<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Looking for some help on syslog configuration in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Looking-for-some-help-on-syslog-configuration/m-p/458215#M44608</link>
    <description>&lt;P&gt;Yes, thank you - this is definitely the problem.&amp;nbsp; We had a rouge service-policy in there (for reasons I wish I could tell you) and changing that to the default-management, which is 0.0.0.0/0 on everything, and I immediately start seeing traffic on the tcpdump on the syslog server.&lt;BR /&gt;&lt;BR /&gt;Now, I can't get syslog to actually log the traffic, but that's another problem - packets are now getting there so thank you very much.&lt;/P&gt;</description>
    <pubDate>Mon, 03 Feb 2025 17:50:03 GMT</pubDate>
    <dc:creator>ssbn743</dc:creator>
    <dc:date>2025-02-03T17:50:03Z</dc:date>
    <item>
      <title>Looking for some help on syslog configuration</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Looking-for-some-help-on-syslog-configuration/m-p/458188#M44602</link>
      <description>&lt;P&gt;We have 4 NetApp's, all version 9.16.&amp;nbsp; These are government systems, so we have no way to upload logs or configs, we'll have to do this the hard way.&lt;BR /&gt;3 of the 4 simply will not send syslogs to the internal syslog server.&amp;nbsp; As far as we can tell, the 1 NetApp that is working, is configured exactly the same way as the 3 that are not working.&lt;BR /&gt;&lt;BR /&gt;We have been through several guides and posts on the Google machine and have come up empty on everything tried.&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;- We have a working filter, tested with the 'event filter test' command&lt;BR /&gt;- We have valid syslog destinations in IP address format (though, just to be 100% sure, we also have DNS configured and working)&lt;BR /&gt;- The syslog destinations have the correct filters applied&lt;BR /&gt;- We can generate a test event and see it in the ONTAP event log (we've been using monitor.volume.nearfull)&lt;BR /&gt;- Using the event history show -destination syslog_1 (syslog_1 being our defined dest) we see absolutely nothing&lt;BR /&gt;- This is confirmed with a tcpdump command on the syslog server itself seeing no packets&lt;BR /&gt;- It's as if the syslog service never gets notified that it needs to send a syslog&lt;BR /&gt;&lt;BR /&gt;- We can ping and traceroute the syslog IP address (and even the DNS name) from the ONTAP CLI&lt;BR /&gt;&lt;BR /&gt;At this point, we're down to a suggestion to login to the systemshell and reset notifiyd.&amp;nbsp; We are, however, pretty nervous about doing so, and since 3 of our 4 devices don't work, it seems like this is not the right thing to be mucking with.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Does anyone have anything on this topic.&amp;nbsp; syslog configurations are pretty darn simple, usually, and ONTAP9 doesn't really seem to be any different.&amp;nbsp; Is there some obscure option, somewhere, that needs to be enabled or something?&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jan 2025 17:17:19 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Looking-for-some-help-on-syslog-configuration/m-p/458188#M44602</guid>
      <dc:creator>ssbn743</dc:creator>
      <dc:date>2025-01-31T17:17:19Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for some help on syslog configuration</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Looking-for-some-help-on-syslog-configuration/m-p/458193#M44603</link>
      <description>&lt;P&gt;You can also test the notification destination using the command:&lt;BR /&gt;event notification destination check -destination-name syslog_1&lt;BR /&gt;&lt;BR /&gt;You can also try to create a different destination (i.e email) and use it to test.&lt;/P&gt;&lt;P&gt;If using different destination works,&amp;nbsp; then it will be connectivity issue between the storage and syslog server where you can use netapp tcpdump to debug.&lt;/P&gt;</description>
      <pubDate>Sat, 01 Feb 2025 19:53:30 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Looking-for-some-help-on-syslog-configuration/m-p/458193#M44603</guid>
      <dc:creator>cruxrealm</dc:creator>
      <dc:date>2025-02-01T19:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for some help on syslog configuration</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Looking-for-some-help-on-syslog-configuration/m-p/458196#M44604</link>
      <description>&lt;P&gt;Have you checked the network interface service policies on 3 clusters don't send to syslog server. Please with the working one.&amp;nbsp; If syslog traffic is sent via management interface, then management interface must have right service policy applied and rules (FW) applied.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;network interface show -fields service-policy -vserver &amp;lt;your_cluster&amp;gt;&lt;/P&gt;&lt;P&gt;Then check the returned sevice-policy has syslog-forwarding policy applied&lt;/P&gt;&lt;P&gt;network interface service-policy show -vserver &amp;lt;your_cluster&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sample out put will be like this (includes syslog forwarding)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;your_cluster&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; default-management management-core: 0.0.0.0/0&lt;BR /&gt;management-autosupport: 0.0.0.0/0&lt;BR /&gt;management-ssh: 0.0.0.0/0&lt;BR /&gt;management-https: 0.0.0.0/0&lt;BR /&gt;management-ems: 0.0.0.0/0&lt;BR /&gt;management-ntp-client: 0.0.0.0/0&lt;BR /&gt;management-dns-client: 0.0.0.0/0&lt;BR /&gt;management-ad-client: 0.0.0.0/0&lt;BR /&gt;management-ldap-client: 0.0.0.0/0&lt;BR /&gt;management-nis-client: 0.0.0.0/0&lt;BR /&gt;management-http: 0.0.0.0/0&lt;BR /&gt;backup-ndmp-control: 0.0.0.0/0&lt;BR /&gt;management-snmp-server: 0.0.0.0/0&lt;BR /&gt;management-ntp-server: 0.0.0.0/0&lt;BR /&gt;&lt;STRONG&gt;management-log-forwarding: 0.0.0.0/0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2025 02:41:39 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Looking-for-some-help-on-syslog-configuration/m-p/458196#M44604</guid>
      <dc:creator>Sanaman</dc:creator>
      <dc:date>2025-02-03T02:41:39Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for some help on syslog configuration</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Looking-for-some-help-on-syslog-configuration/m-p/458214#M44607</link>
      <description>&lt;P&gt;The check -destination only works for tcp connections.&amp;nbsp; I didn't specify in my post, but we are trying to use udp, though, I think we could do tcp if it comes to it.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2025 17:46:33 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Looking-for-some-help-on-syslog-configuration/m-p/458214#M44607</guid>
      <dc:creator>ssbn743</dc:creator>
      <dc:date>2025-02-03T17:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for some help on syslog configuration</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Looking-for-some-help-on-syslog-configuration/m-p/458215#M44608</link>
      <description>&lt;P&gt;Yes, thank you - this is definitely the problem.&amp;nbsp; We had a rouge service-policy in there (for reasons I wish I could tell you) and changing that to the default-management, which is 0.0.0.0/0 on everything, and I immediately start seeing traffic on the tcpdump on the syslog server.&lt;BR /&gt;&lt;BR /&gt;Now, I can't get syslog to actually log the traffic, but that's another problem - packets are now getting there so thank you very much.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2025 17:50:03 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Looking-for-some-help-on-syslog-configuration/m-p/458215#M44608</guid>
      <dc:creator>ssbn743</dc:creator>
      <dc:date>2025-02-03T17:50:03Z</dc:date>
    </item>
  </channel>
</rss>

