ASA syslog logging in multiple context mode

When applying syslog to security contexts within an ASA device, each context is considered a separate and discrete device. In other words, if you configure syslog on the admin context, then syslog will only operate within the confines of that specific context.

It is not possible to channel all syslog messages for all the contexts of the physical device out of a single context like the admin context. In other words, there is no native method of causing an ASA to collect or send a single stream of syslog messages for the whole device.

To achieve something like that, you would have to use a Syslog relay or proxy.

Links:

https://forum.networklessons.com/t/cisco-asa-syslog-configuration/837/8?u=lagapides

https://community.cisco.com/t5/network-security/asa-contexts-and-syslog/td-p/2674438