Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

3500xl addr flap syslog traffic

1. Oct 17 2006 21:01:37 RTD 1 ADDR_FLAP GigabitEthernet0/1 relearning 5 addrs per min

2. Oct 17 2006 20:59:07 RTD 1 ADDR_FLAP GigabitEthernet0/2 relearning 5 addrs per min

I have tons of syslog msg's from a site similar to above. The site has a non cisco wireless installed that creates a moving smorgasbord of mac addresses.

I would prefer not to get these msg's on the management console.. how do i kill just this specific syslog msg without killing all others?

For obvious reasons, I do not want to turn off level 2 syslog traffic and higher. I would prefer to just kill this one type of syslog traffic.

Any suggestions? Either at the switch level or can i filter these somehow in ciscoworks (running latest 2.6 release)?

Cisco Employee

Re: 3500xl addr flap syslog traffic

The only way to filter these at the switch would be using the Embedded Syslog Manager. Unfortunately, ESM is not support on XL series switches.

That just leaves the receiving end. You can easily filter these messages in RME by creating a syslog filter under RME > Tools > Syslog > Message Filters. Make sure your Message Filter Type is set to Drop, and create a new filter with the following parameters:

Facility : RTD

Sub-facility : *

Severity : 1

Mnemonic : ADDR_FLAP

Description : *