Specifications
14-44
Cisco NAC Appliance - Clean Access Manager Configuration Guide
OL-28003-01
Chapter 14 Administering the CAM
Support Logs
To Change the Loglevel for CAM Logs:
Step 1 Go to Administration > CCA Manager > Support Logs.
Step 2 Choose the CAM log category to change:
• CCA Manager General Logging: This category contains the majority of logging events for the
system. Any log event not contained in the other four categories listed below will be found under
CCA Manager General Logging (e.g. authentication failures).
• CAS/CAM Communication Logging: This category contains CAM/CAS configuration or
communication errors, for example, if the CAM’s attempt to publish information to the CAS fails,
the event will be logged.
• General OOB Logging: This category contains general OOB errors that may arise from incorrect
settings on the CAM, for example, if the system cannot process an SNMP linkup trap from a switch
because it is not configured on the CAM or is overloaded.
• Switch Management Logging: This category contains generic SNMP errors that can arise from the
CAM directly communicating with the switch, for example, if the CAM receives an SNMP trap for
which the community string does not match.
• Low-level Switch Communication Logging: This category contains OOB errors for specific switch
models.
• CAM/ Profiler Communication Logging: This category contains the logs/errors at different levels
of the synchronization of the Cisco ISE Profiler with NAC Appliance.
Note This applies only to Cisco ISE Profiler and does not include NAC Profiler.
Step 3 Click the loglevel setting for the category of log:
• OFF: No log events are recorded for this category.
• ERROR: A log event is written to/perfigo/control/tomcat/logs/nac_manager.log only if the
system encounters a severe error, such as:
–
CAM cannot connect to CAS
–
CAM and CAS cannot communicate
–
CAM cannot communicate with database
• WA R N: Records only error and warning level messages for the given category.
• INFO: Provides more details than the ERROR and WAR N log levels. For example, if a user logs
in successfully an Info message is logged. This is the default level of logging for the system.
• DEBUG: Records all debug-level logs for the CAM.
• TRACE: This is the maximum amount of log information available to help troubleshoot issues with
the CAM/CAS.
Step 4 Click Update to save the settings.
Note Cisco recommends using the Debug and Trace options only temporarily for very specific issues.
Although the CAM records logging information and stores them in a series of ten 20MB files before
discarding any old logs, the large amount of logging information can cause the CAM to run out of
available log storage space in a relatively short amount of time.