> Services > Firewall > FW-Cisco Service

FW-Cisco Service

The FW-Cisco service monitors syslog entries from a Cisco ASA or PIX Firewall.

This service cannot use About self-healing.

Service Type


Instances on a Device


Supported Systems/Applications

Cisco PIX and Cisco ASA firewalls

Device Class


Monitored By

Windows Probe

Scan Interval 5 minutes
Regular Expression for Severity 1 to 5

The strings of characters and metacharacters that you want to use to find predetermined key words in the log files.

You can set a different threshold option for each regular expression.

Status Details

Status Detail


Severity 1

The severity levels reported by MSP N-central are based on the regular expressions that you configure. Up to five (5) different severity levels can be reported using the format \%((PIX\|)?(ASA)|(PIX)\- followed by the number corresponding to the Cisco severity level.

The Cisco severity levels are:

  • \%((PIX\|)?(ASA)|(PIX)\-0 = Emergency
  • \%((PIX\|)?(ASA)|(PIX)\-1 = Alert
  • \%((PIX\|)?(ASA)|(PIX)\-2 = Critical
  • \%((PIX\|)?(ASA)|(PIX)\-3 = Error
  • \%((PIX\|)?(ASA)|(PIX)\-4 = Warning
  • \%((PIX\|)?(ASA)|(PIX)\-5 = Notification
  • \%((PIX\|)?(ASA)|(PIX)\-6 = Informational
  • \%((PIX\|)?(ASA)|(PIX)\-7 = Debugging

Severity 2

Severity 3

Severity 4

Severity 5

The line count matched regex...

The number of lines, in the log file, where the agent has located and returned the keyword. This information is displayed for each regular expression on the status details screen for the service, any applicable reports, and any triggered notifications (except for numeric pages).

The first line matched

This is the first line of the lines that were scanned, not the first line in the file.