cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
419
Views
3
Helpful
2
Replies

Missing log from fwsm

justinvo
Level 1
Level 1

Hi,

I noticed that some of our fwsm traffic log is not appearing in the syslog server. I noticed in the show logging queue, it's reporting discard messages like below:

fwsm# sh logg que

Logging Queue length limit : 512 msg(s), 921036 msg(s) discarded.

Current 512 msg on queue, 512 msgs most on queue

fwsm# sh logg que

Logging Queue length limit : 512 msg(s), 921654 msg(s) discarded.

Current 512 msg on queue, 512 msgs most on queue

Does anyone know what it mean by this ? I have tried to increase the queue to 2048 but after a few minutes, it start to fill up and discard message counter increase. I tried to set unlimited but the Current Msg counter keep increment without going down. Does this mean the fw is dropping or the syslog server is too slow to serve ?

Any comments or ideas are welcome

Thanks

Justin Vo

2 Replies 2

Hi,

Disable local logging ...

Only test with logging trap 4 and then with trap 7.

Check your logging server and check trough a repeated ping if the connection is not dropping.

If you find this post usefull

please don't forget to rate this

#########################################

#Iwan Hoogendoorn

#########################################

I have done some tests and what i found is the logging console 7 seem to be the cause. I turned it off and the queue reduced down to 0.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: