Syslog forwarding from CiscoWorks to remote server

Answered Question
Mar 2nd, 2010

I’m looking at both short term and long term integration and I’d like to know if this is possible under Windows instances of either LMS 2.6 or 3.2.

I’d like to be able to configure the common syslog collector to not only forward messages to the LMS Syslog Analyser but also to a remote host.

I can’t see any relevant field in collector.properties – is it possible to do this from the common collector (which would be my preference) or would this have to be defined as an action within the Syslog Analyser?

In an effort to reduce WAN traffic, I don’t want to simply set an additional syslog destination – I guess I’m trying to find the equivalent of syslogd –h.

Thanks for any suggestions

I have this problem too.
0 votes
Correct Answer by Joe Clarke about 6 years 10 months ago

We hadn't considered syslog-ng when 2.6 was released.  While only 3.2 was certified with this white paper, the same steps could be made to work with 2.6 as well.

Correct Answer by Joe Clarke about 6 years 10 months ago

The SyslogCollector is not designed to forward messages to a general syslog receiver.  What you might want to look into is using syslog-ng as a replacement for the server's syslog server (not the Collector, but the daemon which receives the udp/514 messages).  We have a white paper available on doing this at http://www.cisco.com/en/US/prod/collateral/netmgtsw/ps6504/ps6528/ps2425/white_paper_c11-571038.html .

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (2 ratings)
Loading.
Correct Answer
Joe Clarke Wed, 03/03/2010 - 09:04

The SyslogCollector is not designed to forward messages to a general syslog receiver.  What you might want to look into is using syslog-ng as a replacement for the server's syslog server (not the Collector, but the daemon which receives the udp/514 messages).  We have a white paper available on doing this at http://www.cisco.com/en/US/prod/collateral/netmgtsw/ps6504/ps6528/ps2425/white_paper_c11-571038.html .

cbajelis Wed, 03/03/2010 - 15:46

Thanks, Joe.

Have you seen this solution work with LMS 2.6?

Correct Answer
Joe Clarke Wed, 03/03/2010 - 17:52

We hadn't considered syslog-ng when 2.6 was released.  While only 3.2 was certified with this white paper, the same steps could be made to work with 2.6 as well.

cbajelis Wed, 03/03/2010 - 18:48

Again, thank you, Joe. You have me sorted for both now and next quarter.

Actions

This Discussion