Is there a way to officially configure syslogging for both legacy Enterasys hardware S/K/N/C and Extreme switchs.
Currently the Extreme syslogging works if I change the syslog pattern to 'Red Hat Linux Syslog'
Enterasys syslogging works if I change the syslog pattern to 'Netsight Syslog Pattern'.
Each switch has various firmware versions, to list a few:
Netsight is running version 220.127.116.11.
Suspect the configuration maybe in the format SNMP configuration in EXOS, that is currently configured on the Extreme switchs as so:
timestamp seconds date Mmm-dd event-name none process-slot priority tag-name.
If you are concerned with setting the server commands
I unfortunately cannot help you
You would need to modify the differences to your network such as IP address
sh conf ems
# Module ems configuration.
configure syslog add 10.58.195.5:514 vr VR-Mgmt local0
enable log target syslog 10.58.196.5:514 vr VR-Mgmt local0
configure log target syslog 10.58.196.5:514 vr VR-Mgmt local0 filter DefaultFilter severity Debug-Data
configure log target syslog 10.58.196.5:514 vr VR-Mgmt local0 match Any
configure log target syslog 10.58.196.5:514 vr VR-Mgmt local0 format timestamp seconds date Mmm-dd event-name none priority tag-name
Thanks for replying. I haven't tried this config using the default Netsight syslog pattern, but when I do I'll report back if it works ok.
The question I have is around setting the severity to 'Debug-Data', as the configuration guide states the following:
The three severity levels for extended debugging—Debug-Summary, Debug-Verbose, and Debug-Data—require that log debug mode be enabled (which may cause a performance degradation).
So just checking its safe to use the debug-data severity with debug mode enabled on all switchs?
You might just have given that as an example. Currently I have it set to Info, so that is probably sufficient.
Ok, see here are the results....
configure log target syslog X.X.X.X:514 vr VR-Mgmt local0 format timestamp seconds date Mmm-dd event-name none priority tag-name
With 'Netsight Syslog Pattern' entries are now logging but no device details are being shown. So for example if I run a 'show config' the description will show my PC IP address but the client column is blank and no indication as to what switch has reported the entry.
If I leave what is currently set (as per below), using the 'Netsight Syslog Pattern' doesn't report anything but if I change it back to 'Red Hat Linus Syslog Pattern' I get all the information I need but loose the ability to report on legacy Enterasys devices.
configure log target syslog x.x.x.x:514 vr VR-Default local0 format timestamp seconds date Mmm-dd event-name none host-name
For information I'm changing the log pattern in Netsight via..... Tools - Alarms/Events - Event View Manager. I then click on 'SySlog', hit edit and change the pattern.
Tried creating my own pattern without luck (not played to much) but wanted to get any official stance on reporting and configuring for all Extreme / Enterasys.
Enterasys I can configure the switchs for Syslog directly in Netsight, but this is not support yet / if for Extreme.......