Cisco Prime Infrastructure 1.3 Syslog

Dear all,
I found some strange on Cisco PI 1.3: 
Many syslog messages (about interface change status) were sent to PI, however not all message displayed in Event List.
E.g:    All Syslog Messages from C6504 are not displayed.
          From Switch 3750, some are displayed, some not.
Even I used Tcpdump on PI and saw that all syslog packets are received on PI's Interface.
Could anyone help me???
Regards

Hello Cuong,
may be this threat can help you and answer your question.
https://supportforums.cisco.com/thread/2232711
Regards
Bastian

Similar Messages

  • Configure the syslog of ASA 5512-X for display on Cisco Prime Infrastructure 2.1

    Hi, I'm working on implementing the Cisco Prime Infrastructure 2.1 and want to display the syslog about ASA5512-X with Software Version 9.2.
    What would be the procedure for configuring?
    Thanks in advance.

    Hi,
    Enable "logging host x.x.x.x "  command to enable logging
    check the below link:
    http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/general/asa_91_general_config/monitor_syslog.html#68764
    FYI: Prime Infrastructure support only SEV 0,1,2 syslogs as of now.
    Operate > alarm and events > syslogs
    Thanks-
    Afroz
    ****Ratings Encourages Contributors *****

  • Is cisco prime infrastructure support / can be run as syslog server?

    Dear All,
    is cisco prime infrastructure support / can be run as syslog server?
    and,
    where i can see network topology diagram, using cisco prime infrastructure?
    many thanks,
    Jerri

    Hello. Cisco Prime LMS will be replaced by Cisco Prime Infrastructure in the near future.
    In the current release of Cisco Prime Infrastructure you can't use topology diagrams. This feature is in roadmap.
    About syslog, you can send syslogs to Cisco Prime Infrastructure, but I don't recommend using it as syslog server. Please see this link for more information https://supportforums.cisco.com/thread/2179520
    Please rate if this helps

  • Download devices syslogs of Cisco Prime Infrastructure 2.2

    Hello,
    I'm working with Cisco Prime Infrastructure 2.2, wish I could download to my PC syslog captured by PI.

    Hi ,
    In the prime infrastructure Syslogs are directly read from udp port 514 and then filtered , the non SEV1 and SEV2 syslogs will be dropped and will not be entered into db . The syslog messages will not be saved into log files .
    Thanks-
    Afroz
    ***Ratings Encourages Contributors ****

  • Prime Infrastructure 1.2 Syslog

    Hi,
    We are currently working on a solution comprising Cisco Prime Infrastructure 1.2 and we can't understand if Prime Infrastructure can work as a syslog collector, since we can't get it to show us any syslog messages sent from the network devices in its the Alarms & Events section. Is this a normal behavior? Is it necessary to use a remote syslog collector on another machine?
    Best regards!

    You can edit the file in vi if you're handy with that text editor. I find it much easier to just create a new file like aijaz described above (copied below here) using your favorite local text editor (I use notepad++ in Windows) and name it syslog_sev_filter.xml.
    Once you have that, copy it onto the PI server using ftp. You can then drop into the shell rename the current file syslog_sev_filter.xml.old and then copy the new syslog_sev_filter.xml file from your ftp repository to the /opt/CSCOlumos/conf/ directory.
    Follow all that with popping back up out of the shell and do "ncs stop" followed with "ncs start" to restart the server and you should now be getting all severity syslog messages in your application.
    /opt/CSCOlumos/conf/syslog_sev_filter.xml file (Bold lines have been added here):

  • Cisco Prime Infrastructure 2.0 - no traps/info are pushed from devices

    Good evening,
    I have setup Cisco Prime Infrastructure 2.0 and,  though I have added manually my 4 network cores as devices without any  problem, I can't get a single trap or a single SNMP information to be  pushed into my Cisco Prime Infra.
    Here is my SNMP config on my core :
    snmp-server user *edited* *edited* v3
    snmp-server  group *edited* v3 noauth notify  *tv.FFFFFFFF.FFFFFFFF.FFFFFFFF.FFFFFFFF.FFFFFFFF.FFFFFFFF.FFFFFFFF.FFFFFFFF.FFFFFFFF.FFFFFFFF.FFFFFFFF.FFFFFFFF.FFFFFFFF.FFFFFFFF.FFFFFFFF0F
    snmp-server community *edited* RO
    snmp-server enable traps snmp authentication linkdown linkup coldstart warmstart
    snmp-server enable traps flowmon
    snmp-server enable traps transceiver all
    snmp-server enable traps call-home message-send-fail server-fail
    snmp-server enable traps tty
    snmp-server enable traps rf
    snmp-server enable traps memory
    snmp-server enable traps cpu_threshold
    snmp-server enable traps eigrp
    snmp-server enable traps ospf state-change
    snmp-server enable traps ospf errors
    snmp-server enable traps ospf retransmit
    snmp-server enable traps ospf lsa
    snmp-server enable traps ospf cisco-specific state-change nssa-trans-change
    snmp-server enable traps ospf cisco-specific state-change shamlink interface
    snmp-server enable traps ospf cisco-specific state-change shamlink neighbor
    snmp-server enable traps ospf cisco-specific errors
    snmp-server enable traps ospf cisco-specific retransmit
    snmp-server enable traps ospf cisco-specific lsa
    snmp-server enable traps flex-links status
    snmp-server enable traps fru-ctrl
    snmp-server enable traps entity
    snmp-server enable traps ethernet cfm cc mep-up mep-down cross-connect loop config
    snmp-server enable traps ethernet cfm crosscheck mep-missing mep-unknown service-up
    snmp-server enable traps ether-oam
    snmp-server enable traps aaa_server
    snmp-server enable traps flash insertion removal
    snmp-server enable traps l2tc threshold sys-threshold
    snmp-server enable traps power-ethernet police
    snmp-server enable traps rep
    snmp-server enable traps vswitch dual-active vsl
    snmp-server enable traps udld link-fail-rpt status-change
    snmp-server enable traps vtp
    snmp-server enable traps vlancreate
    snmp-server enable traps vlandelete
    snmp-server enable traps auth-framework sec-violation
    snmp-server enable traps dot1x auth-fail-vlan guest-vlan no-auth-fail-vlan no-guest-vlan
    snmp-server enable traps envmon fan shutdown supply temperature status
    snmp-server enable traps entity-diag boot-up-fail hm-test-recover hm-thresh-reached scheduled-test-fail
    snmp-server enable traps port-security
    snmp-server enable traps ethernet evc status create delete
    snmp-server enable traps energywise
    snmp-server enable traps ipsla
    snmp-server enable traps vstack
    snmp-server enable traps bfd
    snmp-server enable traps bgp
    snmp-server enable traps bulkstat collection transfer
    snmp-server enable traps cef resource-failure peer-state-change peer-fib-state-change inconsistency
    snmp-server enable traps config-copy
    snmp-server enable traps config
    snmp-server enable traps config-ctid
    snmp-server enable traps event-manager
    snmp-server enable traps hsrp
    snmp-server enable traps ipmulticast
    snmp-server enable traps isis
    snmp-server enable traps msdp
    snmp-server enable traps pim neighbor-change rp-mapping-change invalid-pim-message
    snmp-server enable traps bridge newroot topologychange
    snmp-server enable traps stpx inconsistency root-inconsistency loop-inconsistency
    snmp-server enable traps syslog
    snmp-server enable traps isakmp policy add
    snmp-server enable traps isakmp policy delete
    snmp-server enable traps isakmp tunnel start
    snmp-server enable traps isakmp tunnel stop
    snmp-server enable traps ipsec cryptomap add
    snmp-server enable traps ipsec cryptomap delete
    snmp-server enable traps ipsec cryptomap attach
    snmp-server enable traps ipsec cryptomap detach
    snmp-server enable traps ipsec tunnel start
    snmp-server enable traps ipsec tunnel stop
    snmp-server enable traps ipsec too-many-sas
    snmp-server enable traps errdisable
    snmp-server enable traps ethernet cfm alarm
    snmp-server enable traps vlan-membership
    snmp-server enable traps mac-notification change move threshold
    snmp-server enable traps vrfmib vrf-up vrf-down vnet-trunk-up vnet-trunk-down
    snmp-server host *ip-address-edited* version 3 noauth *edited*
    Basically all traps are enabled but absolutely nothing is showing up in my Prime Infra except that my 4 devices are "Reachable".
    Here is a show snmp on the same device :
    sh snmp
    Chassis: *S/N Edited*
    38554534 SNMP packets input
        0 Bad SNMP version errors
        14 Unknown community name
        0 Illegal operation for community name supplied
        0 Encoding errors
        38453185 Number of requested variables
        0 Number of altered variables
        17790703 Get-request PDUs
        20583581 Get-next PDUs
        0 Set-request PDUs
        0 Input queue packet drops (Maximum queue size 1000)
    38490708 SNMP packets output
        0 Too big errors (Maximum packet size 1500)
        0 No such name errors
        0 Bad values errors
        0 General errors
        38371069 Response PDUs
        13 Trap PDUs
    SNMP global trap: enabled
    SNMP agent enabled
    SNMP logging: enabled
        Logging to *edited*, 0/10, 13 sent, 0 dropped.
    Can anyone point out what is wrong or missing in my configuration? I can't seem to single it out myself.
    Thanks
    Jeremy

    Hi Jeremy,
    SNMP traps are shown in the events and alerts section of PI.
    SNMP config looks fine. Can  you run the SNMP debug (debug snmp packets ) .check the logs and see if the device is actually sending the TRAPS to the PI server.
    Thanks-
    Afroz
    [Do rate the useful post]
    ****Ratings Encourages Contributors ****

  • UPS monitoring support with Cisco Prime Infrastructure 1.2

    Dear Members,
    Good day,
    I am having a project implemented wherein i have the UPS power redudancy solution for our network devices.
    Now can anyone gide that is it possible for below :-
    UPS units installed with SNMP cards be monitored via Cisco Prime Infrastructure 1.2 as our monitoring & management solution is Cisco Prime Infrastructure 1.2 ?
    if yes
    Can you guide if following action would be possible to export the below logs from UPS unit to our Cisco Prime Infrastructure 1.2
       a) UPS fault status information
       b) UPS operational status(input power available Y/N)
       c) Battery fault status
       d) Battery charging current
       e) Battery charge level
       f) Output current
    Conclusion is we need to confirm that would it be posible to achieve remote monitoring of these UPS units via our CPI 1.2
    Thanks in Advance for your support & replies to this query.
    Regards,
    Muzammil N.

    Prime Infrastructure 1.2 can manage non-Cisco devices in a limited fashion via SNMP query and trap processing. It cannot import logs and does not have a generic syslog server,
    So if your devices have snmp read only support and can generate SNMP traps for the above you can add them to PI. Follow the manual add device procedure here.

  • CISCO PRIME INFRASTRUCTURE 1.2 NCS ERROR

    Hi everyone,
    can anyone put through on this, i'm having issue starting the ncs server on cisco prime infrastructure 1.2 .below is the message i get when i do show ncs status:
    NGPHC-CPR001/admin# ncs status
    Health Monitor is running, with an error.
    failed to start NCS on startup Health Monitor
    Reporting Server is running
    Ftp Server is running
    Database server is running
    Tftp Server is running
    Matlab Server is running
    NMS Server is stopped.
    SAM Daemon is not running ...
    DA Daemon is not running ...
    Syslog Daemon is not running ...
    status
    thanks.

    Hi Marvin,
    Its has never worked. This is the first time i am installing it.
    I haved done as you adviced but still getting the same error as stated above.
    Please is there another way out.
    thanks.

  • Cisco Prime Infrastructure 1.4 SNMP Traps are not converted into Alarms

    Hi everybody,
    I just configured SNMP Traps on a Cisco Catalyst 3750-x to send to our Cisco Prime Infrastructure 1.4 Appliance.
    Now I forced the Switch to send some traps (Power off a Power Supply, Interface errdisable). The only events I see in Alarms & Events on PI is the same information message everytime:
    Configuration management event has been recorded in ccmHistoryEventTable.
    I think the forced traps should be converted into alarms? Why can't I see them?
    Thanks,
    Marc

    Ok, I started debugging as you said. I get the following output:
    Mar 13 09:28:13.711: SNMP: V2 Trap, reqid 11689, errstat 0, erridx 0
     sysUpTime.0 = 198609846
     snmpTrapOID.0 = ciscoSyslogMIB.2.0.1
     clogHistoryEntry.2.1688 = PM
     clogHistoryEntry.3.1688 = 5
     clogHistoryEntry.4.1688 = ERR_RECOVER
     clogHistoryEntry.5.1688 = Attempting to recover from bpduguard err-disable state on Gi1/0/13
     clogHistoryEntry.6.1688 = 198609844
    Mar 13 09:28:13.737: SNMP: Queuing packet to xx.xx.xx.xx
    Looks like the Switch is sending SNMP Traps from the ciscoSyslogMIB. Is this why PI can't show the Traps and convert it into a alarm?
    After this test I configured logging (syslog) to the PI. Now the errors are showed but still not converted into alarms. I just want to be notified by email when such errors occurs.
    Thanks,
    Marc

  • Upgrade NCS 1.1.1.24 to Cisco Prime Infrastructure 1.2

    Having a problem installing the ncs_patch-1.1.1.24-upgrade-pi_1.2.tar.gz patch file on a virtual NCS before upgrading it to Cisco Prime Infrastructure 1.2.
    I've followed the Cisco Prime Infrastructure 1.2 Quick Start Guide and did not had the same success as described in the document (see below):
    gmsncs/admin# dir disk:defaultRepo/
    Directory of disk:defaultRepo/
      508376482 Sep 13 2012 05:38:25  backup-20120913-0530.tar.gpg
      853768584 Sep 20 2012 05:40:17  backup-20120920-0530.tar.gpg
         127019 Sep 26 2012 16:40:58  ncs_patch-1.1.1.24-upgrade-pi_1.2.tar.gz
               Usage for disk: filesystem
                     1544204288 bytes total used
                    27185573888 bytes free
                    30293413888 bytes available
    gmsncs/admin# patch install disk:defaultRepo/ncs_patch-1.1.1.24-upgrade-pi_1.2.tar.gz defaultRepo
    Save the current ADE-OS running configuration? (yes/no) [yes] ? yes
    Generating configuration...
    Saved the ADE-OS running configuration to startup successfully
    Initiating Application Patch installation...
    % Local file not found
    Anybody experience with this procedure.
    Thank You
    --- Update ---
    Skipped Step 4 and followed Step 5 in the Quick Start Quide, however now I receive a diffrent error:
    gmsncs/admin# dir disk:/defaultRepo
    Directory of disk:/defaultRepo
      926193986 Sep 26 2012 17:48:12  GRDbackup-120926-1736.tar.gpg
      508376482 Sep 13 2012 05:38:25  backup-20120913-0530.tar.gpg
      853768584 Sep 20 2012 05:40:17  backup-20120920-0530.tar.gpg
         127019 Sep 26 2012 16:40:58  ncs_patch-1.1.1.24-upgrade-pi_1.2.tar.gz
               Usage for disk: filesystem
                     2471309312 bytes total used
                    26258468864 bytes free
                    30293413888 bytes available
    gmncs/admin# patch install GRDbackup-120926-1736.tar.gpg defaultRepo
    Save the current ADE-OS running configuration? (yes/no) [yes] ? yes
    Generating configuration...
    Saved the ADE-OS running configuration to startup successfully
    Initiating Application Patch installation...
    % Manifest file not found in the bundle
    gmsncs/admin#

    Hi, Thank you again for your help, but I am still stuck. I have gathered the outputs from ncs start and a ncs status afterwards. Currently I am not able to access the web-UI of NCS..
    deberncs01/admin# ncs startStarting Network Control System...This may take a few minutes...Dependency Check Failed: Matlab is not running.Dependency Check Failed: Ftp is not running.Dependency Check Failed: Tftp is not running.Failure during Network Control System startup.  Check launchout.log for details.startdeberncs01/admin#deberncs01/admin#deberncs01/admin#deberncs01/admin#deberncs01/admin#deberncs01/admin# ncs statHealth Monitor is running, with an error.failed to start NCS on startup Health MonitorReporting Server is StartingFtp Server is FailureDatabase server is stoppedTftp Server is runningMatlab Server is runningNMS Server is stopped.SAM Daemon is not running ...DA Daemon is not running ...Syslog Daemon is not running ...statusdeberncs01/admin#
    Anyone got a clue on that? and where can I find that launchout.log on NCS? Thank you

  • Consultations on Cisco Prime Infrastructure 2.2

    I recently installed Cisco Prime Infrastructure 2.2 and I have 2 questions regarding configuration:
    1. What configurations should run for vulnerability when some event occurs on a switch an alarm is lifted in the Cisco Prime Infrastructure 2.2?
    2. Is there any way to put a device into maintenance mode in the web interface of Cisco Prime Infrastructure 2.2, so that can not be spoiled reports regarding equipment availability during the execution of maintenance?

    1. If you configure PI as an SNMP and syslog server for your devices and have enabled logging traps etc., PI's alarm browser will show the alarms. If you want them to be sent to you via email, you can do that under the Admin menu for setting up your Mail server and clicking the link to "Configure email notification for individual alarm categories." (see below - open in new tab to zoom). It's not completely customizable but what you see there is the current product capabilities in that regard.
    2. No, this is not currently an available feature in PI 2.2.

  • Cisco Prime Infrastructure 2.1 Inventory Job

    My cisco prime infrastructure performs a switch inventory job every night at 22:00 hrs.  When I looked at the syslog of the devices in the inventory, I see some entries that I never saw with other LMS versions.
    2014-06-30 22:00:01    Local7.Notice    xxx.xxx.xxx.xxx    5410: Jun 30 22:00:00.623 CST: %SYS-5-CONFIG_I: Configured from xxx.xxx.xxx.xxx by snmp
    2014-06-30 22:00:01    Local7.Notice    xxx.xxx.xxx.xxx    5411: Jun 30 22:00:01.567 CST: %SYS-5-CONFIG_I: Configured from console by vty1 (xxx.xxx.xxx.xxx)
    2014-06-30 22:05:10    Local7.Notice    xxx.xxx.xxx.xxx    5412: Jun 30 22:05:09.008 CST: %SYS-5-CONFIG_I: Configured from console by vty0 (xxx.xxx.xxx.xxx)
    I don't understand what the PI is doing with the switches.  Does anyone know what is happening during this inventory background job?  TIA

    Hello all,
    we have the same problem maybe; Cisco Prime IF 2.1 is changing the running-configs and produces out-of-syncs ;
    it turns so for us is, as if Cisco Prime IF 2.1 a snmp-server host x.x.x.x community entry writes in the running-config,
    so are running-and startup-config are out-of-sync; is this correct?  Herbert

  • Cisco Prime Infrastructure Compatibility

    Hi
    I have been informed by our supplier that i cannot add-
    Nexus switches
    Routers
    Into the switches list in Cisco Prime Infrastructure Version 2.0
    However we seem to have one Fabric SVI 'Managed and Sychronized'
    So i dont know whether i should or should not be able to add 7ks
    and 5ks to the switch list
    Anyone any ideas on this -- the official line seems to be no...  if thats true then how did we
    get the one 7l on and managed
    Steve

    You mention a fabric SVI. Note that the FabricPath and other data center-specific technology features are for the most part not managed by PI. Prime DCNM is the tool for that.
    You can use PI to manange 7ks and 5k's as standard switches - backup their configs, poll them with SNMP queries, collect syslog messages etc.

  • Cisco Prime infrastructure template undeploy

    Hi,
    I am new to cisco prime, I have create the new Trap receiver template and deployed to one of the wireless controller and saved the deployment
    Now I want to undeploy the templates, When I tried undeploying the templates for same wireless controller, I got the warning message stating "Failed to undeploy the template"
    Please advice on below points
    1. How to undeploy the templates in cisco prime infrastructure
    2. Where to find the snmp traps ( steps to check the snmp traps) in cisco prime.
    Please Help!!!!!

    Using System Logs
    Prime Infrastructure logs all error, informational, and trace messages generated by all devices that are managed by Prime Infrastructure.
    Prime Infrastructure also logs all SNMP messages and Syslogs it receives.
    You can download and email the logs to use for troubleshooting Prime Infrastructure.
    Step 1 Choose Administration > Logging. The General Logging Options Screen appears.
    Step 2 Choose a Message Level.
    Step 3 Check the check boxes within the Enable Log Module option to enable various administration modules. Check the Log Modules option to select all modules.
    Step 4 In the Log File Settings portion, enter the following settings. These settings will be effective after restarting Prime Infrastructure.
    Note The log file prefix can include the characters "%g" to sequentially number of files.
    Step 5 Click the Download button to download the log file to your local machine.
    Note The logs.zip filename includes a prefix with the host name, date, and time so that you can easily identify the stored log file. Included in the zip file is an html file that documents the log files.
    Step 6 Enter the Email ID or Email IDs separated by commas to send the log file.
    Note To send the log file in a mail you must have Email Server Configured.
    Step 7 Click Submit.

  • Upgradding Prime Infrastructure version 1.2 and LMS 4.x to Cisco Prime Infrastructure 2.0

    Hello,
    A customer currently have 2,500 Cisco Prime Infrastructure Lifecycle device license using Prime Infrastructure version 1.2 and LMS 4.x. the customer wants to upgrade to Cisco Prime Infrastructure 2.0.
    Does anyone know if it is possible to upgrade to version 2.0 without additional cost? the licenses from
    Cisco Prime Infrastructure 1.2 has to be upgraded or we need only to rehost the VUDI.
    Also could be possible to upgrade LMS 4.x to Cisco Prime Infrastructure 2.0?
    thanks!

    The two features you mention are two big missing ones. Another is full syslog capability. I don't believe CiscoView or day one support via package updates is included either.
    Another is less tangible - the depth of experience and documentation available for LMS vs. Prime Infrastructure (particularly the wired management features). I agree for wireless PI 2.0 looks good. Some new features are coming for wired that look promising but they are new as of PI 2.0 so I'm taking a wait and see on them.
    I hope to get 2.0 up in my lab in the next week or so and will hope to be pleasantly surprised but that's seldom the case with a major new release.

Maybe you are looking for

  • Elderly Mother Being Charged For Work That Wasn't ...

    I wonder if someone can point me in the right direction please to get this resolved, I'm at the end of my rope here. A couple of months back my 82 year old mother moved in to a retirement flat.  The flat had a variety of old unnecessary BT kit (trail

  • Can we restrict a Procedure to be called only once in a session or package?

    Hi, I am having a procedure which is called for each insert statement. The code is non-Editable. So, I want to restrict the procedure to be called only once for the entire session or package. Could any one please suggest me, can we do this? Thak you,

  • Photo App does not display all photos

    Running iOS 7.0.4 on an iPhone 4S. The new Photo App does not display all photos properly. All photos show up as thumbnails. However, when you tap on some of them, only a blank page is displayed. The rest is fine. This issue started after the upgrade

  • Reading pdf files while generating them.

    Hi forum, I've got a database process that invokes many times the report servlet (using UTL_HTTP), in order to generate pdf files that will be stored in a directory accessible from database (appears in all_directories table). At the same time, anothe

  • Webi/Report : Schedule : Destination configuration

    In the Report : Schedule : Destination of Webi, is it possible to disable the "Use the Job Server's defaults" check box in ?