Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Syslog question

Status
Not open for further replies.

yanks2112

IS-IT--Management
Jan 5, 2004
110
US
Hi All

I have about 20 switches throughout my organization (Catalyst 2950) and I want to send logs to a syslog server. I am able to configure logging and send syslogs to the syslog server with no problem. My questions are:

1) Is is wise to log all 20 switches to a syslog server, that may be a stupid question but I was curious in terms of traffic over the wire sending the syslogs.

2) How do I differentiate between the switches? I see the syslogs in the same log file for all the switches (so far I've done 2) and I cant find a way to differentiate the two switches.

Thanks for your help
 
What syslog program are you using? I use SolarWinds and it has the switches all in one log, but there's an IP column, which tells you which switch the event came from. Maybe you just need to add a column to your view.

In answer to your first question, even logging at the highest level (6 - you get every thing from interfaces going up and down to dup mismatches, etc., to more severe messages), it shouldn't be a problem. I have over a hundred switches and routers all syslogging to the same syslog server (running on a Win2k Workstation) and haven't had any traffic problems.
 
It shouldn't be a problem sending those logs . While it may seem like a lot , these are basically small text messages which don't take a lot of bandwidth or space . You do need to set a date on how long you want to keep the messages otherwise your file size would eventually become huge if you never delete anything.
 
Thanks for the info chipk and viperg, I am using the syslog server that came with my PIX. It time stamps the logs for the PIX but not for the switches. Is there a separate syslog program for the switches or is there a parameter within the logging option to set the time stamp on the logs

Thanks again
 
Actually it does time stamp the logs but I can't tell which messages are from what switch, is there a parameter that I can set that will tell me the switch that is sending the syslog message

Thanks again
 
Sorry for asking a question before researching. I dwnloaded KIWI syslog server and it does everything I need, including the ip of the switch sending the logs

Thanks again
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top