ONTAP Discussions

Syslog forwarding - which LIF is the source

kombayn
1,240 Views

Hello

I'm troubleshooting connectivity to syslog server and I can still see:


EMS::SYSLOG_HANDLER: Cannot send an ems message to syslog destination: x.x.x.x Reason: cannot add the destination to the syslog_client. Error: Failed to connect: Operation timed out

Ping to syslog destination is working. Firewall is opened between cluster_mgmt LIF and syslog destination, so it leads me to confirm if really a cluster_mgmt is the source LIF that sends the logs or maybe node management LIFs are sending the logs - can anyone confirm? I've tried to find this information in documentation but I couldn't.

1 REPLY 1

Ontapforrum
917 Views

It uses Node Management interface (for ASUP, time-sync, SNMP, SYSLOG)

Check the ROUTE. Ensure Node_mgmt LIF can reach to Syslog via the configured route.

This KB might help:
https://kb.netapp.com/onprem/ontap/os/Events_not_sent_to_syslog_server_due_to_network_routes

Public