Get the App
SLTechnology News&Howtos  ›  Network Security  › 

Centrally manage the Syslog syslog of switches and routers

Shulou Source: shulou.com Published: 2022-06-01 00:41:53 10月03日 Update

one. Configure the server side

Configure the log server

Install the 64-bit free version of splunk

Create a new "Import data" to listen to the udp514 port, and the default received logs are stored in the index "main".

You can create new logs according to different switch logs, create different indexes, and then associate them to the new index in the process of "importing data".

In the search, the keyword: index= "new index name"

two。 If there is a firewall on the log server, make sure that "udp514" and "tcp146" are turned on in the inbound rules

two. Configure the client

Cisco switch, router

1 Open the log service Router (config) # logging on

2 define the log server address Router (config) # logging host 192.168.2.100

3 define Router (config) # service timestamps log datetime localtime show-timezone msec

3 define Router (config) # service timestamps debug datetime localtime show-timezone msec

4 define facility level Router (config) # logging facility local7 (default)

5 # define severity level Router (config) # logging trap 4

Finally, set the time zone

2.cisco asa equipment

Logging enable

Logging host inside a.b.c.d

Logging source-interface vlan 1 (original address of log packet)

Tags: Log service server index data configuration switch different address time level route router key keyword customer client time zone version port Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno MySQL MariaDB Xiaomi Docker Microsoft