cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1004
Views
3
Helpful
5
Replies

Setting Syslog Notifications on WLC

InquiringTech
Level 1
Level 1

Where do you actually set the syslog on the C9800 WLC (in our case an EWC)?

I see something under Administration > Management > Logging but that doesn't seem to work

InquiringTech_0-1678117070352.png

Then there is something under Configuration > Tags & Profiles > AP Join > ap profile > Management tab, under System Log:

InquiringTech_1-1678117222967.png

I think this might be the actual spot for it? How do I set it up so that it sends messages for authentication issues for clients trying to join APs? I see a variety of Facility and Log Trap Values. What levels do I need to set to see this?

But I don't seem to be getting anything on our actual syslog from it. I configured it so that it should get messages from the management IP of the EWC.

1 Accepted Solution

Accepted Solutions

marce1000
VIP
VIP

 

 - FYI : https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-3/config-guide/b_wl_17_3_cg/m_syslog_server.html#id_135864

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

View solution in original post

5 Replies 5

marce1000
VIP
VIP

 

 - FYI : https://www.cisco.com/c/en/us/td/docs/wireless/controller/9800/17-3/config-guide/b_wl_17_3_cg/m_syslog_server.html#id_135864

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Thanks. Now I am getting logs at my syslog server, but don't seem to be getting them for the client that is having trouble authenticating and joining the network for some reason, even with the wireless client syslog-detailed command and trap level 5 set (getting a lot of client exclusion messages for other, presumably rogue clients). But that's actually a bigger problem that I may make a separate thread for.

what radius you using for client to get authentication, if you using ISE it has all the information.

check below EWC Log level or post what config you have on the device ?

https://www.cisco.com/c/en/us/td/docs/wireless/controller/ewc/17-1/config-guide/ewc_cg_17_11/enabling_syslog_messages_in_access_points_and_controller_for_syslog_server.html

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Thanks. That's useful. However this seems to be a very specific case and it isn't showing up even with that, or if I input the mac address of the client failing to authenticate. Also, there is no Radius server, it's just WPA2-PSK.

Anyway I'll create a separate thread for that since that goes outside the scope of this question.

Rich R
VIP
VIP

Have you done a radioactive trace for that client MAC?

And then put the result through https://cway.cisco.com/wireless-debug-analyzer/

 

Review Cisco Networking for a $25 gift card