cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1188
Views
0
Helpful
18
Replies

zero record syslog reports

jwright
Level 1
Level 1

I am getting reports of 0 records when running reports on at least one switch that is sending data to LMS. RME version is 4.1.1. I've viewed syslog.log and it contains the messages from the switch. I've disabled all message filters but still get nothing from any reports on the device. Ideas?

18 Replies 18

Joe Clarke
Cisco Employee
Cisco Employee

Disabling all message filters is probably the problem. If you disable all filters, make sure the mode is set to KEEP instead of the default DROP.

I tried that before posting but it still isn't working.

Post the output of the pdshow command as well as some of the sample messages not appearing in your syslog reports.

pdshow attached

sample messages include:

Aug 28 09:27:15: %SNMP-3-AUTHFAIL: Authentication failure for SNMP req from host 10.x.x.81

Aug 28 09:28:02: %SEC-6-IPACCESSLOGP: list ???_??? permitted tcp 10.x.x.x(xxxx) -> 0.0.0.0(xxx), 1 packet

This looks okay. Post the SyslogCollector.log and AnalyzerDebug.log.

analyzerdebug attached

syslog collector attached

This all looks healthy. In fact, I'm seeing evidence that syslogs are being processed. Exactly what reports are you running, and how are you running them? Post a screenshot of RME > Tools > Syslog > Syslog Collector Status.

I'm trying to run 24 hour reports on the devices in question. But even standard reports return zero records. A show logging from the devices via telnet shows plenty of snmp authentication failures within the past 24 hours but all reports return zero records. The messages are in the syslog.log file... I just checked again. The only difference being that I run the report based on host name while the log file shows the IP address for the device. The server is getting the data but RME won't show it in a report. The messages I posted earlier should show up in a 24 hour report correct?

Yes, they should. Try running an Unexpected Devices Report to see if the syslog messages show up there. Also, post the NMSROOT/MDC/tomcat/webapps/rme/WEB-INF/classes/com/cisco/nm/rmeng/csc/data/filters.dat file.

Not showing up in unexpected devices... filters.dat attached.

Enable SyslogAnalyzer debugging under RME > Admin > System Preferences > Loglevel Settings, regenerate some new messages, then re-post the AnalyzerDebug.log along with the messages that were generated.

Requested info attached.

According to this, device device generating the SEC-6-IPACCESSLOGP message is not properly managed by RME. It is either in a suspended state or a conflicting state. You need to fix that problem by either resuming management of the device, or correcting the device type.

The same is true for the CONFIG_I message and the AUTHFAIL message.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: