LMS 3.2 Syslogs for CSS not showing up

Unanswered Question
Jan 22nd, 2010
User Badges:

We have several CSS devices that are configured to send logs to our CiscoWorks server.  The CSSs are also configured to log to another syslog system.  We can see log entries for the devices at the other syslog server, but not the CiscoWorks server. I've seen posts about CSS logs not being supported in earlier versions of RME, but from what I've read this should have been fixed by LMS 3.2.  Is there anything I need to configure so that CiscoWorks can process the log entries from the CSS?


CSS 11503, ver 07.50.3.03

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Joe Clarke Fri, 01/22/2010 - 12:42
User Badges:
  • Cisco Employee,
  • Hall of Fame,

    Founding Member

Do you see the CSS syslog messages in the RME server's syslog log (i.e. syslog.log on Windows and /var/log/syslog_info on Solaris)?  If not, then there is most likely a configuration issue on the CSS, or some kind of network filter blocking udp/514 between the CSS and the RME server.

chris.mcgarrah@... Fri, 01/22/2010 - 13:13
User Badges:

Well I think I may have answered my own question.  I see the log entries in syslog.log, but they are not coming from the management adress on the CSS.

I'm guessing this would cause them to not show up in the application since CiscoWorks is using the management address. Is that correct?


If that's the case, how can the source address of the syslogs be changed on the CSS?

Joe Clarke Fri, 01/22/2010 - 13:22
User Badges:
  • Cisco Employee,
  • Hall of Fame,

    Founding Member

Are the messages showing up in the RME "Unexpected devices" syslog report?  RME should be able to determine all of the addresses of the device when matching syslogs.

chris.mcgarrah@... Sun, 01/24/2010 - 17:28
User Badges:

I'm having a difficult time finding the messages in the unexpected device report because there are a couple of unexpected devices that are generating tons of messages. I get the 10,000 message limit for any 24 hour period I select, but haven't been able to locate any from the device in question.  I know a time frame that has some messages from the device because I can see it in syslog.log,  but I can't narrow the window down close enough to see them in the unexpected device report. Any ideas?

Joe Clarke Sun, 01/24/2010 - 18:16
User Badges:
  • Cisco Employee,
  • Hall of Fame,

    Founding Member

Can you generate a new message, then immediately check for it in the log and in the unexpected devices report?  Also, post a sample message which is not showing up in RME.

chris.mcgarrah@... Sun, 01/24/2010 - 20:13
User Badges:

I tried your suggestion but did not see an entry in the Unexpected Device report.


Here are a couple of exmples of messages not showing up in RME:


Jan 21 09:58:16 10.69.166.25 JAN 21 09:58:09 1/1 55309 VRRP-4: Virtual router 12
on interface 10.69.146.25 entering into VRRP negotiation
Jan 21 09:58:16 10.69.166.26 JAN 21 09:58:10 1/1 78692 VRRP-4: Virtual router 12
: master on interface 10.69.166.26

Joe Clarke Sun, 01/24/2010 - 23:25
User Badges:
  • Cisco Employee,
  • Hall of Fame,

    Founding Member

I found a subtle bug in the CSS syslog processing code.  The messages are correct, and are most likely being added to the database.  The problem is they are being added with a timestamp six hours in the future.  So, messages which are generated immediately will not be seen in the reports for six hours.  I wrote a patch which allows me to add your messages to the RME database, and view them in reports in real time.  This would certainly explain why your live test did not work, and may also explain the other problem.  In any event, I would recommend you try my patch as I see no other reason why only CSS messages would not be visible in RME reports.


If you open a TAC service request, and have your engineer contact me directly, I can provide the patch.

chris.mcgarrah@... Tue, 01/26/2010 - 11:03
User Badges:

I've opened SR 613480945 with TAC and they said they would be contacting you for the patch.

Thanks.

Joe Clarke Tue, 01/26/2010 - 16:48
User Badges:
  • Cisco Employee,
  • Hall of Fame,

    Founding Member

I sent your engineer the patch yesterday.

chris.mcgarrah@... Wed, 02/10/2010 - 07:39
User Badges:

The patch worked on my 3.2 system. (top window in screenshot), thanks.


Can the same patch be applied to my 3.1 system (bottom window in screenshot)?


I still have the issue with log entries not showing up in RME if the log message does not come from the management IP address of the CSS.  How can I validate the addresses associated with a device? I do not see IP addresses in the detailed device report for the CSS.

Joe Clarke Wed, 02/10/2010 - 16:38
User Badges:
  • Cisco Employee,
  • Hall of Fame,

    Founding Member

No, the patch cannot be used with LMS 3.1.  It requires 3.2.


If the message comes from a different CSS IP, does it now show up in the Unexpected Device Report?  I don't have a CSS with which to test, but DDR should show all IPs on the device that show up in the ipAddrTable.

d.land Wed, 02/17/2010 - 11:35
User Badges:

Joe,

I'm also experiencing the same problem on LMS 3.1.  Is it possible to get a patch written for 3.1.

Thanks, Dick

Joe Clarke Wed, 02/17/2010 - 12:00
User Badges:
  • Cisco Employee,
  • Hall of Fame,

    Founding Member

Yes, a patch for 3.1 is available from TAC.

Actions

This Discussion