Avatar of considerscs
considerscs
Flag for United States of America asked on

Cisco Syslog setup - Send to syslog server

I have set up my cisco to send the syslog to a syslog server, but it is showing link down on that ip address for the server.

Has anyone done this and know why it is showing link down?

Below is the configuration.

Console logging: level debugging, 991 messages logged, xml disabled,
                     filtering disabled
    Monitor logging: level debugging, 0 messages logged, xml disabled,
                     filtering disabled
    Buffer logging:  level warnings, 757 messages logged, xml disabled,
                    filtering disabled
    Exception Logging: size (4096 bytes)
    Count and timestamp logging messages: disabled
    Persistent logging: disabled
    Trap logging: level warnings, 1034 message lines logged
        Logging to x.x.x.x  (tcp port 515, audit disabled,
              link down),
              0 message lines logged,
              0 message lines rate-limited,
              0 message lines dropped-by-MD,
              xml disabled, sequence number disabled
              filtering disabled
        Logging to x.x.x.x  (tcp port 514, audit disabled,
              link down),
              0 message lines logged,
              0 message lines rate-limited,
              0 message lines dropped-by-MD,
              xml disabled, sequence number disabled
              filtering disabled
        Logging Source-Interface:       VRF Name:
        GigabitEthernet0/1
NetworkingRoutersCisco

Avatar of undefined
Last Comment
considerscs

8/22/2022 - Mon
max_the_king

Hi,
because it may not succeed in opening the socket on tcp port 514 (e.g.: the syslog server may not be listening on that port).
It is usually easier to let logs flow through udp port 514

hope this helps
max
Ernie Beek

So the server is reachable, syslog service is running and listening on those ports (normally it's using UDP)?
considerscs

ASKER
server is reachable (though it is a third party vendors server) but even on udp port it is still not showing as link up.

Logging to x.x.x.x  (udp port 515, audit disabled,
              link down),
              0 message lines logged,
              0 message lines rate-limited,
              0 message lines dropped-by-MD,
              xml disabled, sequence number disabled
              filtering disabled
        Logging Source-Interface:       VRF Name:
        GigabitEthernet0/1
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck
max_the_king

there may be some mess on the sockets ... it might fix with a reload

please have a look at the following, it seems a very similar issue

https://supportforums.cisco.com/thread/1004039

hope this helps
max
Ernie Beek

So are you able to check the server to see if everything is up and running there? Also no firewall blocking anything?
And are you sure the server is listening on port 515? Like max said, normally syslog uses UDP port 514.
considerscs

ASKER
I have it set up for udp port 514 and 515, but the server is controlled by a third party vendor.  This is all they do is run the syslog servers.

I will try the reload after hours when I am able to reload and see if that brings this up.
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
considerscs

ASKER
the reboot did not work, they are all still showing down.
ASKER CERTIFIED SOLUTION
max_the_king

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
Ernie Beek

I think you might also want to check with the 3rd party vendor and let them check if everything is ok.
If you set up another device to send syslogs to the server, does that come through?
considerscs

ASKER
This came up after doing this.
This is the best money I have ever spent. I cannot not tell you how many times these folks have saved my bacon. I learn so much from the contributors.
rwheeler23