<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WLC-5508 logging to syslog in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-5508-logging-to-syslog/m-p/1809547#M8201</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Syslog doesn't give much.&amp;nbsp; All of the auth/deauth messages, etc. are sent via SNMP trap.&amp;nbsp; Here are some OID's that can be useful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.3.6.1.4.1.14179.2.6.3.70&amp;nbsp; Signature attack - Deauth Flood&lt;/P&gt;&lt;P&gt;1.3.6.1.4.1.14179.2.6.3.55&amp;nbsp; Potential denial of service attack&lt;/P&gt;&lt;P&gt;1.3.6.1.4.1.14179.2.6.3.42 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Radios exceed license count&lt;/P&gt;&lt;P&gt;1.3.6.1.4.1.14179.2.6.3.44&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Sensed temperature too high&lt;/P&gt;&lt;P&gt;1.3.6.1.4.1.14179.2.6.3.47&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;POE controller failure&lt;/P&gt;&lt;P&gt;1.3.6.1.4.1.14179.2.6.3.56&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Too many unsuccessful login attempts&lt;/P&gt;&lt;P&gt;1.3.6.1.4.1.14179.2.6.3.59&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Rogue AP detected on wired network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think syslog will catch things like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Web authentication failure for station&lt;/P&gt;&lt;P&gt;Login failed for the user:&lt;/P&gt;&lt;P&gt;Authentication failed for network user&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 01 Mar 2012 20:06:48 GMT</pubDate>
    <dc:creator>MikeM-2468</dc:creator>
    <dc:date>2012-03-01T20:06:48Z</dc:date>
    <item>
      <title>WLC-5508 logging to syslog</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5508-logging-to-syslog/m-p/1809543#M8197</link>
      <description>&lt;P&gt;It appears that there are two different types of log information generated by the WLC-5508.&amp;nbsp; The stuff that can be sent directly to syslog seems to be very basic while most of the good log information is sent via snmp trap.&amp;nbsp; Does anyone have this setup to log to a SIEM in a manner that gives a good security view into the wireless controller?&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 04:10:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5508-logging-to-syslog/m-p/1809543#M8197</guid>
      <dc:creator>MikeM-2468</dc:creator>
      <dc:date>2021-07-04T04:10:29Z</dc:date>
    </item>
    <item>
      <title>WLC-5508 logging to syslog</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5508-logging-to-syslog/m-p/1809544#M8198</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried to change the logging level on the wlc? There are multiple levels of logging that can be set on the wlc. On the wlc GUI, you can check the current logging level by navigating to this page - Management &amp;gt; Logs &amp;gt; Config &amp;gt; Syslog Server. Under the "Syslog Server", you can change the level of logging.　&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P align="left"&gt;&lt;SPAN style="font-size: 10pt;"&gt;If you set a logging level, only those messages whose severity is equal to or less than that level are logged by the controller. Note that setting a higher logging level on the wlc might result in more logs sent to the syslog server. &lt;/SPAN&gt;&lt;/P&gt;&lt;P align="left"&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P align="left"&gt;&lt;SPAN style="font-size: 10pt;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P align="left"&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P align="left"&gt;&lt;SPAN style="font-size: 10pt;"&gt;Nagendra&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Dec 2011 06:46:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5508-logging-to-syslog/m-p/1809544#M8198</guid>
      <dc:creator>naks</dc:creator>
      <dc:date>2011-12-13T06:46:35Z</dc:date>
    </item>
    <item>
      <title>WLC-5508 logging to syslog</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5508-logging-to-syslog/m-p/1809545#M8199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the reply.&amp;nbsp; I'm very familiar with logging levels.&amp;nbsp; The fact is that the WLC provides very little security relevant information via syslog.&amp;nbsp; Most is sent via SNMP trap.&amp;nbsp; I'll be using SNMP traps for this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Dec 2011 12:12:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5508-logging-to-syslog/m-p/1809545#M8199</guid>
      <dc:creator>MikeM-2468</dc:creator>
      <dc:date>2011-12-13T12:12:43Z</dc:date>
    </item>
    <item>
      <title>WLC-5508 logging to syslog</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5508-logging-to-syslog/m-p/1809546#M8200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you get what you wanted out of SNMP for the logging information?&amp;nbsp; I'm trying to work with my (reluctant) network admin to send WLC logs to my SIEM device, but all I'm seeing is unimportant, mostly non-security related logs.&amp;nbsp; I don't even get a log when users attach to wireless or any other useful kinds of info.&amp;nbsp; (logging level is set to 6).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just looking for some suggestions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Mar 2012 19:48:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5508-logging-to-syslog/m-p/1809546#M8200</guid>
      <dc:creator>jaymartin</dc:creator>
      <dc:date>2012-03-01T19:48:16Z</dc:date>
    </item>
    <item>
      <title>WLC-5508 logging to syslog</title>
      <link>https://community.cisco.com/t5/wireless/wlc-5508-logging-to-syslog/m-p/1809547#M8201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Syslog doesn't give much.&amp;nbsp; All of the auth/deauth messages, etc. are sent via SNMP trap.&amp;nbsp; Here are some OID's that can be useful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.3.6.1.4.1.14179.2.6.3.70&amp;nbsp; Signature attack - Deauth Flood&lt;/P&gt;&lt;P&gt;1.3.6.1.4.1.14179.2.6.3.55&amp;nbsp; Potential denial of service attack&lt;/P&gt;&lt;P&gt;1.3.6.1.4.1.14179.2.6.3.42 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Radios exceed license count&lt;/P&gt;&lt;P&gt;1.3.6.1.4.1.14179.2.6.3.44&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Sensed temperature too high&lt;/P&gt;&lt;P&gt;1.3.6.1.4.1.14179.2.6.3.47&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;POE controller failure&lt;/P&gt;&lt;P&gt;1.3.6.1.4.1.14179.2.6.3.56&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Too many unsuccessful login attempts&lt;/P&gt;&lt;P&gt;1.3.6.1.4.1.14179.2.6.3.59&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Rogue AP detected on wired network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think syslog will catch things like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Web authentication failure for station&lt;/P&gt;&lt;P&gt;Login failed for the user:&lt;/P&gt;&lt;P&gt;Authentication failed for network user&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Mar 2012 20:06:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-5508-logging-to-syslog/m-p/1809547#M8201</guid>
      <dc:creator>MikeM-2468</dc:creator>
      <dc:date>2012-03-01T20:06:48Z</dc:date>
    </item>
  </channel>
</rss>

