02-26-2007 05:09 PM - edited 03-09-2019 05:28 PM
Hi,
I noticed that some of our fwsm traffic log is not appearing in the syslog server. I noticed in the show logging queue, it's reporting discard messages like below:
fwsm# sh logg que
Logging Queue length limit : 512 msg(s), 921036 msg(s) discarded.
Current 512 msg on queue, 512 msgs most on queue
fwsm# sh logg que
Logging Queue length limit : 512 msg(s), 921654 msg(s) discarded.
Current 512 msg on queue, 512 msgs most on queue
Does anyone know what it mean by this ? I have tried to increase the queue to 2048 but after a few minutes, it start to fill up and discard message counter increase. I tried to set unlimited but the Current Msg counter keep increment without going down. Does this mean the fw is dropping or the syslog server is too slow to serve ?
Any comments or ideas are welcome
Thanks
Justin Vo
02-28-2007 12:45 AM
Hi,
Disable local logging ...
Only test with logging trap 4 and then with trap 7.
Check your logging server and check trough a repeated ping if the connection is not dropping.
If you find this post usefull
please don't forget to rate this
#########################################
#Iwan Hoogendoorn
#########################################
02-28-2007 02:38 AM
I have done some tests and what i found is the logging console 7 seem to be the cause. I turned it off and the queue reduced down to 0.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: