Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
New Member

Questions on ICM logging to remote syslog server

Hey guys,

I've set up syslogging to a Splunk server using the capability built into the ICM Logger (CW2K) works and I'm able to see entries. However, I'm not seeing all the messages come across that I'd like. For example, the error logging from CTIOS agent desktop login failures don't seem to show up in the feed, nor do traces of created DNs, etc. in the environment (I can understand the latter, but not the former...). Is there a way to tweak the logging level of this feed, or is it pretty much set.

I've also been experimenting with running dumplog periodicallly to pull in the newest entries and streaming that over, but it seems to tax the box if run in a batch manner....any other potential approaches would be welcome!!


Everyone's tags (6)
CreatePlease to create content