Specifications

March 15, 2011 Page 1 of 13
Configuring Syslog
Thisdocumentprovidesthe followinginformationaboutconfiguringandmonitoringSyslogon
Enterasys
®
NSeries,SSeries,andKSeriesmodularswitches,ASeries,BSeries,CSeries
stackablefixedswitches,andDSeries,GSeries,andISeriesstandalonefixedswitches.
What Is Syslog?
Syslog,shortforSystemLogging,isastandardforforwardinglogmessagesinanIPnetworkthat
istypicallyusedfornetworksystemmanagementandsecurityauditing.Thetermoftenappliesto
boththeactualSyslogprotocol,aswellastheapplicationsendingSyslogmessages.
AsdefinedinRFC3164,the
Syslogprotocolisaclient/servertypeprotocolwhichenablesastation
ordevicetogenerateandsendasmalltextualmessage(lessthan1024bytes)toaremotereceiver
calledtheSyslogserver.MessagesaretransmittedusingUserDatagramProtocol(UDP)packets
andarereceivedonUDPport514.Thesemessages
informaboutsimplechangesinoperational
statusorwarnofmoresevereissuesthatmayaffectsystemoperations.
Why Would I Use Syslog in My Network?
Whenmanagedproperly,logsaretheeyesandearsofyournetwork.Theycaptureeventsand
showyouwhenproblemsarise,givingyouinformationyouneedtomakecriticaldecisions,
whetheryouarebuildingapolicyruleset,finetuninganIntrusionDetectionSystem,or
validatingwhichportsshouldbeopen
onaserver.However,sinceitispracticallyimpossibleto
wadethroughthevolumesoflogdataproducedbyallyourserversandnetworkdevices,Syslog’s
abilitytoplacealleventsintoasingleformatsotheycanbeanalyzedandcorrelatedmakesita
vitalmanagementtool.BecauseSyslog
issupportedbyawidevarietyofdevice sand receivers
For information about... Refer to page...
What Is Syslog? 1
Why Would I Use Syslog in My Network? 1
How Do I Implement Syslog? 2
Syslog Overview 2
Syslog Operation on Enterasys Devices 2
Syslog Components and Their Use 3
Interpreting Messages 6
Configuring Syslog 6
Note: For information about logging on the X-Series, refer to the X-Series Configuration Guide.