Software Secure Access
Activity Manage

Cisco Secure Access Help Manage Logging Log Formats and Versioning Remote Access VPN Log Formats Examples

Last updated: Aug 07, 2025

Examples

This is an example v12 Secure Access VPN log of a CONNECTED event:

timestamp,hostname,aws region,event type,origin ids,origin type,user id,organization id,retention days,storage location,msp organization id,session id,session type,vpn profile,public ip,assigned ip,connected at,disconnection reason,os version,anyconnect version,asa syslog id,device id,machine id,public ipv6,assigned ipv6,security group tag,dap record name,dap connection type,failed reasons,log message,asa syslog severity,asa syslog class,asa syslog description
"2024-09-11 21:40:51","hostname-example","us-east-1","CONNECTED","\[1296793508\]","7","example-userid","8236318","365","us","","1486","IKEv2","CiscoSecureAccessVPN","24.123.132.133","10.10.1.100","","","Mac OS X 14.6.1","5.1.2.42","ASA-5-109201","DEVICE-M-L9XH","","n/a","n/a","10","","","[]","AAA Marking param1 server param2 as FAILED","5","INFORMATION","AAA-ERROR"

This is an example of v12 Secure Access VPN log of a DISCONNECTED event:

timestamp,hostname,aws region,event type,origin ids,origin type,user id,organization id,retention days,storage location,msp organization id,session id,session type,vpn profile,public ip,assigned ip,connected at,disconnection reason,os version,anyconnect version,asa syslog id,device id,machine id,public ipv6,assigned ipv6,security group tag,dap record name,dap connection type,failed reasons,log message,asa syslog severity,asa syslog class,asa syslog description	
"2024-09-11 22:28:52","hostname-example","us-east-1","DISCONNECTED","\[1290579891\]","7","example-userid","8236318","365","us","","1476","TLS","CiscoSecureAccessVPN","24.123.132.133","10.10.1.100","2024-09-11T19:54:05Z","User Requested","Mac OS X 14.6.1","5.0.05040","ASA-4-113019","DEVICE-M-F1PG","","n/a","n/a","10","","","[]","AAA Marking param1 server param2 as FAILED","5","INFORMATION","AAA-ERROR"

This is an example of v12 Secure Access VPN log of a failed AUTHORIZATION-CHECK event:

timestamp,hostname,aws region,event type,origin ids,origin type,user id,organization id,retention days,storage location,msp organization id,session id,session type,vpn profile,public ip,assigned ip,connected at,disconnection reason,os version,anyconnect version,asa syslog id,device id,machine id,public ipv6,assigned ipv6,security group tag,dap record name,dap connection type,failed reasons,log message,asa syslog severity,asa syslog class,asa syslog description
"2024-09-11 21:40:51","hostname-example","us-east-1","FAILED","\[1296793508\]","7","example-userid","8236318","365","us","","1486","IKEv2","CiscoSecureAccessVPN","24.123.132.133","10.10.1.100","","","Mac OS X 14.6.1","5.1.2.42","ASA-5-109201","DEVICE-M-L9XH","","n/a","n/a","10","","","\["AUTHORIZATION-CHECK"\]","AAA Marking param1 server param2 as FAILED","5","INFORMATION","AAA-ERROR"

This is an example of v12 Secure Access VPN log of a failed CERT-AUTH-CHECK event:

timestamp,hostname,aws region,event type,origin ids,origin type,user id,organization id,retention days,storage location,msp organization id,session id,session type,vpn profile,public ip,assigned ip,connected at,disconnection reason,os version,anyconnect version,asa syslog id,device id,machine id,public ipv6,assigned ipv6,security group tag,dap record name,dap connection type,failed reasons,log message,asa syslog severity,asa syslog class,asa syslog description
"2024-09-11 21:40:51","hostname-example","us-east-1","FAILED","\[1296793508\]","7","example-userid","8236318","365","us","","1486","IKEv2","CiscoSecureAccessVPN","24.123.132.133","10.10.1.100","","","Mac OS X 14.6.1","5.1.2.42","ASA-5-109201","DEVICE-M-L9XH","","n/a","n/a","10","","","\["CERT-AUTH-CHECK"\]","AAA Marking param1 server param2 as FAILED","5","INFORMATION","AAA-ERROR"