<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forward Routing Logs to Syslog/Splunk in Routing and SD-WAN</title>
    <link>https://community.cisco.com/t5/routing-and-sd-wan/forward-routing-logs-to-syslog-splunk/m-p/3882811#M317573</link>
    <description>&lt;P&gt;Can you explain more about network log you looking ?&amp;nbsp;&lt;STRONG&gt;network traffic&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 01 Jul 2019 20:03:01 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2019-07-01T20:03:01Z</dc:date>
    <item>
      <title>Forward Routing Logs to Syslog/Splunk</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/forward-routing-logs-to-syslog-splunk/m-p/3882804#M317572</link>
      <description>&lt;P&gt;Currently have logging enabled on my CSR 1000v. I can see configuration changes on splunk, but I cannot see network traffic. Is there a way to configure my logs to forward that information to splunk?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2019 19:56:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/forward-routing-logs-to-syslog-splunk/m-p/3882804#M317572</guid>
      <dc:creator>ElishaDean5574</dc:creator>
      <dc:date>2019-07-01T19:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: Forward Routing Logs to Syslog/Splunk</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/forward-routing-logs-to-syslog-splunk/m-p/3882811#M317573</link>
      <description>&lt;P&gt;Can you explain more about network log you looking ?&amp;nbsp;&lt;STRONG&gt;network traffic&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2019 20:03:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/forward-routing-logs-to-syslog-splunk/m-p/3882811#M317573</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-07-01T20:03:01Z</dc:date>
    </item>
    <item>
      <title>Re: Forward Routing Logs to Syslog/Splunk</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/forward-routing-logs-to-syslog-splunk/m-p/3883169#M317598</link>
      <description>&lt;P&gt;I need to forward traffic being sent through my router to Splunk in order to build a dashboard for network traffic. I have "logging trap debugging" turned on. And, I believe that may have done the trick. ISAKMP and ICMP Debugging is turned on and I am receiving those on Splunk, I am hesitant to turn on IP Debugging to see if it works because that is a lot for the router to process. Do you believe this will send all traffic to Splunk?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 12:23:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/forward-routing-logs-to-syslog-splunk/m-p/3883169#M317598</guid>
      <dc:creator>ElishaDean5574</dc:creator>
      <dc:date>2019-07-02T12:23:01Z</dc:date>
    </item>
    <item>
      <title>Re: Forward Routing Logs to Syslog/Splunk</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/forward-routing-logs-to-syslog-splunk/m-p/3883228#M317600</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think you need at a minimum the below on your router:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;logging trap (trap level)&lt;BR /&gt;logging host (Splunk Server) transport (tcp | udp) port (514)&lt;BR /&gt;logging on&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 13:23:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/forward-routing-logs-to-syslog-splunk/m-p/3883228#M317600</guid>
      <dc:creator>Georg Pauwen</dc:creator>
      <dc:date>2019-07-02T13:23:37Z</dc:date>
    </item>
    <item>
      <title>Re: Forward Routing Logs to Syslog/Splunk</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/forward-routing-logs-to-syslog-splunk/m-p/3883231#M317601</link>
      <description>&lt;P&gt;All of that is enabled. See the images I attached with my message.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 13:25:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/forward-routing-logs-to-syslog-splunk/m-p/3883231#M317601</guid>
      <dc:creator>ElishaDean5574</dc:creator>
      <dc:date>2019-07-02T13:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: Forward Routing Logs to Syslog/Splunk</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/forward-routing-logs-to-syslog-splunk/m-p/3883306#M317606</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You don't use logging to send the traffic to a remote device and even if you turned on ip debugging (which you don't want to do on a production router) it won't send the actual packets.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to send the packets you need to mirror the port your router is on and then send on copy of that traffic to the port your server is connected to assuming your switch etc. supports that functionality.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 15:27:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/forward-routing-logs-to-syslog-splunk/m-p/3883306#M317606</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2019-07-02T15:27:11Z</dc:date>
    </item>
    <item>
      <title>Re: Forward Routing Logs to Syslog/Splunk</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/forward-routing-logs-to-syslog-splunk/m-p/3883371#M317608</link>
      <description>&lt;P&gt;We didn't enable ip debugging, I'm aware that would likely brick the CSR. However, we don't want to actually see the packets, we want to see the amount of traffic in real time. So that we can see the busiest times of day for example.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 17:32:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/forward-routing-logs-to-syslog-splunk/m-p/3883371#M317608</guid>
      <dc:creator>ElishaDean5574</dc:creator>
      <dc:date>2019-07-02T17:32:48Z</dc:date>
    </item>
  </channel>
</rss>

