11-07-2024 06:21 PM
Hello,
I have setup Cisco Catalyst 9200 to send log to syslog server and the syslog server manage to get the log. The only things that I didn't expect is the log appear in the syslog server is in a single log file for each line of log from the Catalyst switch. Is there any configuration we can do on the Catalyst 9200 to send the log to a same single log file? Below is the configuration done on the Catalyst 9200 and the example of the log file on the Syslog server.
logging host x.x.x.x transport tcp port 514
Thank you.
11-07-2024 06:27 PM
@matdan16 hi, hope you are using some syslog server in the linux distribution. this log file creation is depends on the log server you are using. switch will keep sending the syslogs to the configured IP through port 514. but receiving server is responsible to catch them and store. so syslog server need to configure it so store as single file or multiple files.
11-08-2024 12:04 AM
Hi @Kasun Bandara , thank you for your reply. I also setup for Nexus 9000 & Cisco APIC to push log to the same syslog server and the log appear only to one single same file.
Thank you.
11-08-2024 12:18 AM
This only command you add?
MHM
11-08-2024 02:03 AM
Could you please share the output of "sh run | s logging" for review?
11-10-2024 05:24 PM
Here are the results of the "sh run | s logging".
logging console critical
logging monitor notifications
logging source-interface Vlanxx
logging host x.x.x.x transport tcp port 514
logging synchronous
logging synchronous
Thank you
11-11-2024 02:54 AM
Thanks, I don't see anything odd on the output. Would you mind please to share the same command output adding "all" keyword after "run":
sh run all | s logging
11-11-2024 07:47 PM
Here is the output of "sh run all | s logging".
no service pt-vty-logging
no logging discriminator
logging exception 4096
no logging count
no logging message-counter log
no logging message-counter debug
logging message-counter syslog
no logging snmp-authfail
no logging userinfo
logging buginf
logging queue-limit 1024
logging queue-limit esm 0
logging queue-limit trap 1024
logging buffered 4096 debugging
logging reload message-limit 1000 notifications
no logging persistent
logging rate-limit console 40 except errors
no logging console guaranteed
logging console critical
logging monitor notifications
logging cns-events informational
logging on
ip dhcp conflict logging
no authentication logging verbose
no access-session wireless event-logging enable session-limit 0 event-limit 0
access-session event-logging enable session-limit 600 event-limit 400
no mab logging verbose
no device-tracking logging packet drop
no device-tracking logging theft
no device-tracking logging resolution-veto
no dot1x logging verbose
logging event link-status
*****repeated same output*****
logging event link-status
logging esm config
logging history size 1
logging history warnings
logging trap informational
logging delimiter tcp
no logging origin-id
logging facility local7
logging source-interface Vlanxx
logging server-arp
logging host x.x.x.x transport tcp port 514
snmp-server enable logging setop
logging synchronous
logging synchronous
no device-tracking binding logging
netconf-yang cisco-ia logging ciaauthd-log-level error
netconf-yang cisco-ia logging confd-log-level error
netconf-yang cisco-ia logging nes-log-level error
netconf-yang cisco-ia logging onep-log-level error
netconf-yang cisco-ia logging sync-log-level error
Thank you!
11-12-2024 01:16 AM
I still can't see anything odd. I would suggest getting engaged with TAC at this point.
11-11-2024 03:00 AM
do you use any EEM or Schedule backup ??
MHM
11-11-2024 07:57 PM - edited 11-11-2024 07:57 PM
Hi @MHM Cisco World ,
Yes, I do setup schedule backup. Below is the configuration if you require it.
kron occurrence Weekly_Sat_3AM at 3:00 Sat recurring
policy-list Kron_Backup_Config_to_SFTP
kron policy-list Kron_Backup_Config_to_SFTP
cli event manager run Backup_Config_to_SFTP
event manager applet Backup_Config_to_SFTP
description **Upload running-config into SFTP server**
event none
action 0.01 info type routername
action 1.01 cli command "enable"
action 1.02 cli command "show clock"
action 1.03 regexp "(2[0-3]|[01][0-9]):([0-6][0-9]):([0-6][0-9])" "$_cli_result" time hour minute second
action 1.11 cli command "show clock"
action 1.12 regexp "(Jan|Feb|Mar|Apr|May|Jun|Jul|Aug|Sep|Oct|Nov|Dec) ([1-9]|0[1-9]|[1-2][0-9]|3[0-1]) (20[1-9][0-9])" "$_cli_result" time2 month day year
action 2.01 cli command "configure terminal"
action 2.02 cli command "file prompt quiet"
action 2.03 cli command "do copy running-config sftp://***/$_info_routername/$_info_routername-$year$month$day-$hour$minute.log"
action 2.04 cli command "no file prompt quiet"
Thank you!
11-12-2024 09:35 AM
11-25-2024 12:21 AM
Hi @MHM Cisco World ,
Thanks. I'll let the linux/server team to look for this and see the results after it.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide