CiscoWorks Resource Manager Essentials (RME) has a feature called SyslogAnalyzer which can run automated actions based on certain syslog messages it receives. One of the action types is to execute a script. That action type can be used to have RME forward the contents of a syslog message to another syslog server (or even multiple remote syslog servers). This will work with any version of RME 4.0 and higher including LMS 4.0.
To do this, first copy the following Perl code into a text file on the RME server. Name the file syslog_forward.pl.
use Sys::Syslog qw(:DEFAULT setlogsock);
my $msg = $ARGV;
$Sys::Syslog::host = 'X.X.X.X';
In this script, the string X.X.X.X needs to be replaced with the IP address of the remote syslog server.
Copy this file to the following location.
(NOTE: NMSROOT is the path into which CiscoWorks was installed. By default, this is C:\PROGRA~1\CSCOpx.)
Next, create another file in the same directory into which you copied syslog_forward.pl. On Windows, this file should be named syslog_forward.bat. On Solaris, the file should be named syslog_forward.sh. The file must contain the following.
On Windows, make sure casuser has permissions to Read & Execute C:\WINDOWS\system32\cmd.exe.
Now the automated action needs to be defined in the GUI. Go to RME > Tools > Syslog > Automated Actions (LMS 3.x) or Monitor > Fault Settings > Syslog > Automated Actions (LMS 4.0), and create a new Automated Action. Select the device or devices to which the action will apply, or leave the default radio button for all devices selected. Next, add a syslog message pattern. Since RME will be forwarding syslogs, a pattern of all asterisks (i.e. forward all syslog messages) is probably desirable.
Click Next then select "Script" as the type of action, and choose the syslog_forward.bat (Windows) or syslog_forward.sh (Solaris) script.
Finally, click Finish, and now any message RME receives that matches your filter pattern (any message in this example) will be forwarded to your remote syslog server.
Hello CISCO Community. I have an idea but I am not sure if I am just limited in the IOS to make this work or if there are any other technologies / configurations to make it happen. Basically, I am connecting two switches together with 2 links a...
Hi Guys, Got a strange issue between our core switch SX550-48 to our edge switch SX350-48. We use 4 copper links between the edge and core in a single port channel. The core switch shows all physical links up but the edge side is down. Not sure what ...
Something very strange started happening. I'm looking for a sanity check. We currently use a Radius-As-A-Service to provide authentication for our VPN on a Cisco ASA and ASDM access to that same ASA. Nothing changed on the radius side at all.&nb...
We see this issue quite often, we're staging an MSTP deployment of an NCS2006 M6 with dual TNC-Es, and we constantly lose connection to the shelf in CTC, making it difficult to setup some initial configuration parameters. This issue occurs on multiple she...
Hi, I want to make a PBR with asa 5520 with ios 9.1.x, but I can not put the set ip next-hop command Configuration aclaccess-list acl-pbr-dmz extended permit ip host 184.108.40.206 anyPbr configuration route-map pbr-dmz permit 10match ip addr...