01-17-2024 02:39 AM
Hi all,
we receive plenty of bad bgp updates from one of our ISP peer
we are able to filter out some messages with the logging discriminator but this only works for logs and lines which include facility+severity+mnemonic and all other lines are not filtered
**MSG 42366 CONTINUATION #01** 4400 0022 4400 0022
4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022
4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4402 FF00 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400**MSG 42366 TRUNCATED**
**MSG 42366 CONTINUATION #02** 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400**MSG 42366 TRUNCATED**
**MSG 42366 CONTINUATION #03** 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
I am able to show or filter it with the cli show command
sh logging | e ^(([0-9A-F])+_)
**MSG 42372 CONTINUATION #03** 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022
**MSG 42372 CONTINUATION #04**
**MSG 42372 CONTINUATION #05**0022 4400 0022 4400
**MSG 42372 CONTINUATION #06**0022 4400 0022 4400 0022 4400 0022 4400
**MSG 42372 CONTINUATION #07**0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
**MSG 42372 TRUNCATED**
**MSG 42372 CONTINUATION #08**0022 4400 031B 90C0 0810 0EAE 1B5E 1D31 0002 1D31 5235 1D31 7AB7 900E 002C 0002
or
sh logging | e \**MSG
4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022
4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022
4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022
4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022
4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022
4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022
4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022
but not with the logging discriminator
So the question > how to filter these lines ???
Many Thanks
Maik
01-23-2024 02:36 AM
thanks - yes I also want to solve the real issue - what I wanted to say was that I don't filter out specific path or prefixes as it changes and it's not always the same as or the same ipv6 prefix with that issue and we do not have the problem on other ISP and router - only by one ISP. I guess the other provider have some filters implemented and do not advertise this update to us. But as they are not able or willing to support or fix I am looking for an option if it would be possible to filter it incoming out or at least disable the logging for it
01-23-2024 02:41 AM
the bug shpukld be fixed in 16.6.5 shouldn't it ?
01-23-2024 02:49 AM
In the link I shared there are two bug did you check both ?
thanks
MHM
01-23-2024 02:55 AM
Hi - I found only CSCva92216 in the post
01-23-2024 03:05 AM
I found this one here
I will try as we have only advertised for one
Neighbor capabilities:
Route refresh: advertised and received(new)
Four-octets ASN Capability: advertised and received
Address family IPv6 Unicast: advertised and received
Graceful Restart Capability: received
Remote Restart timer is 120 seconds
Address families advertised by peer:
none
Enhanced Refresh Capability: advertised
01-23-2024 03:19 AM
I wish you great success in this task
MHM
01-26-2024 04:41 AM
did not help - still received lots of messages
TAC case opened > they could reproduce it
01-19-2024 01:35 AM
Can you attach complete logs to assists here start line to end line
or you can use : (mnemonics) - may try.
#logging discriminator ?
WORD discriminator name; string; max. 8 characters
#logging discriminator FILTERLOG ?
facility Facility pattern for messsage filtering
mnemonics Mnemonics pattern for messsage filtering
msg-body Msg-body pattern for messsage filtering
rate-limit Rate-limit value for messsage rate control
severity Severity group for messsage filtering
<cr>
example - this need to be test on your environment :
logging discriminator FILTERLOG mnemonics drops MSGDUMP_LIMIT|CONTINUATION|TRUNCATED
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide