirect access control l (ACL) that originates from the user or device.

  • Redirect URL—The URL where a user is automatically sent after attempting to access a different URL.

  • Security group Tag— The unique identifier assigned to a device or user, representing their security role or access level within the network.

  • Audit Session ID— The unique identifier generated and associated with a user's process when they successfully log in or connect.

  • Tunnels— How many tunnels are contained within the VPN profile and tunnel information.

From your search results, you can click an identity or destination and go to their respective detailed report.


View Zero Trust Access Events in the Remote Access Log

View the Enrollment Logs

From the Remote Access Log page (Monitor > Reports > Remote Access Logs) click the Zero trust Access tab. This page displays all the enrollment activity and events for the users in your organization. Some columns may not generate data if they are not applicable to the type of device used to enroll.

The following aspects of the event is addressed:

  • Source - The username that initiated the event or enrollment activity.

  • Event Type - The type of event that triggered an action. Users are either Enrolled or Unenrolled.

  • Event Status - The status of the event, whether it was successful or if it failed.

  • Event Details -The category of activity or action committed. If there are failures, reasons for the failures are displayed here.

  • Public IP address - The public-facing IP address configured in the VPN profile.

  • ZTA client version - The version of the Zero Trust Access client.

  • OS Type and Versions - The OS type and software version of the machine associated with the event.

  • Authentication Method - The type of authentication used to validate the event. At this time supported authentication methods are SAM or Identity certificate.

  • Event Time - The day, year, and timestamp of the event.

Note
In some instances, a single enrollment event generates multiple log lines depending on stage of enrollment. All events related to a single enrollment even will have the same Enrollment ID. This Enrollment ID field is available in the Event Details.

Columns are customizable. Click the gear icon in the upper right of the display table to modify which columns are included in your view. Ensure you apply the changes to save your selection.

Additionally, click the Filters button next to the advanced search bar to filter through the available results for specific components of the report. Use the time range drop-down option to search for a specific time frame; you can also add conditions through this option for specific dates that are not recent.

Note
You can recall previous searches made in the advanced search bar. Note that the recall feature only remembers searches made from your user account for the organization.

Scheduled Reports

You can schedule a report on the ZTA enrollment data in advance. See Schedule a Report for more information.

Export CSV

You can export the history of your organization or a specific query. See Export Report Data to CSV for more information.


View Zero Trust Access Enrollment Logging Event Details

Procedure

  1. Option 1: Click the View Details icon (the blue ellipsis at the right end of each row).

    The View Event Details interface.
  2. Option 2: Hover over an Event Details field in any row, then click Read More below the ASA syslog message ID.



What to do next

Result: The Event Details drawer displays detailed information about an individual event.

Extra information is available in the Event Details window:

  • Date & Time - The timestamp when this event occurred.

  • Source - The username that initiated the event or enrollment activity.

  • Event Status - Denotes whether the action of the event is Successful or a Failure.

  • Authentication Method - The type of authentication used to validate the event. At this time supported authentication methods are SAM or Identity certificate.

  • Public IP address - The public-facing IP address configured in the posture profile.

  • Enrollment ID - The unique Identifier

  • ZTA client version - The version of the Zero Trust Access client.

  • Device - The type of device detected in the event. This reflects the device of the user who initiated the event.

  • OS Type and Versions - The OS type and software version of the machine associated with the event.

  • Event Detail - A brief description of the category of activity or action committed.

From your search results, you can click an identity or destination and go to their respective detailed report.


Schedule a Remote Access Log Report

You can now schedule remote access log reports to be emailed to you at regular intervals. The scheduled report email includes an HTML table preview of the report, a downloadable CSV file containing all available data, and a direct link to a live version of the report in the portal. Any filters applied in the Remote Access Logs view, such as connection event, event details, or identities, are reflected in the scheduled report, ensuring only relevant data is included.

Scheduling is supported for both VPN and Zero Trust remote access logs, allowing tailored reporting based on your security and compliance requirements.

Note
Data older than 30 days cannot be included in scheduled or exported reports.

For step-by-step instructions on how to schedule a report, see Schedule a Report.