Missing log from fwsm

Unanswered Question
Feb 26th, 2007

Hi,

I noticed that some of our fwsm traffic log is not appearing in the syslog server. I noticed in the show logging queue, it's reporting discard messages like below:

fwsm# sh logg que

Logging Queue length limit : 512 msg(s), 921036 msg(s) discarded.

Current 512 msg on queue, 512 msgs most on queue

fwsm# sh logg que

Logging Queue length limit : 512 msg(s), 921654 msg(s) discarded.

Current 512 msg on queue, 512 msgs most on queue

Does anyone know what it mean by this ? I have tried to increase the queue to 2048 but after a few minutes, it start to fill up and discard message counter increase. I tried to set unlimited but the Current Msg counter keep increment without going down. Does this mean the fw is dropping or the syslog server is too slow to serve ?

Any comments or ideas are welcome

Thanks

Justin Vo

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 3 (1 ratings)
Loading.

Hi,

Disable local logging ...

Only test with logging trap 4 and then with trap 7.

Check your logging server and check trough a repeated ping if the connection is not dropping.

If you find this post usefull

please don't forget to rate this

#########################################

#Iwan Hoogendoorn

#########################################

justinvo Wed, 02/28/2007 - 02:38

I have done some tests and what i found is the logging console 7 seem to be the cause. I turned it off and the queue reduced down to 0.

Actions

This Discussion