?
Solved

cisco syslog logging

Posted on 2013-02-07
11
Medium Priority
?
312 Views
Last Modified: 2013-06-21
Hello Experts

I have configured my router to send syslog messages to my server, however without issuing the command logging source-interface xxxx the the syslog server won't see any syslog messages.

Is there any explanation why?

Cheers

Carlton
0
Comment
Question by:cpatte7372
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 5
11 Comments
 
LVL 29

Expert Comment

by:Jan Springer
ID: 38864202
If your syslog server is firewalled and your cisco router has multiple IPs, the IP originating the syslog packets may not be in the firewall list of allowed tcp/udp port 514.

Have you run wireshark on the syslog server to determine the originating IP
0
 

Author Comment

by:cpatte7372
ID: 38864229
Jesper,

I have disabled the firewall. I do have other interfaces on the syslog server but they are either disconnected or disabled.

I will run wireshark and post the results

Any other suggestions?
0
 
LVL 29

Expert Comment

by:Jan Springer
ID: 38864377
Do you have more than one IP address on the router?  I suspect that the syslog packets are not originating from the IP that you want them to.
0
Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

 

Author Comment

by:cpatte7372
ID: 38864551
Hi Jesper

Attached is copy of the configs. There is more than ip address. I'm trying to log to logging 10.44.96.142

Appreciate your help
mxrouter.txt
0
 

Author Comment

by:cpatte7372
ID: 38864710
Experts,

Any thoughts?
0
 
LVL 29

Accepted Solution

by:
Jan Springer earned 2000 total points
ID: 38864735
my typical logging config is:

Sample:                                                           Example:

logging buffered <#>                                      logging buffered 32768
no logging console                                          no logging console
logging facility local<#>                                  logging facility local6
logging source-interface <interface>              logging source-interface Vlan1
logging <IP>                                                    logging 10.44.96.142
                                                                       logging 10.44.108.79

Your syslog data from the router may be originating from one of the other IP addresses on the router.  Specifying it is usually necessary.
0
 

Author Comment

by:cpatte7372
ID: 38864809
Jesper,

Thanks for responding. I tried all your suggestions - no luck :-(
0
 
LVL 29

Expert Comment

by:Jan Springer
ID: 38864853
Please post either your "syslog.conf" or "rsyslog.conf" and the "/etc/sysconfig/*syslog* file.

Also post "iptables --list -n"

And, I'd like to see a "netstat -an | grep 514"
0
 
LVL 29

Expert Comment

by:Jan Springer
ID: 38864856
One little detail:  one the router,

logging on

Then do a "show log" and post the log data minus the actual detail.
0
 

Author Comment

by:cpatte7372
ID: 38865727
Jesper, thanks again for getting back to me. The server is Windows 7, not unix.
0
 

Author Closing Comment

by:cpatte7372
ID: 39265438
Cheers
0

Featured Post

Limited time offer using promo code EXPERTS30

Designed with a wealth of functionality and convenience, ATEN's new Thunderbolt™ 2 Sharing Switch takes your Thunderbolt setup to the next level. Now through September 15, 2017, Experts Exchange members get 30% off the US7220 on the ATEN USA eShop using promo code EXPERTS30.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Problem Description:   Couple of months ago we upgraded the ADSL line at our branch office from Home to Business line. The purpose of transforming the service to have static public IP’s. We were in need for public IP’s to publish our web resour…
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question