07-24-2024 10:48 PM
Hello everyone,
This week, we upgraded ACI from release 4.2(7f) to 5.2(8i). The process was straightforward and went smoothly. However, since the upgrade, we have encountered an issue with log reception.
Without changing any configurations, in the previous release, we received ACLLOG_PKTLOG permit and deny logs related to L3 connections passing through the leafs on our external Syslog server.
Since the upgrade, this no longer occurs. With the configuration unchanged, we currently receive logs related to interfaces up/down, percentages of packet drops in the last connection, and similar logs.
Additional details:
I would like to ask if anyone has more information regarding this issue and how we might resolve it.
Thank you very much for your support.
Solved! Go to Solution.
10-29-2024 02:52 AM
Hello @kekkophone
It sounds like the upgrade to ACI 5.2(8i) may have introduced changes that affect how ACL logs are generated or forwarded. Here are some steps and considerations to help you troubleshoot and resolve the issue:
Ensure that the ACL logging configuration is still intact and correctly set up. Sometimes, upgrades can reset or alter configurations.
Ensure that the Syslog configuration on the ACI fabric is still correctly set up to forward the desired logs.
Review the release notes and documentation for ACI 5.2(8i) to identify any changes related to logging or ACLs. There might be new features, bug fixes, or changes in behavior that affect log generation or forwarding.
If the above steps do not resolve the issue, you can enable more detailed logging to diagnose the problem.
Check Cisco's bug tracker and support forums for any known issues related to ACL logging in ACI 5.2(8i). There might be a known bug or a required patch.
Create a test ACL with logging enabled and generate traffic that matches the ACL. Check if the logs are generated and forwarded to the Syslog server.
If the issue persists, consider reaching out to Cisco TAC for support. Provide them with detailed information about your configuration and the issue you're facing.
Navigate to the Tenant:
Check ACL Rules:
Navigate to Syslog Settings:
Check Syslog Server Configuration:
Navigate to Logging Settings:
Increase Verbosity:
By following these steps, you should be able to identify and resolve the issue with ACL log reception on your external Syslog server after the ACI upgrade.
10-29-2024 02:52 AM
Hello @kekkophone
It sounds like the upgrade to ACI 5.2(8i) may have introduced changes that affect how ACL logs are generated or forwarded. Here are some steps and considerations to help you troubleshoot and resolve the issue:
Ensure that the ACL logging configuration is still intact and correctly set up. Sometimes, upgrades can reset or alter configurations.
Ensure that the Syslog configuration on the ACI fabric is still correctly set up to forward the desired logs.
Review the release notes and documentation for ACI 5.2(8i) to identify any changes related to logging or ACLs. There might be new features, bug fixes, or changes in behavior that affect log generation or forwarding.
If the above steps do not resolve the issue, you can enable more detailed logging to diagnose the problem.
Check Cisco's bug tracker and support forums for any known issues related to ACL logging in ACI 5.2(8i). There might be a known bug or a required patch.
Create a test ACL with logging enabled and generate traffic that matches the ACL. Check if the logs are generated and forwarded to the Syslog server.
If the issue persists, consider reaching out to Cisco TAC for support. Provide them with detailed information about your configuration and the issue you're facing.
Navigate to the Tenant:
Check ACL Rules:
Navigate to Syslog Settings:
Check Syslog Server Configuration:
Navigate to Logging Settings:
Increase Verbosity:
By following these steps, you should be able to identify and resolve the issue with ACL log reception on your external Syslog server after the ACI upgrade.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide