cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2602
Views
3
Helpful
5
Replies

Setting Syslog Notifications on WLC

InquiringTech
Level 3
Level 3

Where do you actually set the syslog on the C9800 WLC (in our case an EWC)?

I see something under Administration > Management > Logging but that doesn't seem to work

InquiringTech_0-1678117070352.png

Then there is something under Configuration > Tags & Profiles > AP Join > ap profile > Management tab, under System Log:

InquiringTech_1-1678117222967.png

I think this might be the actual spot for it? How do I set it up so that it sends messages for authentication issues for clients trying to join APs? I see a variety of Facility and Log Trap Values. What levels do I need to set to see this?

But I don't seem to be getting anything on our actual syslog from it. I configured it so that it should get messages from the management IP of the EWC.

1 Accepted Solution

Accepted Solutions

Mark Elsen
Hall of Fame
Hall of Fame

 

 - FYI : https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-3/config-guide/b_wl_17_3_cg/m_syslog_server.html#id_135864

 M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

View solution in original post

5 Replies 5

Mark Elsen
Hall of Fame
Hall of Fame

 

 - FYI : https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-3/config-guide/b_wl_17_3_cg/m_syslog_server.html#id_135864

 M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

Thanks. Now I am getting logs at my syslog server, but don't seem to be getting them for the client that is having trouble authenticating and joining the network for some reason, even with the wireless client syslog-detailed command and trap level 5 set (getting a lot of client exclusion messages for other, presumably rogue clients). But that's actually a bigger problem that I may make a separate thread for.

what radius you using for client to get authentication, if you using ISE it has all the information.

check below EWC Log level or post what config you have on the device ?

https://www.cisco.com/c/en/us/td/docs/wireless/controller/ewc/17-1/config-guide/ewc_cg_17_11/enabling_syslog_messages_in_access_points_and_controller_for_syslog_server.html

BB

=====️ Preenayamo Vasudevam ️=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Thanks. That's useful. However this seems to be a very specific case and it isn't showing up even with that, or if I input the mac address of the client failing to authenticate. Also, there is no Radius server, it's just WPA2-PSK.

Anyway I'll create a separate thread for that since that goes outside the scope of this question.

Rich R
VIP
VIP

Have you done a radioactive trace for that client MAC?

And then put the result through https://cway.cisco.com/wireless-debug-analyzer/

 

------------------------------
Please click Helpful if this post helped you and Accept as Solution (drop down menu at top right of this reply) if this answered your query.
------------------------------
TAC recommended codes for AireOS WLC's   and   TAC recommended codes for 9800 WLC's
Best Practices for AireOS WLC's,   Best Practices for 9800 WLC's   and   Cisco Wireless compatibility matrix
Check your 9800 WLC config with Wireless Config Analyzer using "show tech wireless" output or "config paging disable" then "show run-config" output on AireOS and use Wireless Debug Analyzer to analyze your WLC client debugs
Field Notice: FN63942 APs and WLCs Fail to Create CAPWAP Connections Due to Certificate Expiration
Field Notice: FN72424 Later Versions of WiFi 6 APs Fail to Join WLC - Software Upgrade Required
Field Notice: FN72524 IOS APs stuck in downloading state after 4 Dec 2022 due to Certificate Expired
- Fixed in 8.10.196.0, latest 9800 releases, 8.5.182.12 (8.5.182.13 for 3504) and 8.5.182.109 (IRCM, 8.5.182.111 for 3504)
Field Notice: FN70479 AP Fails to Join or Joins with 1 Radio due to Country Mismatch, RMA needed
Field Notice: FN74383 APs Running 17.12.4/5/6/6a May Run Out of Flash Space Preventing Upgrades
How to avoid boot loop due to corrupted image on Wave 2 and Catalyst 11ax Access Points (CSCvx32806)
Field Notice: FN74035 - Wave2 APs DFS May Not Detect Radar After Channel Availability Check Time
Leo's list of bugs affecting 2800/3800/4800/1560 APs
Default AP console baud rate from 17.12.x is 115200 - introduced by CSCwe88390
Review Cisco Networking for a $25 gift card