03-20-2023 08:06 AM
Hi everyone,
I am new to syslog world, i intend to see following in my syslog server
- Who logged into WLC and when logged out
- Changes made in the configuration of WLC
For time being my config at WLC is
Syslog Server Ip : xx.xx.xx.xx
Syslog Level -->Notifications
Syslog Facility --> Local use 0
Buffered log Level --> Errors
Console Log Level --> Disable
File info Ticked
Trace info Ticked
Any help shall be highly appreciated.
Regards
03-20-2023 12:03 PM
- Not possible on the older aireos based controllers such as the 2504 , you can do that on the 9800 platform with IOS XE , for instance : https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/config-mgmt/configuration/xe-3se/wlc5700/config-mgmt-xe-3se-wlc5700-book/cm-config-logger.html
M.
03-21-2023 09:37 AM
What can help you get that visibility is using Cisco ISE for TACACS. A TACACS server can provide that information and also what commands were ran by that user. Plus with TACACS, you have the ability to allow certain groups or commands to be executed which is nice to have by being able to build rules for device access.
03-21-2023 10:22 AM
The correct way to do this is with TACACS, not syslog, as per what Scott said above.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide