cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
440
Views
0
Helpful
4
Replies

we didn't get any log in syslog server

SK Faisal
Level 1
Level 1

when we are configure cisco router 4461 ios version 17.3.2 ,

 

i didn't get any log in syslog server(Linux syslog server)

 

.........................................................................

logging alarm minor

logging on 
logging source-interface GigabitEthernet0 vrf Mgmt-intf
logging host 192.168.18.13 vrf Mgmt-intf
logging host 192.168.18.14 vrf Mgmt-intf
logging host 192.168.18.15 vrf Mgmt-intf
logging host 192.168.18.16 vrf Mgmt-intf

ip route vrf Mgmt-intf 0.0.0.0 0.0.0.0 192.168.18.1


flow record LOG-SVR
match ipv4 source address
match ipv4 destination address
match ipv4 protocol
match transport source-port
match transport destination-port
match interface input
collect interface output
collect routing source as
collect routing destination as
!
!
flow exporter FLOW-EXPORTER
destination flow record LOG-SVR
match ipv4 source address
match ipv4 destination address
match ipv4 protocol
match transport source-port
match transport destination-port
match interface input
collect interface output
collect routing source as
collect routing destination as
!
!
flow exporter FLOW-EXPORTER
destination 192.168.18.13
source GigabitEthernet0
!
!
flow monitor LOG-MONITOR
exporter FLOW-EXPORTER
record LOG-SVR

source GigabitEthernet0
!
!
flow monitor LOG-MONITOR
exporter FLOW-EXPORTER
record LOG-SVR

 

 

 

4 Replies 4

Richard Burts
Hall of Fame
Hall of Fame

Can you ping to the various syslog server addresses specifying source GigabitEthernet0 and vrf Mgmt-intf?  

Can you post the first couple of pages of output from show log

HTH

Rick

balaji.bandi
Hall of Fame
Hall of Fame
flow exporter FLOW-EXPORTER
destination 192.168.18.13
source GigabitEthernet0

as per the config you using soruce as G0, is this part of VRF ? you have default routing poing towards VRF interface.

 

check using G0 are you able to reach 192.168.18.13

 

Note : If this is Linux server (if this is default installation iptables or UFW FW enable - try to disable or add ports required to get Logs to come in)

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hello,

 

which interfaces did you apply to ?

 

--> interface x ?
--> ip flow monitor LOG-MONITOR input
--> ip flow monitor LOG-MONITOR output

These are good questions about flow monitor. But the original post asks about issues with syslog, which is quite different from flow monitor. I still think that the first couple of pages of output from show log will help us understand the issue with syslog. And it is important to verify IP connectivity to the server addresses specifying the source address as G0.

HTH

Rick
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Innovations in Cisco Full Stack Observability - A new webinar from Cisco