02-07-2021 10:06 PM
when we are configure cisco router 4461 ios version 17.3.2 ,
i didn't get any log in syslog server(Linux syslog server)
.........................................................................
logging alarm minor
logging on
logging source-interface GigabitEthernet0 vrf Mgmt-intf
logging host 192.168.18.13 vrf Mgmt-intf
logging host 192.168.18.14 vrf Mgmt-intf
logging host 192.168.18.15 vrf Mgmt-intf
logging host 192.168.18.16 vrf Mgmt-intf
ip route vrf Mgmt-intf 0.0.0.0 0.0.0.0 192.168.18.1
flow record LOG-SVR
match ipv4 source address
match ipv4 destination address
match ipv4 protocol
match transport source-port
match transport destination-port
match interface input
collect interface output
collect routing source as
collect routing destination as
!
!
flow exporter FLOW-EXPORTER
destination flow record LOG-SVR
match ipv4 source address
match ipv4 destination address
match ipv4 protocol
match transport source-port
match transport destination-port
match interface input
collect interface output
collect routing source as
collect routing destination as
!
!
flow exporter FLOW-EXPORTER
destination 192.168.18.13
source GigabitEthernet0
!
!
flow monitor LOG-MONITOR
exporter FLOW-EXPORTER
record LOG-SVR
source GigabitEthernet0
!
!
flow monitor LOG-MONITOR
exporter FLOW-EXPORTER
record LOG-SVR
02-08-2021 12:16 AM
Can you ping to the various syslog server addresses specifying source GigabitEthernet0 and vrf Mgmt-intf?
Can you post the first couple of pages of output from show log
02-08-2021 02:44 AM
flow exporter FLOW-EXPORTER destination 192.168.18.13 source GigabitEthernet0
as per the config you using soruce as G0, is this part of VRF ? you have default routing poing towards VRF interface.
check using G0 are you able to reach 192.168.18.13
Note : If this is Linux server (if this is default installation iptables or UFW FW enable - try to disable or add ports required to get Logs to come in)
02-08-2021 03:24 AM
Hello,
which interfaces did you apply to ?
--> interface x ?
--> ip flow monitor LOG-MONITOR input
--> ip flow monitor LOG-MONITOR output
02-08-2021 07:36 AM
These are good questions about flow monitor. But the original post asks about issues with syslog, which is quite different from flow monitor. I still think that the first couple of pages of output from show log will help us understand the issue with syslog. And it is important to verify IP connectivity to the server addresses specifying the source address as G0.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide