Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Attention: The Community will be in read-only mode on 12/14/2017 from 12:00 am pacific to 11:30 am.

During this time you will only be able to see content. Other interactions such as posting, replying to questions, or marking content as helpful will be disabled for few hours.

We apologize for the inconvenience while we perform important updates to the Community.

New Member

Syslog Server Settings

Hello Experts,

We are in process of configiuring the Network devices to send the logs to syslog server that we newly setup in our enviornment. Below is the config that we did over the network devices:

conf t

logging host transport udp port 520

logging trap informational


write memory.

We are using the software that will report the alert of any failure attemps of network devices but when I try to create some dummy login failures then there are no logs being shown up on syslog server and no alert is triggered for the same.

Can somebody help me in this issue as we have no problem with the Cisco ASA firewall.



Syslog Server Settings

New Member

Syslog Server Settings

Thanks John.

Can you please tell me what logs the Cisco appliance (Router and Switch) is send to the Syslog Server when the trap is set "informational".

The same settings is done on Cisco ASA firewall and it logged everything (Attacks, Spoof, Failure, Successfull attemps and etc.)

I reviewed the resolution stated in the link that you are given and we need to set the additional config on router to have the successfull/failure log events:

login block-for 60 attempts 3 within 60

login on-failure log every 3

login on-success log

We are using

Version 12.4(15)T12, RELEASE SOFTWARE (fc3)



New Member

Syslog Server Settings

Also what about the dropped traffic from access lists, is it required some additional settings on Router/Switch?


Syslog Server Settings


I honestly don't know everythign that is included with the Information Level. Except for that it includes everything at the INformation Level and above.

You would have to search for a link to find this information I'm sure.

Depending on where your syslog server is, I would recommend, not logging so much that you really can't tell what's going on.

CreatePlease to create content