02-25-2020 01:39 AM - edited 02-25-2020 01:40 AM
Hi all,
I have Cisco PI 3.7 with 52 switches, 1 WLC, and 51 AP's in the database.
The problem is that PI connect with SSH only on 4 switches and execute the command "enable" in random times.
Does anybody know why he does that, why only on few switches and how to disable this option?
I didn't schedule any user job.
Thx in advance.
02-25-2020 02:19 AM
check what job it running and have a look in the job, what commands issueing in the logs. i suspect this because enable and taking the backup config. until we see what is the job template configured,
02-25-2020 03:22 AM
This is the clean install of PI. I just added devices in the monitoring section.
As I said, there is no additional job defined.
Here are the logs from the switch:
Feb 24 10:33:54.063: %PARSER-5-CFGLOG_LOGGEDCMD: User:prime logged command:!exec: enable
Feb 24 10:33:59.071: %PARSER-5-CFGLOG_LOGGEDCMD: User:prime logged command:!exec: enable
Feb 24 10:50:41.437: %PARSER-5-CFGLOG_LOGGEDCMD: User:prime logged command:!exec: enable
Feb 24 10:51:59.799: %PARSER-5-CFGLOG_LOGGEDCMD: User:prime logged command:!exec: enable
Feb 24 11:06:54.716: %PARSER-5-CFGLOG_LOGGEDCMD: User:prime logged command:!exec: enable
Feb 24 11:06:59.996: %PARSER-5-CFGLOG_LOGGEDCMD: User:prime logged command:!exec: enable
Feb 24 11:17:54.813: %PARSER-5-CFGLOG_LOGGEDCMD: User:prime logged command:!exec: enable
Feb 24 11:18:00.066: %PARSER-5-CFGLOG_LOGGEDCMD: User:prime logged command:!exec: enable
Feb 24 11:35:05.211: %PARSER-5-CFGLOG_LOGGEDCMD: User:prime logged command:!exec: enable
And that's all of the executed commands.
02-25-2020 05:59 AM
Hi,
Prime polls device and collect show commands during inventory sync, during config archive collection which can be triggered via inventory change, syslog change on device.
Also, Monitoring Policy defined for switches like Nexus for vpc data collection involve ssh connection and collect vpc data.
Multi session are connected to perform collection of data and so you may observe ssh connection and enable command execution.
02-25-2020 06:23 AM
Hi,
thank you for your reply, but why I see that logs only on 3-4 switches and on other switches there's no connection and logs.
All switches are 3850 models with the same IOS image.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide