weird error on my CISCO2911/K9 voice gateway ...

Anyone know why my log buffer in my functioning voice gateway 2911 is full of this message and how I can stop it? debug is not turned on....:

SIP: Trying to parse unsupported attribute at media level

I see a bug report at https://quickview.cloudapps.cisco.com/quickview/bug/CSCuv36964 but they have no advice for how to stop it from constantly filling up my log buffer .... does anyone know how to make this irritating message stop? Is there any way to determine exactly what the "unsupported attribute" message might be that triggers this or where it is coming from? If someone has an old test sending out something repeatedly, am I going to have to sniff packets all day to find it?
LVL 7
Jane UpdegraffSr. Systems AdministratorAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

arnoldCommented:
Do you have the packet/sip entire info to see whether this is a sip fishing type of event.
Given the info, what are you hoping to achieve?
First thing, as noted, identify the source of the packet. If external to your provider......
There is little you can do to stop an external source from sending this packet your way.
0
Jane UpdegraffSr. Systems AdministratorAuthor Commented:
All I want to achieve is to not have this event filling up my log buffer. I can't keep logs of any "real" activity when one of these messages is logged every five or ten minutes. I guess I can increase the buffer size. Or replace this aging device....

You said:

here is little you can do to stop an external source from sending this packet your way.

....that's what i thought you would say. *sigh*

According to what I've read in the community, this message can't be turned off.  And although I may be able to figure out what's triggering the log entry, if it is something normal that actually belongs in the traffic then I'm out of luck, it seems.  

But thanks for confirming ....
0
arnoldCommented:
What resources do you have. Instead of relying on the buffer, I.e. You can forward these event to a syslog server in your environment to a point that you can proactively can configure it to evaluate the event as it arrives, and generate an alert, notification on an event of concern, while these can be discarded, ignored.

Identifying the source of these packets, if coming from the same source, email a complaint to the people in charge based on the Ip registration (arin.net, ripe.net, apnic.net)
They may address this issue and reduce your issue.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Jane UpdegraffSr. Systems AdministratorAuthor Commented:
As you suggest I would rather know where they are coming from and stop the message from being created to begin with, rather than have to filter my syslog. Thanks for the ideas. :-)
0
Jane UpdegraffSr. Systems AdministratorAuthor Commented:
Thanks for the ideas!
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Voice Over IP

From novice to tech pro — start learning today.