12-30-2020 09:18 AM
My 6509 is configured correctly to send syslog messages to my ManageEngine Eventlog analyzer. The messages are not arriving. I have a ASA FWSM in the 6509. I conduct a packet tracer and the traffic is allowed between the 6509 and Syslog server. I conduct a packet capture and see no UDP 514 traffic from 6509 to Syslog server. Show logging reveals that syslog server is configured correctly and messages are being logged.
6509 config:
logging buffered 32768 informational
no logging console
logging source-interface Vlan910
logging host 10.3.10.6
logging host 10.3.10.26
Show logging:
BLDG300-6509-SW1#sh logging
Syslog logging: enabled (0 messages dropped, 195693 messages rate-limited, 4 flushes, 0 overruns, xml disabled, filtering disabled)
No Active Message Discriminator.
No Inactive Message Discriminator.
Console logging: disabled
Monitor logging: level debugging, 222355 messages logged, xml disabled,
filtering disabled
Logging to: tty1(222307)
Buffer logging: level informational, 2968 messages logged, xml disabled,
filtering disabled
Exception Logging: size (4096 bytes)
Count and timestamp logging messages: disabled
Persistent logging: disabled
Trap logging: level informational, 37925 message lines logged
Logging to 10.3.10.6 (udp port 514, audit disabled,
link up),
37918 message lines logged,
0 message lines rate-limited,
0 message lines dropped-by-MD,
xml disabled, sequence number disabled
filtering disabled
Logging to 10.3.10.26 (udp port 514, audit disabled,
link up),
1250 message lines logged,
0 message lines rate-limited,
0 message lines dropped-by-MD,
xml disabled, sequence number disabled
filtering disabled
Logging Source-Interface: VRF Name:
Vlan910
12-30-2020 09:23 AM - edited 12-30-2020 09:24 AM
trap logging: level informational, 37925 message lines logged Logging to 10.3.10.6 (udp port 514, audit disabled, link up),
as per the message the logs are shipped to 10.3.10.6 and other IP address.
make sure this IP 10.3.10.6 reachable (no FW involved between) using source Vlan910
10.3.10.6 - on thisIP check syslog running ?
12-30-2020 10:02 AM
My apologies. The syslog is running on the other ip 10.3.10.26. I can ping from the 6509 (10.9.10.9) -> Syslog (10.3.10.26). I can ping from Syslog (10.3.10.26) -> 6509 (10.9.10.9).
12-30-2020 12:20 PM
you made the source as VLAN 910, are you able to use a source of VLAN910 and able to ping 10.3.10.26. ?
12-30-2020 10:22 AM
Hello,
--> Syslog logging: enabled (0 messages dropped, 195693 messages rate-limited,
Just to be sure you are not rate limiting the messages, try and disable rate limiting altogether:
no logging rate-limit
12-30-2020 11:48 AM
Thanks for the input. I believe that --> Syslog logging: enabled (0 messages dropped, 195693 messages rate-limited, is old data. This switch's uptime is over 6 years.
Besides, that count is not incrementing and the switch is not configured to rate-limit.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide