
Using Syslog Messaging to Monitor Router Events
308657-14.00 Rev 00
C-7
Filtering by Event Severity Level
Each event message generated by the router software has a unique severity level.
You can use severity levels to filter these messages (that is, you define a severity
mask for the filter).
Syslog uses the severity levels as criteria for selecting and forwarding only the
types of messages you want a remote host to receive.
An entity filter passes only messages that have a severity level equal to any you
specified in the message severity mask. You define severity levels by setting a
value for the wfSyslogEntFltrSevMask filter attribute in the router’s active MIB.
For example, if an entity filter for FTP has a Message Severity Mask of “wfi,” the
filter passes only FTP event messages that have a severity level of warning (w),
fault (f), or information (i).
Filtering by Slot Number
The router stores event messages in the log buffer associated with each slot. You
can configure an entity filter to select for forwarding only event messages logged
on the slots you specify. You must specify at least one slot in the range 1 to 14,
where the slot numbers depend on the router model.
You define a range of slot numbers for an entity filter by specifying:
• An upper boundary number (MIB object wfSyslogFltrSlotUppBnd)
• A lower boundary number (MIB object wfSyslogFltrSlotLowBnd)
Syslog considers the upper and lower boundary numbers as part of the range. For
example, you can configure an entity filter for FTP with an event number range of
5 to 27 and a slot number range of 2 to 5. In this case, Syslog forwards to the
associated remote host FTP log messages numbered 5 to 27 logged on slots 2 to 5
only.
Note:
Syslog checks the message severity mask only when you accept the
default event message number range of 0 to 255 for the same filter. This causes
Syslog to ignore event numbers as criteria for selecting and forwarding
messages to a remote host.
Kommentare zu diesen Handbüchern