Centrally manage the Syslog syslog of switches and routers
one. Configure the server side
Configure the log server
Install the 64-bit free version of splunk
Create a new "Import data" to listen to the udp514 port, and the default received logs are stored in the index "main".
You can create new logs according to different switch logs, create different indexes, and then associate them to the new index in the process of "importing data".
In the search, the keyword: index= "new index name"
two。 If there is a firewall on the log server, make sure that "udp514" and "tcp146" are turned on in the inbound rules
two. Configure the client
Cisco switch, router
1 Open the log service Router (config) # logging on
2 define the log server address Router (config) # logging host 192.168.2.100
3 define Router (config) # service timestamps log datetime localtime show-timezone msec
3 define Router (config) # service timestamps debug datetime localtime show-timezone msec
4 define facility level Router (config) # logging facility local7 (default)
5 # define severity level Router (config) # logging trap 4
Finally, set the time zone
2.cisco asa equipment
Logging enable
Logging host inside a.b.c.d
Logging source-interface vlan 1 (original address of log packet)