cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
916
Views
5
Helpful
1
Replies

Setting up another Email to send syslog events to

47csnetops
Level 1
Level 1

I have followed the directions on http://www.cisco.com/en/US/products/sw/cscowork/ps2421/products_user_guide_chapter09186a00804fc54a.html to setup DFM to forward syslog events to my email. These current settings are not working at all. Here are my settings.

Summary from Syslog Notification

Subscription Name: TEST

Notification Group: Test

Facility: Local Use 7

Location: Ciscoworks

Recipient(s): Hostname Port Comments

syslog 162

Notification Group Summary: Edit

Notification Group Name: Test

Device List: 192.168.111.15 ; 192.168.109.16 ; 192.168.109.15 ; 192.168.102.2 ; 205.250.5.15 ; 198.190.47.16 ; 198.190.47.15 ; 192.168.109.249 ; 192.168.109.248 ; 192.168.100.2 ; 192.168.109.247 ; 192.168.109.246 ; 192.168.89.6 ;

Alarm Status: Active ; ACK ; Cleared ;

Event Set: C

Event Severity: Critical ; Warning ; Informational ;

Event Status: Active ; Cleared ;

Customer Identification: Test

Customer Revision: 2

1 Reply 1

Joe Clarke
Cisco Employee
Cisco Employee

It seems you have confused syslog and SNMP traps. DFM does not process syslog messages, so it will not be able to forward syslog messages via email. RME's Automated Action feature has this capability. See the online help under RME > Tools > Syslog > Automated Actions for more details on that.

What DFM will allow you to do is convert the events and alerts you see in the DFM Alerts and Activities Display into email messages. For this to work, you will need to create an Email notification subscription in DFM, and specify your email address as the recipient. You can use the same notification group, but you might want to consider NOT sending alerts if you are sending events. An event marks an individual device problem where as an alert rolls up multiple events for a given device. By sending both, you will see emails that appear to be duplicates.