<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Syslogging: Cluster log-forwarding vs event destination in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Syslogging-Cluster-log-forwarding-vs-event-destination/m-p/437747#M41103</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/49015"&gt;@DavidDAVE&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So a couple of things to keep in mind.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;"&lt;SPAN&gt;cluster log-forwarding" commands are used for enabling AUDIT LOGS to be sent to a Syslog&amp;nbsp;&lt;/SPAN&gt;destination&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;"event notification" commands is for enabling EMS LOGS to be sent to a Syslog&amp;nbsp;&lt;/SPAN&gt;destination.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Now, you can control to an extent what is included in the AUDIT LOGs (and in turn passed along to the Syslog server). See -&amp;nbsp;&lt;A href="https://docs.netapp.com/us-en/ontap/system-admin/commands-manage-audit-settings-reference.html" target="_blank"&gt;https://docs.netapp.com/us-en/ontap/system-admin/commands-manage-audit-settings-reference.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In terms of the EMS logs, you can absolutely manage what EMS events are passed along to the Syslog server when configuring it using the event notification commands.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Some helpful articles that might point you in the right direction,&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/Overview_of_ONTAP_Logs" target="_blank"&gt;https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/Overview_of_ONTAP_Logs&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/Event_forwarding_to_a_Syslog_server" target="_blank"&gt;https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/Event_forwarding_to_a_Syslog_server&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://www.netapp.com/pdf.html?item=/media/16880-tr-4303pdf.pdf" target="_blank"&gt;https://www.netapp.com/pdf.html?item=/media/16880-tr-4303pdf.pdf&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 29 Aug 2022 07:16:02 GMT</pubDate>
    <dc:creator>RossC</dc:creator>
    <dc:date>2022-08-29T07:16:02Z</dc:date>
    <item>
      <title>Syslogging: Cluster log-forwarding vs event destination</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Syslogging-Cluster-log-forwarding-vs-event-destination/m-p/437685#M41089</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Dear all,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First of all, thank you for your time reading this. We have configured splunk as our syslog server, and configuring everything to forward over there. We are working with a non-standard port for this, so no 514.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Googling this a bit, I founded this new command, “cluster log-forwarding”, which allows you to specify a port, so that’s cool. Our worries here are that this command doesnt seem to filter which events are sent to the syslog server, and we are worried about the level of logging, we don’t want our splunk server to be overwhelmed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is possible to combine cluster log-forwarding with even destination filtering somehow?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.netapp.com/us-en/ontap-cli-93/cluster-log-forwarding-create.html#description" target="_blank" rel="noopener"&gt;https://docs.netapp.com/us-en/ontap-cli-93/cluster-log-forwarding-create.html#description&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.netapp.com/us-en/ontap/error-messages/configure-ems-events-notifications-syslog-task.html" target="_blank" rel="noopener"&gt;https://docs.netapp.com/us-en/ontap/error-messages/configure-ems-events-notifications-syslog-task.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;BR /&gt;&lt;BR /&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 09:57:37 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Syslogging-Cluster-log-forwarding-vs-event-destination/m-p/437685#M41089</guid>
      <dc:creator>DavidDAVE</dc:creator>
      <dc:date>2025-06-04T09:57:37Z</dc:date>
    </item>
    <item>
      <title>Re: Syslogging: Cluster log-forwarding vs event destination</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Syslogging-Cluster-log-forwarding-vs-event-destination/m-p/437747#M41103</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/49015"&gt;@DavidDAVE&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So a couple of things to keep in mind.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;"&lt;SPAN&gt;cluster log-forwarding" commands are used for enabling AUDIT LOGS to be sent to a Syslog&amp;nbsp;&lt;/SPAN&gt;destination&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;"event notification" commands is for enabling EMS LOGS to be sent to a Syslog&amp;nbsp;&lt;/SPAN&gt;destination.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Now, you can control to an extent what is included in the AUDIT LOGs (and in turn passed along to the Syslog server). See -&amp;nbsp;&lt;A href="https://docs.netapp.com/us-en/ontap/system-admin/commands-manage-audit-settings-reference.html" target="_blank"&gt;https://docs.netapp.com/us-en/ontap/system-admin/commands-manage-audit-settings-reference.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In terms of the EMS logs, you can absolutely manage what EMS events are passed along to the Syslog server when configuring it using the event notification commands.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Some helpful articles that might point you in the right direction,&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/Overview_of_ONTAP_Logs" target="_blank"&gt;https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/Overview_of_ONTAP_Logs&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/Event_forwarding_to_a_Syslog_server" target="_blank"&gt;https://kb.netapp.com/Advice_and_Troubleshooting/Data_Storage_Software/ONTAP_OS/Event_forwarding_to_a_Syslog_server&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://www.netapp.com/pdf.html?item=/media/16880-tr-4303pdf.pdf" target="_blank"&gt;https://www.netapp.com/pdf.html?item=/media/16880-tr-4303pdf.pdf&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2022 07:16:02 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Syslogging-Cluster-log-forwarding-vs-event-destination/m-p/437747#M41103</guid>
      <dc:creator>RossC</dc:creator>
      <dc:date>2022-08-29T07:16:02Z</dc:date>
    </item>
    <item>
      <title>Re: Syslogging: Cluster log-forwarding vs event destination</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Syslogging-Cluster-log-forwarding-vs-event-destination/m-p/437789#M41117</link>
      <description>&lt;P&gt;Ey mate, really good answer!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just something to clarify here, is there anyway to choose port for event notification? 514 forbidden here!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2022 19:40:11 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Syslogging-Cluster-log-forwarding-vs-event-destination/m-p/437789#M41117</guid>
      <dc:creator>DavidDAVE</dc:creator>
      <dc:date>2022-08-29T19:40:11Z</dc:date>
    </item>
    <item>
      <title>Re: Syslogging: Cluster log-forwarding vs event destination</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Syslogging-Cluster-log-forwarding-vs-event-destination/m-p/437817#M41122</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/49015"&gt;@DavidDAVE&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the looks of our documentations it looks like we do not support a custom port at this point in time for the "Event notification" commands. You can see a similar conversation unfold over at this thread, where another customer had to use NAT rules to reroute the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.netapp.com/t5/ONTAP-Discussions/Syslog-custom-port/m-p/430889/highlight/true#M39809" target="_blank" rel="noopener"&gt;https://community.netapp.com/t5/ONTAP-Discussions/Syslog-custom-port/m-p/430889/highlight/true#M39809&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alternatively (and I think it's also discussed in the same above thread) we have customers whom deploy ActiveIQ Unified Manager to monitor and manage their ONTAP based NetApp systems, then use SNMP traps to gather certain log events from Unified Manger (instead of each separate ONTAP system).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2022 03:26:49 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Syslogging-Cluster-log-forwarding-vs-event-destination/m-p/437817#M41122</guid>
      <dc:creator>RossC</dc:creator>
      <dc:date>2022-08-30T03:26:49Z</dc:date>
    </item>
    <item>
      <title>Re: Syslogging: Cluster log-forwarding vs event destination</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Syslogging-Cluster-log-forwarding-vs-event-destination/m-p/437823#M41125</link>
      <description>&lt;P&gt;Understood, thanks for your time and your answers Ross &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Aug 2022 10:09:17 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Syslogging-Cluster-log-forwarding-vs-event-destination/m-p/437823#M41125</guid>
      <dc:creator>DavidDAVE</dc:creator>
      <dc:date>2022-08-30T10:09:17Z</dc:date>
    </item>
  </channel>
</rss>

