cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
826
Views
0
Helpful
2
Replies
Highlighted
Beginner
Beginner

NX-OS 5.0(4d) / MDS-9124/9148 and Syslog

Hi!

I'm trying to get some SAN-switches (9124/9148 with NX-OS 5.0(4d) to log everything to a syslog server.

From looking in the manuals it seems like "logging server <ip-address> <severity>" should do the trick, but when i tested with using severity 6, i couldnt see anything on the syslog server from something like logging in or logging out, which i assumed should be logged to the syslog-server.

In short due to paranoia and security, the security people wants everything (including logins, logouts etc) that happens on the switches to be logged to a syslog server.

So if anyone has any pointers on this that would be great :-)

Everyone's tags (3)
2 REPLIES 2
Highlighted
Beginner

NX-OS 5.0(4d) / MDS-9124/9148 and Syslog

what is the output of show logging server ?

you should get something similar to this.

switch# show logging server

Logging server: enabled

{IP address}

server severity: debugging

server facility: local7

Highlighted
Beginner

NX-OS 5.0(4d) / MDS-9124/9148 and Syslog

Configuration is simple(on the core switch)

1) Config t

2) logging server 192.168.1.1

3) logging server 192.168.1.2

4) logging distribute

5) logging commit

On the Edge

1) sh cfs application name syslogd

2) show logging server

NOTE: By default the log level is local7 --> which is pretty much ur security folks will need.