Describes About the Remote Access Log Report in Cisco Secure Access. The Remote Access Log report lists users that have remotely connected to Secure Access and requested access to destinations.
The Remote Access Log report lists connection events for users who connect remotely to Secure Access. Use the report to investigate connection activity, troubleshoot failed sessions, and identify access issues. Some relevant fields include:
-
Display username for failed events – Helps you identify the affected user.
-
ASA syslog message ID – Helps you identify the syslog message associated with the event.
-
Device ID and device name – Helps you identify the endpoint.
-
Machine name – Identifies the client machine when the value is returned for the event.
-
Endpoint posture information – Provides posture details for failed events when posture data is returned.
-
Connection information – Includes the VPN profile, session type, IP addresses, operating system, and Secure Client version.
Use the time-range control and the filter menu to refine the report. Depending on the selected time range and the data returned for that period, you can filter by user, country, region, posture profile, session type, device name, machine name, IP address, VPN profile, reason code, and Security Group Tag information. Some filters provide fixed choices, some provide values found in the report data, and some accept a value that you enter.
You can also hover over a supported value in a table column and select the search control to add that value to the applied filters. Use table settings to change the visible columns or table density. The report supports sorting for supported columns, including User, Region, and VPN Profile.
Select a row to expand its details. The expanded area can include Source, Endpoint Posture, Connection, and Tunnels information. Endpoint Posture details can include the posture attributes evaluated for the event and the posture profile used for the evaluation. If the posture profile is linked, select the link to open that posture profile.
For failed posture checks, the Remote Acess Logs now provide a section in the details panel that include the status, the region, the affected posture profile, and any detected errors such as a disabled firwall or a missing executionable file. an example of such failure is shown here:
You can schedule automatic delivery of Remote Access Log reports or export them as CSV files for further analysis. For more information, see Schedule a Remote Access Log report and Export Report Data to CSV.
The exported CSV file of Remote Access Logs includes the following columns: Date, Time, User, Device Name, Connection Event, Event Details, Public IP, Internal IP, VPN Profile, Session Type, OS Type and Versions, Secure Client Version, Session Duration, and Region.