[c-nsp] Cisco boxes and Syslog-ng

A.Rahman Isnaini R.suTan risnaini at indo.net.id
Wed Sep 7 23:50:17 EDT 2005



I noted that Cisco couldn't log the traffic with thousands hits persecond.
They shown on the ACL matches but not shown either on "show logging"  or 
in the log file of syslog-ng server.

I believe there is a limitation or threshold hits that Cisco could log them.

Ariel Biener wrote:

> Are we talking about high volume or low volume (in lines per second) ?
> In general, assuming you define the same syslog severity and facility (log
> level) on your various Cisco routers, then it will include an identifier of
> who sent the syslog entry. Now, syslog (regular, see NG below) accepts
> as out either files, or a pipe `|' to a script. Your script can then
> manipulate the entries, and write each to it's own file based on whatever
> you write in that script.
> 

:: Rahman Isnaini R suTan
:: Network Operation Engineer
:: PT IndoInternet




More information about the cisco-nsp mailing list