cisco syslog logging

Hello Experts

I have configured my router to send syslog messages to my server, however without issuing the command logging source-interface xxxx the the syslog server won't see any syslog messages.

Is there any explanation why?

Cheers

Carlton
cpatte7372Asked:
Who is Participating?
 
Jan SpringerConnect With a Mentor Commented:
my typical logging config is:

Sample:                                                           Example:

logging buffered <#>                                      logging buffered 32768
no logging console                                          no logging console
logging facility local<#>                                  logging facility local6
logging source-interface <interface>              logging source-interface Vlan1
logging <IP>                                                    logging 10.44.96.142
                                                                       logging 10.44.108.79

Your syslog data from the router may be originating from one of the other IP addresses on the router.  Specifying it is usually necessary.
0
 
Jan SpringerCommented:
If your syslog server is firewalled and your cisco router has multiple IPs, the IP originating the syslog packets may not be in the firewall list of allowed tcp/udp port 514.

Have you run wireshark on the syslog server to determine the originating IP
0
 
cpatte7372Author Commented:
Jesper,

I have disabled the firewall. I do have other interfaces on the syslog server but they are either disconnected or disabled.

I will run wireshark and post the results

Any other suggestions?
0
Cloud Class® Course: Microsoft Office 2010

This course will introduce you to the interfaces and features of Microsoft Office 2010 Word, Excel, PowerPoint, Outlook, and Access. You will learn about the features that are shared between all products in the Office suite, as well as the new features that are product specific.

 
Jan SpringerCommented:
Do you have more than one IP address on the router?  I suspect that the syslog packets are not originating from the IP that you want them to.
0
 
cpatte7372Author Commented:
Hi Jesper

Attached is copy of the configs. There is more than ip address. I'm trying to log to logging 10.44.96.142

Appreciate your help
mxrouter.txt
0
 
cpatte7372Author Commented:
Experts,

Any thoughts?
0
 
cpatte7372Author Commented:
Jesper,

Thanks for responding. I tried all your suggestions - no luck :-(
0
 
Jan SpringerCommented:
Please post either your "syslog.conf" or "rsyslog.conf" and the "/etc/sysconfig/*syslog* file.

Also post "iptables --list -n"

And, I'd like to see a "netstat -an | grep 514"
0
 
Jan SpringerCommented:
One little detail:  one the router,

logging on

Then do a "show log" and post the log data minus the actual detail.
0
 
cpatte7372Author Commented:
Jesper, thanks again for getting back to me. The server is Windows 7, not unix.
0
 
cpatte7372Author Commented:
Cheers
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.