{"id":714,"date":"2013-04-12T23:39:36","date_gmt":"2013-04-12T22:39:36","guid":{"rendered":"http:\/\/www.balajibandi.com\/?p=714"},"modified":"2024-02-18T16:15:40","modified_gmt":"2024-02-18T16:15:40","slug":"syslog-tutorial-with-cisco-device","status":"publish","type":"post","link":"https:\/\/www.balajibandi.com\/?p=714","title":{"rendered":"Syslog Tutorial with Cisco Device."},"content":{"rendered":"<p>By default, Cisco routers and switches send log messages to the console. We should use a syslog server to contain our logging messages with the\u00a0<span class=\"pinkandbold\">logging\u00a0<\/span>command. Syslog server is the most popular place to store logging messages and administrators can easily monitor the wealth of their networks based on the received information.<\/p>\n<p>&nbsp;<\/p>\n<p id=\"zLoFVHl\"><img loading=\"lazy\" decoding=\"async\" width=\"555\" height=\"429\" class=\"alignnone size-full wp-image-715 \" src=\"http:\/\/www.balajibandi.com\/wp-content\/uploads\/2018\/09\/img_5ba68f0b60c4d.png\" alt=\"\" srcset=\"https:\/\/www.balajibandi.com\/wp-content\/uploads\/2018\/09\/img_5ba68f0b60c4d.png 555w, https:\/\/www.balajibandi.com\/wp-content\/uploads\/2018\/09\/img_5ba68f0b60c4d-300x232.png 300w\" sizes=\"auto, (max-width: 555px) 100vw, 555px\" \/><\/p>\n<p>A syslog message has the following format:<\/p>\n<table border=\"1\">\n<tbody>\n<tr>\n<td><strong>seq no:timestamp%FACILTY-SEVERITY-MNEMONIC<\/strong>: message text<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>A detail explanation of what this means:<\/strong><br \/>\n<strong>seq no\u00a0<\/strong>: This a sequence number of the message, but not by default. for you to know the time the message was sent,\u00a0you\u2019ve got to configure it.<br \/>\n<strong>Timestamp<\/strong>\u00a0: This means Data and time of the message or event, which also need to be configured<br \/>\n<strong>Facility<\/strong>\u00a0: The facility to which the message refers.<br \/>\n<strong>Severity<\/strong>\u00a0: this a single-digit code from 0 to 7 that shows the severity of the message.<br \/>\n<strong>MNEMONIC<\/strong>\u00a0: Text string that uniquely describes the message.<br \/>\n<strong>Description<\/strong>\u00a0: Text string containing detailed information about the event<\/p>\n<table border=\"1\">\n<tbody>\n<tr>\n<td><strong>Level<\/strong><\/td>\n<td><strong>Keyword<\/strong><\/td>\n<td><strong>Description<\/strong><\/td>\n<\/tr>\n<tr>\n<td>0<\/td>\n<td>emergencies<\/td>\n<td>System is unusable<\/td>\n<\/tr>\n<tr>\n<td>1<\/td>\n<td>alerts<\/td>\n<td>Immediate action is needed<\/td>\n<\/tr>\n<tr>\n<td>2<\/td>\n<td>critical<\/td>\n<td>Critical conditions exist<\/td>\n<\/tr>\n<tr>\n<td>3<\/td>\n<td>errors<\/td>\n<td>Error conditions exist<\/td>\n<\/tr>\n<tr>\n<td>4<\/td>\n<td>warnings<\/td>\n<td>Warning conditions exist<\/td>\n<\/tr>\n<tr>\n<td>5<\/td>\n<td>notification<\/td>\n<td>Normal, but significant, conditions exist<\/td>\n<\/tr>\n<tr>\n<td>6<\/td>\n<td>informational<\/td>\n<td>Informational messages<\/td>\n<\/tr>\n<tr>\n<td>7<\/td>\n<td>debugging<\/td>\n<td>Debugging messages<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Let\u2019s see an example of the syslog message:<\/p>\n<table border=\"1\">\n<tbody>\n<tr>\n<td>12345: Apr 12 20:00:35.823: %LINEPROTO-5-UPDOWN: Line protocol on Interface Serial0\/0\/2, changed state to down<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>+\u00a0<strong>seq no<\/strong>: 12345<br \/>\n+\u00a0<strong>T<\/strong><strong>imestamp<\/strong>: Apr 12 20:00:35.823<br \/>\n+\u00a0<strong>FACILTY<\/strong>: LINEPROTO<br \/>\n+\u00a0<strong>SEVERITY level<\/strong>: 5 (notification)<br \/>\n+\u00a0<strong>MNEMONIC<\/strong>: UPDOWN<br \/>\n+\u00a0<strong>message text<\/strong>: Line protocol on Interface Serial0\/0\/2, changed state to down<\/p>\n<p><span class=\"blueandbold\">Syslog Configuration<\/span><\/p>\n<p>The following example tells the device to store syslog messages to a server on 10.10.9.9 and limit the messages for levels 4 and higher (0 through 4):<\/p>\n<table border=\"1\">\n<tbody>\n<tr>\n<td>Router(config)#logging host 10.10.9.9Router(config)#logging trap 4<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By default, Cisco routers and switches send log messages to the console. We should use a syslog server to contain our logging messages with the\u00a0logging\u00a0command. Syslog server is the most popular place to store logging messages and administrators can easily monitor the wealth of their networks based on the received information. &nbsp; A syslog message [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,10,2],"tags":[],"class_list":["post-714","post","type-post","status-publish","format-standard","hentry","category-ccie-sec","category-ccie-rns","category-cisco"],"_links":{"self":[{"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=\/wp\/v2\/posts\/714","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=714"}],"version-history":[{"count":2,"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=\/wp\/v2\/posts\/714\/revisions"}],"predecessor-version":[{"id":2087,"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=\/wp\/v2\/posts\/714\/revisions\/2087"}],"wp:attachment":[{"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=714"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=714"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=714"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}