Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Configure Centralized Syslog Management and Forwarding in NextGen Port Extender

Configure syslog forwarding in your NextGen Port Extender (NGPE) topology, allowing satellite devices to send syslog data to the aggregation device. The aggregation device collects syslog data from the satellite devices and forwards the data to an external device. You can configure syslogging for a variety of situations, so we cover multiple scenarios.

Configure File-Based Syslog

Configure a file to capture syslog data.
Confirm that syslogs are generated on the satellite device.

Configure Match-Based Syslog

  1. Configure a file to capture syslog data.
  2. Configure match parameters using a regular expression.
    Confirm that syslogs are generated on the satellite device.

Configure a Structured Format-Based Syslog

  1. Configure a file to capture syslog data.
  2. Configure the file to use the structured-format statement. This statement has an additional sub-option of brief, which if applied will omit English language text from the end of logged messages. brief is an optional configuration component.
    Confirm that syslogs are generated on the satellite device.

Configure Explicit Priority-Based Syslog

  1. Configure a file to capture syslog data.
  2. Configure the file to use the explicit-priority statement, which includes the priority and facility in log messages.
    Confirm that syslogs are generated on the satellite device.

Configure User-Based Syslog

Configure a file to capture syslog data, including the username to log.
Confirm that syslogs are generated on the satellite device.

Configure Syslog Forwarding to the Aggregation Device

Configure a satellite device to send syslog data to the aggregation device.
Confirm that syslogs are forwarded from the satellite device.

Configure Syslog Forwarding to an External Server

  1. Configure a file to capture syslog data.
  2. Configure a satellite device to send syslog data to the aggregation device.
  3. Configure the aggregation device to forward syslogs to an external server.

    All syslog messages received from satellite devices retain their original source address or hostname within the log format when processed by the aggregation device. However, when these logs are sent to the external server, the source IP or hostname is updated to that of the aggregation device. Since the original hostname is preserved in the log format and is unique per device, logs originating from individual satellite devices can still be easily distinguished.