04-26-2013 10:30 AM
I'm running CW LMS 4.0.1 and I see in packet captures on my PC that my CiscoWorks server is sending syslog entries to my PC that are getting rejected because I'm not running a syslog server application. I want to stop receiving these syslog entries. I'm sure this is a simple setting somewhere, but for the life of me I can't find it anywhere. Does anybody know how I can stop receiving these syslog entries? Any help would be much appreciated.
Thank you,
Rob
04-26-2013 12:39 PM
It could have been setup as a remote syslog collector under Admin > Collection Settings > Syslog > Syslog Collection Settings. (Reference)
04-26-2013 12:53 PM
That was my first thought, but there is nothing entered there. I wonder if something was left behind from a previous version after an upgrade.
Rob
04-26-2013 12:58 PM
If you're running on a Windows host, there might be another forwarder operating outside of LMS. These can sometimes run as a service and not be obvious at first (or second) glance.
Check your Services from the Windows admin tools. Also, if you run tcpview (free Microsoft download) on the server you can confirm what process (and thus what application) is opening the connections to your local machine.
04-26-2013 01:35 PM
It definitely looks like it's the Ciscoworks application running as a system process over port 1741.
04-26-2013 02:28 PM
Can you provide a packet capture?
04-26-2013 03:05 PM
Packet capture added to my original post.
04-26-2013 03:15 PM
That capture shows syslog messages from a Cisco router at 10.80.1.1 to a Dell host at 10.96.17.10.
So that capture would seem to indicate the router (not LMS) has the host defined as a log server.
04-26-2013 03:17 PM
Oops. My bad.
04-26-2013 03:26 PM
In addition it seems FastEthernet0/170 & FastEthernet0/180 seem to be going up & down often.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide