<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forward Event Logs on non-Standard Port in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Forward-Event-Logs-on-non-Standard-Port/m-p/159555#M36423</link>
    <description>&lt;P&gt;I'm not sure what version of OnTap you are using but yes you can in OnTap 9.&amp;nbsp; Here is the man page for OnTap 9.3.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1 class="title topictitle1"&gt;cluster log-forwarding create&lt;/H1&gt;
&lt;DIV class="body refbody"&gt;
&lt;P class="shortdesc"&gt;Create a log forwarding destination&lt;/P&gt;
&lt;DIV class="section"&gt;&lt;STRONG class="ph b"&gt;Availability:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;This command is available to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM class="ph i"&gt;cluster&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;administrators at the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM class="ph i"&gt;admin&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;privilege level.&lt;/DIV&gt;
&lt;DIV class="section"&gt;
&lt;H2 class="title sectiontitle"&gt;Description&lt;/H2&gt;
The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="keyword cmdname"&gt;cluster log-forwarding create&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;command creates log forwarding destinations for remote logging.&lt;/DIV&gt;
&lt;DIV class="section"&gt;
&lt;H2 class="title sectiontitle"&gt;Parameters&lt;/H2&gt;
&lt;DL class="dl parml"&gt;
&lt;DT class="dt pt dlterm"&gt;&lt;SPAN class="keyword option"&gt;-destination&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR class="keyword varname"&gt;&amp;lt;Remote InetAddress&amp;gt;&lt;/VAR&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Destination Host&lt;/DT&gt;
&lt;DD class="dd pd"&gt;Host name or IPv4 or IPv6 address of the server to forward the logs to.&lt;/DD&gt;
&lt;DT class="dt pt dlterm"&gt;[&lt;SPAN class="keyword option"&gt;-port&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR class="keyword varname"&gt;&amp;lt;integer&amp;gt;&lt;/VAR&gt;] - Destination Port&lt;/DT&gt;
&lt;DD class="dd pd"&gt;The port that the destination server listen on.&lt;/DD&gt;
&lt;DT class="dt pt dlterm"&gt;[&lt;SPAN class="keyword option"&gt;-protocol&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR class="keyword varname"&gt;{udp-unencrypted|tcp-unencrypted|tcp-encrypted}&lt;/VAR&gt;] - Log Forwarding Protocol&lt;/DT&gt;
&lt;DD class="dd pd"&gt;The protocols are used for sending messages to the destination. The protocols can be one of the following values:
&lt;UL class="ul"&gt;
&lt;LI class="li"&gt;&lt;VAR class="keyword varname"&gt;udp-unencrypted&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/VAR&gt;- User Datagram Protocol with no security&lt;/LI&gt;
&lt;LI class="li"&gt;&lt;VAR class="keyword varname"&gt;tcp-unencrypted&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/VAR&gt;- Transmission Control Protocol with no security&lt;/LI&gt;
&lt;LI class="li"&gt;&lt;VAR class="keyword varname"&gt;tcp-encrypted&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/VAR&gt;- Transmission Control Protocol with Transport Layer Security (TLS)&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DD&gt;
&lt;DT class="dt pt dlterm"&gt;[&lt;SPAN class="keyword option"&gt;-verify-server&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR class="keyword varname"&gt;{true|false}&lt;/VAR&gt;] - Verify Destination Server Identity&lt;/DT&gt;
&lt;DD class="dd pd"&gt;When this parameter is set to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;KBD class="ph userinput nolinebreak"&gt;true&lt;/KBD&gt;, the identity of the log forwarding destination is verified by validating its certificate. The value can be set to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;KBD class="ph userinput nolinebreak"&gt;true&lt;/KBD&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;only when the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR class="keyword varname"&gt;tcp-encrypted&lt;/VAR&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;value is selected in the protocol field. When this value is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;KBD class="ph userinput nolinebreak"&gt;true&lt;/KBD&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;the remote server might be validated by OCSP. The OCSP validation for cluster logs is controlled with the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="xref nopagenum"&gt;&lt;SPAN class="keyword cmdname"&gt;security config ocsp enable -app audit_log&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="xref nopagenum"&gt;&lt;SPAN class="keyword cmdname"&gt;security config ocsp disable -app audit_log&lt;/SPAN&gt;&lt;/SPAN&gt;.&lt;/DD&gt;
&lt;DT class="dt pt dlterm"&gt;[&lt;SPAN class="keyword option"&gt;-facility&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR class="keyword varname"&gt;&amp;lt;Syslog Facility&amp;gt;&lt;/VAR&gt;] - Syslog Facility&lt;/DT&gt;
&lt;DD class="dd pd"&gt;The syslog facility to use for the forwarded logs.&lt;/DD&gt;
&lt;DT class="dt pt dlterm"&gt;[&lt;SPAN class="keyword option"&gt;-force&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR class="keyword varname"&gt;[true]&lt;/VAR&gt;] - Skip the Connectivity Test&lt;/DT&gt;
&lt;DD class="dd pd"&gt;Normally, the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="keyword cmdname"&gt;cluster log-forwarding create&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;command checks that the destination is reachable via an ICMP ping, and fails if it is not reachable. Setting this value to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;KBD class="ph userinput nolinebreak"&gt;true&lt;/KBD&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;bypasses the ping check so that the destination can be configured when it is unreachable.&lt;/DD&gt;
&lt;/DL&gt;
&lt;/DIV&gt;
&lt;DIV class="example"&gt;
&lt;H2 class="title sectiontitle"&gt;Examples&lt;/H2&gt;
This example causes audit logs to be forwarded to a server at address 192.168.0.1, port 514 with USER facility.
&lt;PRE class="pre screen" space="preserve"&gt;cluster1::&amp;gt; cluster log-forwarding create -destination 192.168.0.1 -port 514 -facility user&lt;BR /&gt;&lt;BR /&gt;https://docs.netapp.com/ontap-9/index.jsp?topic=%2Fcom.netapp.doc.dot-cm-cmpr-930%2Fcluster__log-forwarding__create.html
    &lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Mon, 21 Sep 2020 15:12:18 GMT</pubDate>
    <dc:creator>nboggs</dc:creator>
    <dc:date>2020-09-21T15:12:18Z</dc:date>
    <item>
      <title>Forward Event Logs on non-Standard Port</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Forward-Event-Logs-on-non-Standard-Port/m-p/159545#M36420</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a FAS2620 running ONTAP 9.3. We need to send the Event logs to a location using a non-standard port, 5514 vice 514. Can that be done? The command syntax does not look like it does.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 10:53:03 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Forward-Event-Logs-on-non-Standard-Port/m-p/159545#M36420</guid>
      <dc:creator>jtovb</dc:creator>
      <dc:date>2025-06-04T10:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: Forward Event Logs on non-Standard Port</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Forward-Event-Logs-on-non-Standard-Port/m-p/159555#M36423</link>
      <description>&lt;P&gt;I'm not sure what version of OnTap you are using but yes you can in OnTap 9.&amp;nbsp; Here is the man page for OnTap 9.3.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1 class="title topictitle1"&gt;cluster log-forwarding create&lt;/H1&gt;
&lt;DIV class="body refbody"&gt;
&lt;P class="shortdesc"&gt;Create a log forwarding destination&lt;/P&gt;
&lt;DIV class="section"&gt;&lt;STRONG class="ph b"&gt;Availability:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;This command is available to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM class="ph i"&gt;cluster&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;administrators at the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM class="ph i"&gt;admin&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;privilege level.&lt;/DIV&gt;
&lt;DIV class="section"&gt;
&lt;H2 class="title sectiontitle"&gt;Description&lt;/H2&gt;
The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="keyword cmdname"&gt;cluster log-forwarding create&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;command creates log forwarding destinations for remote logging.&lt;/DIV&gt;
&lt;DIV class="section"&gt;
&lt;H2 class="title sectiontitle"&gt;Parameters&lt;/H2&gt;
&lt;DL class="dl parml"&gt;
&lt;DT class="dt pt dlterm"&gt;&lt;SPAN class="keyword option"&gt;-destination&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR class="keyword varname"&gt;&amp;lt;Remote InetAddress&amp;gt;&lt;/VAR&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Destination Host&lt;/DT&gt;
&lt;DD class="dd pd"&gt;Host name or IPv4 or IPv6 address of the server to forward the logs to.&lt;/DD&gt;
&lt;DT class="dt pt dlterm"&gt;[&lt;SPAN class="keyword option"&gt;-port&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR class="keyword varname"&gt;&amp;lt;integer&amp;gt;&lt;/VAR&gt;] - Destination Port&lt;/DT&gt;
&lt;DD class="dd pd"&gt;The port that the destination server listen on.&lt;/DD&gt;
&lt;DT class="dt pt dlterm"&gt;[&lt;SPAN class="keyword option"&gt;-protocol&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR class="keyword varname"&gt;{udp-unencrypted|tcp-unencrypted|tcp-encrypted}&lt;/VAR&gt;] - Log Forwarding Protocol&lt;/DT&gt;
&lt;DD class="dd pd"&gt;The protocols are used for sending messages to the destination. The protocols can be one of the following values:
&lt;UL class="ul"&gt;
&lt;LI class="li"&gt;&lt;VAR class="keyword varname"&gt;udp-unencrypted&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/VAR&gt;- User Datagram Protocol with no security&lt;/LI&gt;
&lt;LI class="li"&gt;&lt;VAR class="keyword varname"&gt;tcp-unencrypted&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/VAR&gt;- Transmission Control Protocol with no security&lt;/LI&gt;
&lt;LI class="li"&gt;&lt;VAR class="keyword varname"&gt;tcp-encrypted&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/VAR&gt;- Transmission Control Protocol with Transport Layer Security (TLS)&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DD&gt;
&lt;DT class="dt pt dlterm"&gt;[&lt;SPAN class="keyword option"&gt;-verify-server&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR class="keyword varname"&gt;{true|false}&lt;/VAR&gt;] - Verify Destination Server Identity&lt;/DT&gt;
&lt;DD class="dd pd"&gt;When this parameter is set to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;KBD class="ph userinput nolinebreak"&gt;true&lt;/KBD&gt;, the identity of the log forwarding destination is verified by validating its certificate. The value can be set to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;KBD class="ph userinput nolinebreak"&gt;true&lt;/KBD&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;only when the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR class="keyword varname"&gt;tcp-encrypted&lt;/VAR&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;value is selected in the protocol field. When this value is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;KBD class="ph userinput nolinebreak"&gt;true&lt;/KBD&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;the remote server might be validated by OCSP. The OCSP validation for cluster logs is controlled with the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="xref nopagenum"&gt;&lt;SPAN class="keyword cmdname"&gt;security config ocsp enable -app audit_log&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="xref nopagenum"&gt;&lt;SPAN class="keyword cmdname"&gt;security config ocsp disable -app audit_log&lt;/SPAN&gt;&lt;/SPAN&gt;.&lt;/DD&gt;
&lt;DT class="dt pt dlterm"&gt;[&lt;SPAN class="keyword option"&gt;-facility&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR class="keyword varname"&gt;&amp;lt;Syslog Facility&amp;gt;&lt;/VAR&gt;] - Syslog Facility&lt;/DT&gt;
&lt;DD class="dd pd"&gt;The syslog facility to use for the forwarded logs.&lt;/DD&gt;
&lt;DT class="dt pt dlterm"&gt;[&lt;SPAN class="keyword option"&gt;-force&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR class="keyword varname"&gt;[true]&lt;/VAR&gt;] - Skip the Connectivity Test&lt;/DT&gt;
&lt;DD class="dd pd"&gt;Normally, the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="keyword cmdname"&gt;cluster log-forwarding create&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;command checks that the destination is reachable via an ICMP ping, and fails if it is not reachable. Setting this value to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;KBD class="ph userinput nolinebreak"&gt;true&lt;/KBD&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;bypasses the ping check so that the destination can be configured when it is unreachable.&lt;/DD&gt;
&lt;/DL&gt;
&lt;/DIV&gt;
&lt;DIV class="example"&gt;
&lt;H2 class="title sectiontitle"&gt;Examples&lt;/H2&gt;
This example causes audit logs to be forwarded to a server at address 192.168.0.1, port 514 with USER facility.
&lt;PRE class="pre screen" space="preserve"&gt;cluster1::&amp;gt; cluster log-forwarding create -destination 192.168.0.1 -port 514 -facility user&lt;BR /&gt;&lt;BR /&gt;https://docs.netapp.com/ontap-9/index.jsp?topic=%2Fcom.netapp.doc.dot-cm-cmpr-930%2Fcluster__log-forwarding__create.html
    &lt;/PRE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 21 Sep 2020 15:12:18 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Forward-Event-Logs-on-non-Standard-Port/m-p/159555#M36423</guid>
      <dc:creator>nboggs</dc:creator>
      <dc:date>2020-09-21T15:12:18Z</dc:date>
    </item>
    <item>
      <title>Re: Forward Event Logs on non-Standard Port</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Forward-Event-Logs-on-non-Standard-Port/m-p/159700#M36479</link>
      <description>&lt;P&gt;Thanks nboggs, sorry for the delay. I did the cluster xxx commands and logging is set.&lt;/P&gt;
&lt;P&gt;I was using the event destination xxx commands. That was what was talked about in a NetApp course I am taking. I am getting entries to our log server now with the cluster xxx commands.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2020 13:29:12 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Forward-Event-Logs-on-non-Standard-Port/m-p/159700#M36479</guid>
      <dc:creator>jtovb</dc:creator>
      <dc:date>2020-09-24T13:29:12Z</dc:date>
    </item>
  </channel>
</rss>

