<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic problem with event logging in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/problem-with-event-logging/m-p/161476#M36882</link>
    <description>&lt;P&gt;Hi all,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in short - how can I change the formatting on the event logs going to a syslog server?&lt;BR /&gt;&lt;BR /&gt;in detail -&amp;nbsp;&lt;BR /&gt;&amp;nbsp;I have configured my cluster to to send event logs to Splunk.&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;mucfs01::&amp;gt; event notification destination show -name fluentd_sierra
 
                Destination Name: fluentd_sierra
             Type of Destination: syslog
                     Destination: fluentd.sierra.local
 Server CA Certificates Present?: -
   Client Certificate Issuing CA: -
Client Certificate Serial Number: -
       Client Certificate Valid?: -
 
mucfs01::&amp;gt; event filter show -filter-name forSplunk
Filter Name Rule     Rule      Message Name           SNMP Trap Type  Severity
            Position Type
----------- -------- --------- ---------------------- --------------- --------
forSplunk
            1        include   *                      *               EMERGENCY, ALERT, ERROR
            2        exclude   *                      *               *
2 entries were displayed.&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Splunk sees the hostname as cluster nodename + event message name&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="keremcumhur_0-1606211984051.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/10441iA64F0986A35163EB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="keremcumhur_0-1606211984051.png" alt="keremcumhur_0-1606211984051.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And if you look at how packages are being sent from NetApp, the syslog package is created this way.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="keremcumhur_1-1606212082490.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/10442iE5C3DECB0DC46E20/image-size/medium?v=v2&amp;amp;px=400" role="button" title="keremcumhur_1-1606212082490.png" alt="keremcumhur_1-1606212082490.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't know the reason for this, but I could not change it. And this way it is creating for each event on each node a new 'host' entry on Splunk, which ends up with 100x new non-existing nodes.&lt;/P&gt;
&lt;P&gt;I want to be able to modify the syslog event like&lt;/P&gt;
&lt;P&gt;hostname = name of the node&lt;/P&gt;
&lt;P&gt;ident = message name&lt;/P&gt;
&lt;P&gt;message = message text&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 10:44:15 GMT</pubDate>
    <dc:creator>keremcumhur</dc:creator>
    <dc:date>2025-06-04T10:44:15Z</dc:date>
    <item>
      <title>problem with event logging</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/problem-with-event-logging/m-p/161476#M36882</link>
      <description>&lt;P&gt;Hi all,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in short - how can I change the formatting on the event logs going to a syslog server?&lt;BR /&gt;&lt;BR /&gt;in detail -&amp;nbsp;&lt;BR /&gt;&amp;nbsp;I have configured my cluster to to send event logs to Splunk.&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;mucfs01::&amp;gt; event notification destination show -name fluentd_sierra
 
                Destination Name: fluentd_sierra
             Type of Destination: syslog
                     Destination: fluentd.sierra.local
 Server CA Certificates Present?: -
   Client Certificate Issuing CA: -
Client Certificate Serial Number: -
       Client Certificate Valid?: -
 
mucfs01::&amp;gt; event filter show -filter-name forSplunk
Filter Name Rule     Rule      Message Name           SNMP Trap Type  Severity
            Position Type
----------- -------- --------- ---------------------- --------------- --------
forSplunk
            1        include   *                      *               EMERGENCY, ALERT, ERROR
            2        exclude   *                      *               *
2 entries were displayed.&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Splunk sees the hostname as cluster nodename + event message name&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="keremcumhur_0-1606211984051.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/10441iA64F0986A35163EB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="keremcumhur_0-1606211984051.png" alt="keremcumhur_0-1606211984051.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And if you look at how packages are being sent from NetApp, the syslog package is created this way.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="keremcumhur_1-1606212082490.png" style="width: 400px;"&gt;&lt;img src="https://community.netapp.com/t5/image/serverpage/image-id/10442iE5C3DECB0DC46E20/image-size/medium?v=v2&amp;amp;px=400" role="button" title="keremcumhur_1-1606212082490.png" alt="keremcumhur_1-1606212082490.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't know the reason for this, but I could not change it. And this way it is creating for each event on each node a new 'host' entry on Splunk, which ends up with 100x new non-existing nodes.&lt;/P&gt;
&lt;P&gt;I want to be able to modify the syslog event like&lt;/P&gt;
&lt;P&gt;hostname = name of the node&lt;/P&gt;
&lt;P&gt;ident = message name&lt;/P&gt;
&lt;P&gt;message = message text&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 10:44:15 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/problem-with-event-logging/m-p/161476#M36882</guid>
      <dc:creator>keremcumhur</dc:creator>
      <dc:date>2025-06-04T10:44:15Z</dc:date>
    </item>
    <item>
      <title>Re: problem with event logging</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/problem-with-event-logging/m-p/161488#M36885</link>
      <description>&lt;P&gt;Curious....ONTAP version and Splunk Version?&lt;/P&gt;
&lt;P&gt;Maybe there is a bug on either side?&lt;/P&gt;
&lt;P&gt;Have you updated one or both?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 13:04:46 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/problem-with-event-logging/m-p/161488#M36885</guid>
      <dc:creator>TMACMD</dc:creator>
      <dc:date>2020-11-24T13:04:46Z</dc:date>
    </item>
    <item>
      <title>Re: problem with event logging</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/problem-with-event-logging/m-p/161578#M36908</link>
      <description>&lt;P&gt;we are using&amp;nbsp;NetApp Release 9.6P8.&lt;/P&gt;&lt;P&gt;Splunk Ent. is using version&amp;nbsp;&lt;SPAN&gt;7.2.10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is Splunk is a central service and I don't have permissions to update it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found a tutorial.&amp;nbsp;&lt;A href="http://www.cosonok.com/2017/09/how-to-setup-syslog-from-netapp-in.html" target="_blank" rel="noopener"&gt;http://www.cosonok.com/2017/09/how-to-setup-syslog-from-netapp-in.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you look at the 3rd picture, you will see that his logs are also being formatted with hostname + error type.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a workaround, we have installed a plugin on the fluentd aggregator, which parses the input coming from the cluster and pushes it properly to Splunk.&lt;/P&gt;&lt;P&gt;But I am still curious, why Ontap does not allow me to modify how I want to send my syslog messages.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 11:41:40 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/problem-with-event-logging/m-p/161578#M36908</guid>
      <dc:creator>keremcumhur</dc:creator>
      <dc:date>2020-11-27T11:41:40Z</dc:date>
    </item>
  </channel>
</rss>

