Specifications

How Do I Implement Syslog?
March 15, 2011 Page 2 of 13
acrossmultipleplatforms,youcanuseittointegratelogdatafrommanydifferenttypesof
systemsintoacentralrepository.
EfficientSyslogmonitoringandanalysisreducessystemdowntime,increasesnetwork
performance,andhelpstightensecuritypolicies.Itcanhelpyou:
Troubleshootswitches,firewallsandotherdevicesduringinstallationandproblemsituations.
•Performintrusiondetection.
•Trackuseractivity.
How Do I Implement Syslog?
Bydefault,SyslogisoperationalonEnterasysswitchdevicesatstartup.Allgeneratedmessages
areeligibleforloggingtolocaldestinationsandtoremoteserversconfiguredasSyslogservers.
UsingsimpleCLIcommands,youcanadjustdevicedefaultstoconfigurethefollowing:
•Messagesources—whichsystemapplicationsonwhichmodulesshouldlog
messages?
•Messagedestinations—willmessagesbesenttothelocalconsole,thelocalfilesystem,orto
remoteSyslogservers?Whichfacility(functionalprocess)willbeallowedtosendtoeach
destination?
ThefollowingsectionprovidesanoverviewofSyslogfeaturesandfunctionssupportedon
Enterasysdevicesandtheirdefaultconfigurations.Later
sectionswillprovideinstructionson
changingdefaultsettingstosuityournetworkloggingneeds.
Syslog Overview
Developersofvariousoperatingsystems,processes,andapplicationsdeterminethe circumstances
thatwillgeneratesystemmessagesandwritethosespecificationsintotheirprograms.Messages
canbegeneratedtogivestatus,eitheratacertainperiodoftime,oratsomeotherinterval,suchas
theinvocationorexitofaprogram.
Messagescanalsobegeneratedduetoasetofconditions
beingmet.Typically,developersquantifythesemessagesintooneofseveralbroadcategories,
generallyconsistingofthefacilitythatgeneratedthem,alongwithanindicationoftheseverityof
themessage.Thisallowssystemadministratorstoselectivelyfilterthe
messagesandbe presented
withthemoreimportantandtimesensitivenotificationsquickly, whilealsohavingtheabilityto
placestatusorinformativemessagesinafileforlaterreview.
Switchesmustbeconfiguredwithrulesfordisplayingand/orforwardingev entmessages
generatedbytheirapplications.Inaddition,Syslogserversneed
tobeconfiguredwith
appropriaterulestocollectmessagessotheycanbestoredforfuturereference.Thisdocument
willdescribehowtocompletethesekeyconfigurationstepsonNSeries,SSeries,stackable,and
standaloneswitchplatforms
.
Syslog Operation on Enterasys Devices
TheSyslogimplementationonEnterasysdevicesusesaseriesofsystemloggingmessagestotrack
deviceactivityandstatus.Thesemessagesinformusersaboutsimplechangesinoperational
statusorwarnofmoresevereissuesthatmayaffectsystemoperations.Loggingcanbeconfigured
Note: This guide describes features supported on the N-Series, S-Series, K-Series, stackable, and
standalone switch platforms. For information on X-Series support, refer to the X-Series
Configuration Guide.