<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Syslog severity in Netsight in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/syslog-severity-in-netsight/m-p/44368#M5911</link>
    <description>I made two modifications and I get syslog severity in EMC syslog events:&lt;BR /&gt;
1 . Changed symbol of separator from &amp;lt;&amp;gt; to space :&lt;BR /&gt;
#$ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormatand replace it with:&lt;BR /&gt;
&lt;BR /&gt;
 # Use precise instead&lt;BR /&gt;
$template precise,"%syslogpriority% %timegenerated% %HOSTNAME% %syslogtag% %msg%\n"&lt;BR /&gt;
&lt;BR /&gt;
$ActionFileDefaultTemplate precise&lt;BR /&gt;
&lt;BR /&gt;
2. Modified pattern for Log Manager Parameters -SYSLOG (Event View Manager) - added field %sevint% with separators \w  to standard Ubuntu pattern :&lt;BR /&gt;
%sevint%\w%month%\w%day%\w%time%\w%src%\w%info%&lt;BR /&gt;
&lt;BR /&gt;
It works.&lt;BR /&gt;
&lt;BR /&gt;
If there  would be a possibility to use different patterns for device groups it would be useful.  How to manage this issue?</description>
    <pubDate>Thu, 24 Nov 2016 19:50:00 GMT</pubDate>
    <dc:creator>Marius_Matijosi</dc:creator>
    <dc:date>2016-11-24T19:50:00Z</dc:date>
    <item>
      <title>Syslog severity in Netsight</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/syslog-severity-in-netsight/m-p/44361#M5904</link>
      <description>My idea was to create severity alarm based on syslog messages i ECM. But I noticed that all syslog messages are logged and displayed with one severity INFO. Severity is coded in first 3 bits of every syslog message. But ECM is ignoring original severity. &lt;BR /&gt;
Is there any explanation for such behavior?&lt;BR /&gt;
Can ECM log syslog messages with original severity?&lt;BR /&gt;
&lt;BR /&gt;
Thanks for your advices.&lt;BR /&gt;</description>
      <pubDate>Wed, 23 Nov 2016 14:53:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/syslog-severity-in-netsight/m-p/44361#M5904</guid>
      <dc:creator>Marius_Matijosi</dc:creator>
      <dc:date>2016-11-23T14:53:00Z</dc:date>
    </item>
    <item>
      <title>RE: Syslog severity in Netsight</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/syslog-severity-in-netsight/m-p/44362#M5905</link>
      <description>Hi Marius,&lt;BR /&gt;
&lt;BR /&gt;
This is a bug in the /etc/rsyslog.conf file which will be fixed in an upcoming release.&lt;BR /&gt;
&lt;BR /&gt;
If you edit the /etc/rsyslog.conf file and find the line:&lt;BR /&gt;
&lt;BR /&gt;
$ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat&lt;BR /&gt;
&lt;BR /&gt;
and replace it with:&lt;BR /&gt;
&lt;BR /&gt;
 # Use precise instead&lt;BR /&gt;
$template precise,"&amp;lt;%syslogpriority%&amp;gt;%timegenerated% %HOSTNAME% %syslogtag% %msg%\n"&lt;BR /&gt;
$ActionFileDefaultTemplate precise&lt;BR /&gt;
&lt;BR /&gt;
and then run:&lt;BR /&gt;
&lt;BR /&gt;
service rsyslog restart&lt;BR /&gt;
&lt;BR /&gt;
your /var/log/syslog files should have the following format with the severity in the first 3 characters:&lt;BR /&gt;
&lt;BR /&gt;
&amp;lt;6&amp;gt;Nov 23 14:17:01 netsight147-11 CRON[182011]:  (root) CMD (   cd / &amp;amp;&amp;amp; run-parts --report /etc/cron.hourly)&lt;BR /&gt;
&amp;lt;6&amp;gt;Nov 23 14:17:02 netsight147-11 CRON[182007]:  (CRON) info (No MTA installed, discarding output)&lt;BR /&gt;
&lt;BR /&gt;
Please let us know how it goes.&lt;BR /&gt;
&lt;BR /&gt;
Thanks&lt;BR /&gt;
&lt;BR /&gt;
Mike Butterfield&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 24 Nov 2016 02:33:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/syslog-severity-in-netsight/m-p/44362#M5905</guid>
      <dc:creator>Michael_Butterf</dc:creator>
      <dc:date>2016-11-24T02:33:00Z</dc:date>
    </item>
    <item>
      <title>RE: Syslog severity in Netsight</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/syslog-severity-in-netsight/m-p/44363#M5906</link>
      <description>Hey Marius,&lt;BR /&gt;
&lt;BR /&gt;
I've tried it and now I'd see the severity# in front of the message....&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="01d65b08f71b4683a22ef26c9a0a1533_RackMultipart20161123-63229-p28fgw-syslog_facilities01_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/4077iC3E730EFD8CA8E75/image-size/large?v=v2&amp;amp;px=999" role="button" title="01d65b08f71b4683a22ef26c9a0a1533_RackMultipart20161123-63229-p28fgw-syslog_facilities01_inline.png" alt="01d65b08f71b4683a22ef26c9a0a1533_RackMultipart20161123-63229-p28fgw-syslog_facilities01_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
Could you also fix it that the facility information is used.&lt;BR /&gt;
&lt;BR /&gt;
My WLAN controller has the following syslog settings.&lt;BR /&gt;
i.e. Station Events should use facility local.1&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="01d65b08f71b4683a22ef26c9a0a1533_RackMultipart20161123-52049-19htcv9-syslog_facilities02_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/2127iA808482F6E5FE492/image-size/large?v=v2&amp;amp;px=999" role="button" title="01d65b08f71b4683a22ef26c9a0a1533_RackMultipart20161123-52049-19htcv9-syslog_facilities02_inline.png" alt="01d65b08f71b4683a22ef26c9a0a1533_RackMultipart20161123-52049-19htcv9-syslog_facilities02_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
Trace from a packet that is tx by the controller = local.1 for a station events&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="01d65b08f71b4683a22ef26c9a0a1533_RackMultipart20161123-21667-v46mlf-syslog_facilities04_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/3270i245C94C7F2A196DB/image-size/large?v=v2&amp;amp;px=999" role="button" title="01d65b08f71b4683a22ef26c9a0a1533_RackMultipart20161123-21667-v46mlf-syslog_facilities04_inline.png" alt="01d65b08f71b4683a22ef26c9a0a1533_RackMultipart20161123-21667-v46mlf-syslog_facilities04_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
This is what I get in the EMC syslog...&lt;BR /&gt;
&amp;lt;6&amp;gt;Nov 23 21:15:58 172.24.24.101 events:  EventType[Registration] MAC[84:18:26:7C:1C:2B] AP[AP3825i] SSID[Home] BSSID[D8:84:66:02:DF:E8] Details: Radio[2]&lt;BR /&gt;
&lt;BR /&gt;
It would be great to also have that information in EMC and be able to  filter on it so i.e. I'd only see my station events = local.1&lt;BR /&gt;
&lt;BR /&gt;
Thanks,&lt;BR /&gt;
Ron</description>
      <pubDate>Thu, 24 Nov 2016 03:31:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/syslog-severity-in-netsight/m-p/44363#M5906</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2016-11-24T03:31:00Z</dc:date>
    </item>
    <item>
      <title>RE: Syslog severity in Netsight</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/syslog-severity-in-netsight/m-p/44364#M5907</link>
      <description>EMC is still showing all messages as severity info even I've some with &amp;lt;3&amp;gt; which should be Error.&lt;BR /&gt;
&lt;BR /&gt;
&amp;lt;3&amp;gt;Nov 23 21:59:17 172.24.24.101 events:  Radar Analysis Engine Security threat [Unauthorized Bridging] detected by AP [AP3935-2], SN [1628Y-1033100000]. Details: state [inactive], location [Home], channel [6], frequency [2437MHz], associated MAC [A4:B1:E9:43:C3:1F], RSS [-85], description [Potential unauthorized AP active - WPS-enabled AP operating in vicinity] 1&lt;BR /&gt;
&lt;BR /&gt;
&amp;lt;3&amp;gt;Nov 23 21:59:47 172.24.24.101 events:  Radar Analysis Engine Security threat [Unauthorized Bridging] detected by AP [AP3935-2], SN [1628Y-1033100000]. Details: state [active], location [Home], channel [6], frequency [2437MHz], associated MAC [A4:B1:E9:43:C3:1F], RSS [-85], description [Potential unauthorized AP active - WPS-enabled AP operating in vicinity] 1&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="1458aa69b1ed42fb84f726f54dd69967_RackMultipart20161123-53795-n2onjc-syslog_facilities05_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1373iD60BC279CAAE3FAE/image-size/large?v=v2&amp;amp;px=999" role="button" title="1458aa69b1ed42fb84f726f54dd69967_RackMultipart20161123-53795-n2onjc-syslog_facilities05_inline.png" alt="1458aa69b1ed42fb84f726f54dd69967_RackMultipart20161123-53795-n2onjc-syslog_facilities05_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
I'm running EMC 7.0.6.27 and also tried it after a ./stopserver &amp;amp; ./startserver&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 24 Nov 2016 04:07:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/syslog-severity-in-netsight/m-p/44364#M5907</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2016-11-24T04:07:00Z</dc:date>
    </item>
    <item>
      <title>RE: Syslog severity in Netsight</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/syslog-severity-in-netsight/m-p/44365#M5908</link>
      <description>Hello,&lt;BR /&gt;
i tried to modify rsyslog.conf.&lt;BR /&gt;
I got severity in 3 first characters of messages in syslog file. But unfortunately ECM doesn't show these messages in SYSLOG events. &lt;BR /&gt;
ex. of syslog file:&lt;BR /&gt;
&amp;lt;6&amp;gt;Nov 24 09:14:18 Fima-03 AAA:  Login passed for user admin through xml (172.16.69.100)&amp;lt;6&amp;gt;Nov 24 09:14:20 Fima-03 AAA:  User admin logout from xml (172.16.69.100)&lt;BR /&gt;
&amp;lt;4&amp;gt;Nov 24 09:16:09 172.16.69.6 snmp:   SNMP Security access violation from 172.16.100.69&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 24 Nov 2016 14:31:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/syslog-severity-in-netsight/m-p/44365#M5908</guid>
      <dc:creator>Marius_Matijosi</dc:creator>
      <dc:date>2016-11-24T14:31:00Z</dc:date>
    </item>
    <item>
      <title>RE: Syslog severity in Netsight</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/syslog-severity-in-netsight/m-p/44366#M5909</link>
      <description>Hi Marius,&lt;BR /&gt;
&lt;BR /&gt;
can you let me know what is your netsight version ?&lt;BR /&gt;
&lt;BR /&gt;
Thanks,&lt;BR /&gt;
Suresh.B&lt;BR /&gt;</description>
      <pubDate>Thu, 24 Nov 2016 14:48:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/syslog-severity-in-netsight/m-p/44366#M5909</guid>
      <dc:creator>Bharathiraja__S</dc:creator>
      <dc:date>2016-11-24T14:48:00Z</dc:date>
    </item>
    <item>
      <title>RE: Syslog severity in Netsight</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/syslog-severity-in-netsight/m-p/44367#M5910</link>
      <description>Hi Suresh,&lt;BR /&gt;
&lt;BR /&gt;
I am currently testing on ECM 7.0.4.29&lt;BR /&gt;
&lt;BR /&gt;
Thanks,&lt;BR /&gt;
Marius</description>
      <pubDate>Thu, 24 Nov 2016 17:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/syslog-severity-in-netsight/m-p/44367#M5910</guid>
      <dc:creator>Marius_Matijosi</dc:creator>
      <dc:date>2016-11-24T17:57:00Z</dc:date>
    </item>
    <item>
      <title>RE: Syslog severity in Netsight</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/syslog-severity-in-netsight/m-p/44368#M5911</link>
      <description>I made two modifications and I get syslog severity in EMC syslog events:&lt;BR /&gt;
1 . Changed symbol of separator from &amp;lt;&amp;gt; to space :&lt;BR /&gt;
#$ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormatand replace it with:&lt;BR /&gt;
&lt;BR /&gt;
 # Use precise instead&lt;BR /&gt;
$template precise,"%syslogpriority% %timegenerated% %HOSTNAME% %syslogtag% %msg%\n"&lt;BR /&gt;
&lt;BR /&gt;
$ActionFileDefaultTemplate precise&lt;BR /&gt;
&lt;BR /&gt;
2. Modified pattern for Log Manager Parameters -SYSLOG (Event View Manager) - added field %sevint% with separators \w  to standard Ubuntu pattern :&lt;BR /&gt;
%sevint%\w%month%\w%day%\w%time%\w%src%\w%info%&lt;BR /&gt;
&lt;BR /&gt;
It works.&lt;BR /&gt;
&lt;BR /&gt;
If there  would be a possibility to use different patterns for device groups it would be useful.  How to manage this issue?</description>
      <pubDate>Thu, 24 Nov 2016 19:50:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/syslog-severity-in-netsight/m-p/44368#M5911</guid>
      <dc:creator>Marius_Matijosi</dc:creator>
      <dc:date>2016-11-24T19:50:00Z</dc:date>
    </item>
    <item>
      <title>RE: Syslog severity in Netsight</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/syslog-severity-in-netsight/m-p/44369#M5912</link>
      <description>Could you explain where to add/change the line for 2. - I don't get it.&lt;BR /&gt;
&lt;BR /&gt;
Thanks</description>
      <pubDate>Thu, 24 Nov 2016 19:50:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/syslog-severity-in-netsight/m-p/44369#M5912</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2016-11-24T19:50:00Z</dc:date>
    </item>
    <item>
      <title>RE: Syslog severity in Netsight</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/syslog-severity-in-netsight/m-p/44370#M5913</link>
      <description>Hello,&lt;BR /&gt;
This is instruction for step 2:&lt;BR /&gt;
Netsight Console&lt;BR /&gt;
Tools tab /Alarm event/Event View Manager&lt;BR /&gt;
Available log managers/Syslog -Edit&lt;BR /&gt;
Pattern - Config&lt;BR /&gt;
create new Custom pattern configuration - enter name and pattern:&lt;BR /&gt;
%sevint%\w%month%\w%day%\w%time%\w%src%\w%info%&lt;BR /&gt;
ok/apply.....&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 24 Nov 2016 19:50:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/syslog-severity-in-netsight/m-p/44370#M5913</guid>
      <dc:creator>Marius_Matijosi</dc:creator>
      <dc:date>2016-11-24T19:50:00Z</dc:date>
    </item>
    <item>
      <title>RE: Syslog severity in Netsight</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/syslog-severity-in-netsight/m-p/44371#M5914</link>
      <description>Thanks a lot... works like a charm.&lt;BR /&gt;</description>
      <pubDate>Thu, 24 Nov 2016 19:50:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/syslog-severity-in-netsight/m-p/44371#M5914</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2016-11-24T19:50:00Z</dc:date>
    </item>
    <item>
      <title>RE: Syslog severity in Netsight</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/syslog-severity-in-netsight/m-p/44372#M5915</link>
      <description>Release Notes 7.0.8.34&lt;BR /&gt;
All syslog messages were displaying with a severity of Info, regardlessof the severity with which they were configured. &amp;gt; 1144968&lt;BR /&gt;
&lt;BR /&gt;
Thanks team !</description>
      <pubDate>Tue, 20 Dec 2016 01:24:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/syslog-severity-in-netsight/m-p/44372#M5915</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2016-12-20T01:24:00Z</dc:date>
    </item>
  </channel>
</rss>

