<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic EXOS Syslog Severity Overview? in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-syslog-severity-overview/m-p/31024#M5403</link>
    <description>Hello Community,&lt;BR /&gt;
&lt;BR /&gt;
just stumpled over the avaible/following syslog severity list and wondering, if there is also an severityname &amp;lt;-&amp;gt; fix number mapping existing?&lt;BR /&gt;
&lt;BR /&gt;
configure log target syslog 1.2.3.4:514 vr VR-Mgmt local0 filter "DefaultFilter" severity ?&lt;BR /&gt;
  &amp;lt;severity&amp;gt;      Severity value to use&lt;BR /&gt;
    "critical"  "debug-data"  "debug-summary"  "debug-verbose"  "error"  "info"  "notice"  "warning"&lt;BR /&gt;
&lt;BR /&gt;
&lt;BR /&gt;
I'm testing the syslog sensor feature from PRTG [1] and the per device configuration sensor is working with the following filter option:&lt;BR /&gt;
&lt;BR /&gt;
&lt;BLOCKQUOTE&gt;severity[number]&lt;BR /&gt;
&lt;BR /&gt;
    any number (or range) from 0 (emergency) to 7 (debug) specifying the type of message&lt;BR /&gt;
&lt;BR /&gt;
    &lt;UL&gt; 
&lt;LI&gt;severity[4] 
&lt;/LI&gt;&lt;LI&gt;severity[1-3] 
&lt;/LI&gt;&lt;LI&gt;severity[1] AND severity[2]&lt;/LI&gt;&lt;/UL&gt;&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;
Durign my tests I found out:&lt;BR /&gt;
&lt;BR /&gt;
&lt;UL&gt; 
&lt;LI&gt;Failed logins are listed in PRTG as "Severity 4" events and on the EXOS side, the failed login entry is listed as an "warning" event.&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt; 
&lt;LI&gt;Successfull logins are listed in PRTG as "Severity 6" and on the EXOS side as "info".&lt;/LI&gt;&lt;/UL&gt;
But what about all other possible syslog messages and severitys, to which "number level" do they belong to?&lt;BR /&gt;
&lt;BR /&gt;
Cisco f.e. is using the following mapping:&lt;BR /&gt;
&lt;BR /&gt;
&lt;BLOCKQUOTE&gt;&lt;UL&gt; 
&lt;LI&gt; &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/syslog-guide/syslogs/logsevp.html#40350" target="_blank" rel="nofollow noreferrer noopener"&gt;Alert Messages, Severity 1&lt;/A&gt;  
&lt;/LI&gt;&lt;LI&gt;  &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/syslog-guide/syslogs/logsevp.html#13063" target="_blank" rel="nofollow noreferrer noopener"&gt;Critical Messages, Severity 2&lt;/A&gt;  
&lt;/LI&gt;&lt;LI&gt;  &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/syslog-guide/syslogs/logsevp.html#39517" target="_blank" rel="nofollow noreferrer noopener"&gt;Error Messages, Severity 3&lt;/A&gt;  
&lt;/LI&gt;&lt;LI&gt;  &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/syslog-guide/syslogs/logsevp.html#33023" target="_blank" rel="nofollow noreferrer noopener"&gt;Warning Messages, Severity 4&lt;/A&gt;  
&lt;/LI&gt;&lt;LI&gt;  &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/syslog-guide/syslogs/logsevp.html#12356" target="_blank" rel="nofollow noreferrer noopener"&gt;Notification Messages, Severity 5&lt;/A&gt;  
&lt;/LI&gt;&lt;LI&gt;  &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/syslog-guide/syslogs/logsevp.html#30538" target="_blank" rel="nofollow noreferrer noopener"&gt;Informational Messages, Severity 6&lt;/A&gt;  
&lt;/LI&gt;&lt;LI&gt;  &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/syslog-guide/syslogs/logsevp.html#26609" target="_blank" rel="nofollow noreferrer noopener"&gt;Debugging Messages, Severity 7&lt;/A&gt;  &lt;/LI&gt;&lt;/UL&gt;&lt;/BLOCKQUOTE&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/syslog-guide/syslogs/logsevp.html" target="_blank" rel="nofollow noreferrer noopener"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/syslog-guide/syslogs/logsevp.html&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
[1] &lt;A href="https://prtg.paessler.com/help/syslog_receiver_sensor.htm" target="_blank" rel="nofollow noreferrer noopener"&gt;https://prtg.paessler.com/help/syslog_receiver_sensor.htm&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
Cheers,&lt;BR /&gt;
Jan&lt;BR /&gt;
&lt;BR /&gt;</description>
    <pubDate>Tue, 07 Jul 2015 16:38:00 GMT</pubDate>
    <dc:creator>SchmuFoo</dc:creator>
    <dc:date>2015-07-07T16:38:00Z</dc:date>
    <item>
      <title>EXOS Syslog Severity Overview?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-syslog-severity-overview/m-p/31024#M5403</link>
      <description>Hello Community,&lt;BR /&gt;
&lt;BR /&gt;
just stumpled over the avaible/following syslog severity list and wondering, if there is also an severityname &amp;lt;-&amp;gt; fix number mapping existing?&lt;BR /&gt;
&lt;BR /&gt;
configure log target syslog 1.2.3.4:514 vr VR-Mgmt local0 filter "DefaultFilter" severity ?&lt;BR /&gt;
  &amp;lt;severity&amp;gt;      Severity value to use&lt;BR /&gt;
    "critical"  "debug-data"  "debug-summary"  "debug-verbose"  "error"  "info"  "notice"  "warning"&lt;BR /&gt;
&lt;BR /&gt;
&lt;BR /&gt;
I'm testing the syslog sensor feature from PRTG [1] and the per device configuration sensor is working with the following filter option:&lt;BR /&gt;
&lt;BR /&gt;
&lt;BLOCKQUOTE&gt;severity[number]&lt;BR /&gt;
&lt;BR /&gt;
    any number (or range) from 0 (emergency) to 7 (debug) specifying the type of message&lt;BR /&gt;
&lt;BR /&gt;
    &lt;UL&gt; 
&lt;LI&gt;severity[4] 
&lt;/LI&gt;&lt;LI&gt;severity[1-3] 
&lt;/LI&gt;&lt;LI&gt;severity[1] AND severity[2]&lt;/LI&gt;&lt;/UL&gt;&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;
Durign my tests I found out:&lt;BR /&gt;
&lt;BR /&gt;
&lt;UL&gt; 
&lt;LI&gt;Failed logins are listed in PRTG as "Severity 4" events and on the EXOS side, the failed login entry is listed as an "warning" event.&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt; 
&lt;LI&gt;Successfull logins are listed in PRTG as "Severity 6" and on the EXOS side as "info".&lt;/LI&gt;&lt;/UL&gt;
But what about all other possible syslog messages and severitys, to which "number level" do they belong to?&lt;BR /&gt;
&lt;BR /&gt;
Cisco f.e. is using the following mapping:&lt;BR /&gt;
&lt;BR /&gt;
&lt;BLOCKQUOTE&gt;&lt;UL&gt; 
&lt;LI&gt; &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/syslog-guide/syslogs/logsevp.html#40350" target="_blank" rel="nofollow noreferrer noopener"&gt;Alert Messages, Severity 1&lt;/A&gt;  
&lt;/LI&gt;&lt;LI&gt;  &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/syslog-guide/syslogs/logsevp.html#13063" target="_blank" rel="nofollow noreferrer noopener"&gt;Critical Messages, Severity 2&lt;/A&gt;  
&lt;/LI&gt;&lt;LI&gt;  &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/syslog-guide/syslogs/logsevp.html#39517" target="_blank" rel="nofollow noreferrer noopener"&gt;Error Messages, Severity 3&lt;/A&gt;  
&lt;/LI&gt;&lt;LI&gt;  &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/syslog-guide/syslogs/logsevp.html#33023" target="_blank" rel="nofollow noreferrer noopener"&gt;Warning Messages, Severity 4&lt;/A&gt;  
&lt;/LI&gt;&lt;LI&gt;  &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/syslog-guide/syslogs/logsevp.html#12356" target="_blank" rel="nofollow noreferrer noopener"&gt;Notification Messages, Severity 5&lt;/A&gt;  
&lt;/LI&gt;&lt;LI&gt;  &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/syslog-guide/syslogs/logsevp.html#30538" target="_blank" rel="nofollow noreferrer noopener"&gt;Informational Messages, Severity 6&lt;/A&gt;  
&lt;/LI&gt;&lt;LI&gt;  &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/syslog-guide/syslogs/logsevp.html#26609" target="_blank" rel="nofollow noreferrer noopener"&gt;Debugging Messages, Severity 7&lt;/A&gt;  &lt;/LI&gt;&lt;/UL&gt;&lt;/BLOCKQUOTE&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/syslog-guide/syslogs/logsevp.html" target="_blank" rel="nofollow noreferrer noopener"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/syslog-guide/syslogs/logsevp.html&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
[1] &lt;A href="https://prtg.paessler.com/help/syslog_receiver_sensor.htm" target="_blank" rel="nofollow noreferrer noopener"&gt;https://prtg.paessler.com/help/syslog_receiver_sensor.htm&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
Cheers,&lt;BR /&gt;
Jan&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 07 Jul 2015 16:38:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-syslog-severity-overview/m-p/31024#M5403</guid>
      <dc:creator>SchmuFoo</dc:creator>
      <dc:date>2015-07-07T16:38:00Z</dc:date>
    </item>
    <item>
      <title>RE: EXOS Syslog Severity Overview?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-syslog-severity-overview/m-p/31025#M5404</link>
      <description>Jan,&lt;BR /&gt;
&lt;BR /&gt;
The EXOS EMS Messages Catalog contains a significant amount of information regarding EXOS log messages including severity level. Here is a link to the EXOS EMS Messages Catalog.&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="http://documentation.extremenetworks.com/ems_catalog/downloads/EMS_Messages_Catalog.pdf" target="_blank" rel="nofollow noreferrer noopener"&gt;http://documentation.extremenetworks.com/ems_catalog/downloads/EMS_Messages_Catalog.pdf&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
-Andrew &lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 07 Jul 2015 19:08:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-syslog-severity-overview/m-p/31025#M5404</guid>
      <dc:creator>Andrew_Maldonad</dc:creator>
      <dc:date>2015-07-07T19:08:00Z</dc:date>
    </item>
    <item>
      <title>RE: EXOS Syslog Severity Overview?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-syslog-severity-overview/m-p/31026#M5405</link>
      <description>Link is dead. Found new EMS Messages Catalog: &lt;A href="http://documentation.extremenetworks.com/ems_catalog_22.1/EMS_Messages_21/introduction.shtml" target="_blank" rel="nofollow noreferrer noopener"&gt;http://documentation.extremenetworks.com/ems_catalog_22.1/EMS_Messages_21/introduction.shtml&lt;/A&gt;</description>
      <pubDate>Tue, 07 Jul 2015 19:08:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-syslog-severity-overview/m-p/31026#M5405</guid>
      <dc:creator>Ryan_Yacobucci</dc:creator>
      <dc:date>2015-07-07T19:08:00Z</dc:date>
    </item>
    <item>
      <title>RE: EXOS Syslog Severity Overview?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-syslog-severity-overview/m-p/31027#M5406</link>
      <description>Jan,&lt;BR /&gt;
&lt;BR /&gt;
Here is a link to a section of the EXOS Command Reference Guide that goes into more detail regarding the severity levels.&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="http://documentation.extremenetworks.com/exos_commands/EXOS_All/EXOS_Commands_All/r_configure-log-target-severity.shtml" target="_blank" rel="nofollow noreferrer noopener"&gt;http://documentation.extremenetworks.com/exos_commands/EXOS_All/EXOS_Commands_All/r_configure-log-ta...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
-Andrew</description>
      <pubDate>Tue, 07 Jul 2015 19:48:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-syslog-severity-overview/m-p/31027#M5406</guid>
      <dc:creator>Andrew_Maldonad</dc:creator>
      <dc:date>2015-07-07T19:48:00Z</dc:date>
    </item>
    <item>
      <title>RE: EXOS Syslog Severity Overview?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-syslog-severity-overview/m-p/31028#M5407</link>
      <description>Hi Jan,&lt;BR /&gt;
&lt;BR /&gt;
The severity should line up with the severity in &lt;A href="https://www.ietf.org/rfc/rfc3164.txt" target="_blank" rel="nofollow noreferrer noopener"&gt;RFC 3164 &lt;/A&gt;. &lt;BR /&gt;
Numerical Code        Severity       0            Emergency: system is unusable       1            Alert: action must be taken immediately       2            Critical: critical conditions       3            Error: error conditions       4            Warning: warning conditions       5            Notice: normal but significant condition       6            Informational: informational messages       7            Debug: debug-level messages        EXOS does not use Emergency or Alert, so the highest severity that will be seen is 2 (Critical). Debug-data, debug-summary, and debug-verbose will all be sent with severity 7.&lt;BR /&gt;
&lt;BR /&gt;
-Brandon</description>
      <pubDate>Tue, 07 Jul 2015 21:21:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-syslog-severity-overview/m-p/31028#M5407</guid>
      <dc:creator>BrandonC</dc:creator>
      <dc:date>2015-07-07T21:21:00Z</dc:date>
    </item>
    <item>
      <title>RE: EXOS Syslog Severity Overview?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-syslog-severity-overview/m-p/31029#M5408</link>
      <description>I also created a GTAC Knowledge article with further information regarding this:&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://gtacknowledge.extremenetworks.com/articles/Q_A/How-do-EXOS-log-severities-map-to-the-numerical-severity-in-syslog-messages/" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/Q_A/How-do-EXOS-log-severities-map-to-the-numeric...&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 07 Jul 2015 21:21:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-syslog-severity-overview/m-p/31029#M5408</guid>
      <dc:creator>BrandonC</dc:creator>
      <dc:date>2015-07-07T21:21:00Z</dc:date>
    </item>
    <item>
      <title>RE: EXOS Syslog Severity Overview?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-syslog-severity-overview/m-p/31030#M5409</link>
      <description>Brandon and Andrew...really nice job bridging the gap between our formal technical publications and EXOS.  Your GTAC Knowledge article and reference to the RFC are spot on.&lt;BR /&gt;
&lt;BR /&gt;
Jan,&lt;BR /&gt;
Thank you for providing the Cisco example on what you'd like to see from Extreme.  Not only did that help Brandon and Andrew address your inquiry quickly with the KB, it also gave us some good feedback to provide our Information Dev team to improve our technical publications.  &lt;BR /&gt;
&lt;BR /&gt;
Along those lines, I created a GTAC Knowledge article to capture how you give feedback on our formal technical publications in the future.&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://gtacknowledge.extremenetworks.com/articles/Q_A/Where-do-I-provide-feedback-on-Extreme-s-Technical-Publications" target="_blank" rel="nofollow noreferrer noopener"&gt;https://gtacknowledge.extremenetworks.com/articles/Q_A/Where-do-I-provide-feedback-on-Extreme-s-Tech...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
Lots of quality collaboration here.  Good stuff!</description>
      <pubDate>Tue, 07 Jul 2015 21:21:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-syslog-severity-overview/m-p/31030#M5409</guid>
      <dc:creator>Ryan_Mathews</dc:creator>
      <dc:date>2015-07-07T21:21:00Z</dc:date>
    </item>
    <item>
      <title>RE: EXOS Syslog Severity Overview?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-syslog-severity-overview/m-p/31031#M5410</link>
      <description>Thank you all very much, your feedback, motivation AND response time is outstanding and realy realy appreciated!&lt;BR /&gt;
&lt;BR /&gt;
Before doing business with Extreme Networks, there where only one single vendor which impressed me for many years in a similar manner:&lt;BR /&gt;
&lt;BR /&gt;
-&amp;gt; F5 Networks which their Knowledge Portal "Ask F5" (&lt;A href="https://support.f5.com/kb/en-us.html" target="_blank" rel="nofollow noreferrer noopener"&gt;https://support.f5.com/kb/en-us.html&lt;/A&gt;)&lt;BR /&gt;
&lt;BR /&gt;
Great to see that you step in their footsteps (From my point of view) &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
&lt;BR /&gt;
Cheers from Cologne,&lt;BR /&gt;
Jan&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Tue, 07 Jul 2015 21:21:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-syslog-severity-overview/m-p/31031#M5410</guid>
      <dc:creator>SchmuFoo</dc:creator>
      <dc:date>2015-07-07T21:21:00Z</dc:date>
    </item>
    <item>
      <title>RE: EXOS Syslog Severity Overview?</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-syslog-severity-overview/m-p/31032#M5411</link>
      <description>Wow...thanks for the great comments Jan.&lt;BR /&gt;
&lt;BR /&gt;
Also very much appreciate the F5 reference.  That's a great company and we're always looking to learn ways to improve.  Keep the feedback coming!</description>
      <pubDate>Tue, 07 Jul 2015 21:21:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/exos-syslog-severity-overview/m-p/31032#M5411</guid>
      <dc:creator>Ryan_Mathews</dc:creator>
      <dc:date>2015-07-07T21:21:00Z</dc:date>
    </item>
  </channel>
</rss>

