cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
463
Views
0
Helpful
4
Replies

PIX syslog servers

abevers
Level 1
Level 1

Our pix is sending syslog messages to two servers. The servers archive messages every hour. Why would one server have 2% larger files than the other? Does the pix have a first choice server? thanks

4 Replies 4

Solace
Level 1
Level 1

Is your syslog software configured the same on both machines? They could be logging at different log levels. The same goes for the PIX, it can log at different log levels to different syslog servers.

The software (Kiwi) is configured the same but the machines are not. One is an XP workstation and one is a 2003 server. Is there a way to tell if messages are being dropped? maybe compare message count on the pix with message count on the servers?

Are both disk partitions NTFS or FAT? If they are different file structures, then that would clearly explain it. It might also be the file structure on the server versus workstation. All things being equal, you should expect equal file sizes, but all things are not equal in your configuration.

tbissett
Level 1
Level 1

Also, don't forget that unless you are using syslog over TCP, syslog is based on UDP (i.e. "spray and pray"). There is no guarantee of delivery with UDP, so occasional messages could be dropping within your network.

Review Cisco Networking for a $25 gift card