cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
912
Views
0
Helpful
1
Replies

3500xl addr flap syslog traffic

rpsunbeam
Level 1
Level 1

1. 172.31.51.11 172.31.51.11 Oct 17 2006 21:01:37 RTD 1 ADDR_FLAP GigabitEthernet0/1 relearning 5 addrs per min

2. 172.31.51.11 172.31.51.11 Oct 17 2006 20:59:07 RTD 1 ADDR_FLAP GigabitEthernet0/2 relearning 5 addrs per min

I have tons of syslog msg's from a site similar to above. The site has a non cisco wireless installed that creates a moving smorgasbord of mac addresses.

I would prefer not to get these msg's on the management console.. how do i kill just this specific syslog msg without killing all others?

For obvious reasons, I do not want to turn off level 2 syslog traffic and higher. I would prefer to just kill this one type of syslog traffic.

Any suggestions? Either at the switch level or can i filter these somehow in ciscoworks (running latest 2.6 release)?

1 Reply 1

Joe Clarke
Cisco Employee
Cisco Employee

The only way to filter these at the switch would be using the Embedded Syslog Manager. Unfortunately, ESM is not support on XL series switches.

That just leaves the receiving end. You can easily filter these messages in RME by creating a syslog filter under RME > Tools > Syslog > Message Filters. Make sure your Message Filter Type is set to Drop, and create a new filter with the following parameters:

Facility : RTD

Sub-facility : *

Severity : 1

Mnemonic : ADDR_FLAP

Description : *

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Innovations in Cisco Full Stack Observability - A new webinar from Cisco