We have a Cisco PIX 506, v. 6.3.(4). The syslog is being sent to the server with Firwall Analyzer on UDP port 1025. We are not using the Cisco Emblem format for logs. Right now we have informational level set for syslogs from the PIX
This has been up and running now for 2 days. Today it seems no logs are being analyzed. Yesterday everything seemed fine. This afternoon I noticed that all reports now say "No Data Available".
In terms of setting up, we just had the PIX send the syslog to the ip address and port of the Firwall Analyzer machine. At first FA seemed to identify everything correctly. But I did notice that any reports that were made did not seem to be able to identify properly protocals. All were listed as unassigned, which should not be the case for VPN, FTP, Web, and mail, all of which got heavy use the past couple of days.
Any ideas or tips on what we can do to, or where we can start to look to resolve these issues?