cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1207
Views
5
Helpful
22
Replies

logging filter and discriminator does not work

maik.hahn
Level 1
Level 1

Hi all,

we receive plenty of bad bgp updates from one of our ISP peer

we are able to filter out some messages with the logging discriminator but this only works for logs and lines which include facility+severity+mnemonic and all other lines are not filtered

**MSG 42366 CONTINUATION #01** 4400 0022 4400 0022
4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022
4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4402 FF00 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400**MSG 42366 TRUNCATED**
**MSG 42366 CONTINUATION #02** 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400**MSG 42366 TRUNCATED**
**MSG 42366 CONTINUATION #03** 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400

I am able to show or filter it with the cli show command

sh logging | e ^(([0-9A-F])+_)
**MSG 42372 CONTINUATION #03** 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022
**MSG 42372 CONTINUATION #04**
**MSG 42372 CONTINUATION #05**0022 4400 0022 4400
**MSG 42372 CONTINUATION #06**0022 4400 0022 4400 0022 4400 0022 4400
**MSG 42372 CONTINUATION #07**0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400
**MSG 42372 TRUNCATED**
**MSG 42372 CONTINUATION #08**0022 4400 031B 90C0 0810 0EAE 1B5E 1D31 0002 1D31 5235 1D31 7AB7 900E 002C 0002
 or

sh logging | e \**MSG

4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022
4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022
4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022
4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022
4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022
4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022
4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022 4400 0022

 but not with the logging discriminator

So the question > how to filter these lines ???

Many Thanks

Maik

22 Replies 22

thanks - yes I also want to solve the real issue - what I wanted to say was that I don't filter out specific path or prefixes as it changes and it's not always the same as or the same ipv6 prefix with that issue and we do not have the problem on other ISP and router - only by one ISP. I guess the other provider have some filters implemented and do not advertise this update to us. But as they are not able or willing to support or fix I am looking for an option if it would be possible to filter it incoming out or at least disable the logging for it

the bug shpukld be fixed in 16.6.5 shouldn't it ?

In the link I shared there are two bug did you check both ?
thanks 
MHM

Hi - I found only CSCva92216 in the post

I found this one here

https://www.cisco.com/c/en/us/support/docs/ip/border-gateway-protocol-bgp/116189-problemsolution-technology-00.pdf

I will try as we have only advertised for one

Neighbor capabilities:
Route refresh: advertised and received(new)
Four-octets ASN Capability: advertised and received
Address family IPv6 Unicast: advertised and received
Graceful Restart Capability: received
Remote Restart timer is 120 seconds
Address families advertised by peer:
none
Enhanced Refresh Capability: advertised

I wish you great success in this task 
MHM

did not help - still received lots of messages

TAC case opened > they could reproduce it

balaji.bandi
Hall of Fame
Hall of Fame

Can you  attach complete logs to assists here start line to end line

or you can use : (mnemonics) - may try.

#logging discriminator ?
WORD discriminator name; string; max. 8 characters

#logging discriminator FILTERLOG ?
facility Facility pattern for messsage filtering
mnemonics Mnemonics pattern for messsage filtering
msg-body Msg-body pattern for messsage filtering
rate-limit Rate-limit value for messsage rate control
severity Severity group for messsage filtering
<cr>

example - this need to be test on your environment :

 

logging discriminator  FILTERLOG mnemonics drops MSGDUMP_LIMIT|CONTINUATION|TRUNCATED

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help