Show log command on 4500

Dear all,
If I do a show log command on switch it starts showing logs which are several months old.
How can I filter those to show only last month log -like pipe is one way or anything to be set on switch.
Also if I do sh log and if it starts showing logs for last 6 months then i can't break it and hence might b causing overhead.
Please advise.
Sent from Cisco Technical Support iPhone App

Hi,
I believe there is no other options to view the logs options apart from using the pipe filter.
or we can tune the logging level in such a way to capture only the interested message by applying the below options.
There are eight levels of logging. If you specify a particular level of logging for console logging, for example the messages of that level and of the higher levels (numerically lower) are forwarded to the console.
Level
Logging Message
0
Emergencies
1
Alerts
2
Critical
3
Errors
4
Warnings
5
Notifications
6
Informational
7
Debugging
Router(config)# logging monitor error
Now let us discuss the anatomy of the logging messages. Each message is associated with one of the eight levels of logging, which is referred to as the severity of the message
Level Name
Severity
Description
Syslog Definition
Emergencies
0
System unusable
LOG_EMERG
Alerts
1
Immediate action needed
LOG_ALERT
Critical
2
Critical conditions
LOG_CRIT
Errors
3
Error conditions
LOG_ERR
Warnings
4
Warning conditions
LOG_WARNING
Notifications
5
Normal significant conditions
LOG_NOTICE
Informational
6
Informational messages only
LOG_INFO
Debugging
7
Debugging messages
LOG_DEBUG
Hope this helps
Cheers
Somu
Rate helpful posts

Similar Messages

  • Privilege mode disable the show logging command

    any one pls advice how to disable the show logging command through the privilege

    Pls see this link,
    http://www.cisco.com/en/US/tech/tk59/technologies_tech_note09186a00800949d5.shtml
    Regards,
    ~JG
    Do rate helpful posts

  • Aaa authorization and show logging command

    Hello Guys,
    I am running IOS 15 on some routers and using ACS version 5.3.0.40.5 for authentication and authorization.
    I would like to have a group of users not be able to access the configuration mode but issue all show commands.
    However, the show logging command does not seem to work in user mode.
    Any ideas or work arounds are welcome.
    thanks in advance.

    Hello,
    There is no contradiction. You can be a level 15 access and deny or permit access to whatever commands that you want.
    I am using ACS where everyone have level 15 access but some of them can only use show commands (no conf t).
    You can configure things the same way by allowing everyone level 15 access and allow or deny whatever commands you want.
    let me know if you need extra help.
    Regards,
    Amjad
    Rating useful replies is more useful than saying "Thank you"

  • "show logging" not available in privilege 7 anymore

    Hi,
    I am encoutering an issue on some Catalysts 3750/3560/2960 on IOS 12.2(55). Users logged on privilege 7 can't use the "show logging" command anymore. The command vas available on previous IOS like 12.2(50).
    I fixed it with the command "privilege exec level 7 show logging" but I wanted to know if it was intentional or not, as I couldn't find anything about a change on the privilege 7 rights int any of the Cisco's release notes between 12.2(50) and 12.2(55).
    Do anyone know about that ?

    This was implemented as a security feature. Take a look at:
    CSCsl61281
    https://supportforums.cisco.com/discussion/10624981/change-privilege-level-command-show-logging
    Thank you for  rating helpful posts!

  • Change in privilege level for the command show logging

    I have recently discovered a change in behavior in IOS. The command show logging has traditionally been available at user level. Now it has become a privilege level 15 command.
    I thought that this was strange and opened a case with Cisco TAC about it. I was told that this is a new "feature" that was implemented for bugid CSCsl61281. Unfortunately this bugid is viewable by Cisco internally but not viewable by the public.
    The TAC engineer tells me that this change is integrated into these releases:
    This was integrated into the following releases:
    12.4(24.05.01)PIX11
    12.4(21.14.09)PIC01
    12.4(19.03)T
    12.2(52.23)SIN
    12.2(33)SXI01
    12.2(32.08.11)SX229
    12.2(32.08.11)SR174
    I do not think that this is a good change. If you do not think that this is a good change I suggest that you contact your Cisco support team and express your opinion about this change.
    Otherwise as you go to new versions of IOS be aware of the potential impact on your network monitoring processes and procedures that show logging will require level 15 privilege access.
    HTH
    Rick

    Hi Rick,
    Can you suggest me references to know more about privilege level commands?
    How to enable different commands for different levels of privileges?
    Thanks.
    -Sudhish

  • Show run command with date

    Hello Community,
    Is there a command in the IOS that will pick up todays date?
    For example, show loggin | inc <todays_date>
    Cheers
    Carlton

    Well, I have one, but it's not pretty. It's tcl which your router should support. To run it manually on the router, here's what I suggest (although I haven't been able to do much research):
    Copy this to your router or a tftp server.
    Here's the script:
    ---- Copy Below -----
    set date [ exec {show clock} ]
    set day [lindex $date 4]
    set mth [lindex $date 3];
    if { [ string length $day ] == 2 } {
        set result "${mth} ${day}"
    } else {
        set result "${mth}  ${day}"
    show log | inc $result
    ---- End of script -----
    You can then create an alias on the router that you want to use this script on to launch it:
    alias exec todayslogs tclsh tftp:///currentdate.tcl
    OR
    alias exec todayslogs tclsh flash://currentdate.tcl
    ***** My Disclaimer: ******
    I tested this on my router and it works great, although I can't guarantee that it will work correctly on yours. It's a start though....
    HTH,
    John
    *** Please rate all useful posts ***

  • Where is the "show duplicates" command in iTunes 11?

    I can't find the "show dupicates" command in iTunes 11 and I have a number I want to delete.

    https://discussions.apple.com/message/20438897?ac_cid=op123456#20438897

  • OBIEE 10g UI shows logging in message while downloading a report.

    Hi Experts,
    We have a report on OBIEE Dashboard which show URLs (GO URLs) to download the report in .CSV format.
    Most of the times, It works fine... However, sometimes the user clicks on the link, the report starts downloading but the page (on which the link was clicked) keeps showing Logging In message.
    Has anyone faced this issue ever?
    (We are using OBIEE 10.1.3.4.1 on Solaris)
    Regards,
    Vishal

    Vishal,
    It would be great if you can provide us the screen shot?
    Thanks,

  • Question about ACE show Conn command (tcp duration)

    Hello,
    I was checking connections and noticed that I would see the initial connection, but after a short time the connection quits showing up in the counters and the “show conn” command. However the user is still up and working.
    This is the command I used:
    sho conn serverfarm STAGING-HTTPS detail
    The output shows all the connection info from source to destination, and in the ESTABLISHED state.
    However, after maybe 2~3 minutes, when I up arrow I don't see any connection info. The web page is still up. If I refresh the web page, I do see the connections come in.
    Can someone kindly point me to a document or provide an answer on how long should the connection be stored before they are flushed?
    Config profile:
    4 real servers
    HTTPS protocol
    Leastconn for predictor
    sticky based on src/dst IP
    Thanks,
    Raman

    Raman,
    If you would play with a sniffer capture, you could answer the question yourself.
    If the browser loads a flash object or a java applet, once it is loaded, you can still work on the page but there is no data transfer.
    with a sniffer tool you could see the browser closing the connections.
    The default TCP idle timeout on ACE is 1 hour.
    Gilles.

  • IPS Tech Tip - "show tech" command part 2 - IPS dev team webinar

    Hi Folks,
    The IPS product management and development team would like to invite you to this 30-40 minute webinar followed by Q&A sessions. These will be recorded and put on this forum as well. We hope you can attend.
    -Robert
    Robert Albach invites you to attend a Web seminar using WebEx. This event requires registration.
    Topic: Cisco IPS Tech Tips - show tech part 2
    Host: Robert Albach
    This month's Cisco IPS Tech Tip will continue December's show tech command discussion. The show tech command holds a wealth of information regarding your IPS's performance and status. Cisco IPS development team members will continue to talk about what all this information means to you and then answers your questions.
    Date and Time:
    January 27, 2011 10:00 am, Central Standard Time (Chicago, GMT-06:00)
    To register for the online event
    1. Go to https://cisco.webex.com/ciscosales/onstage/g.php?d=202882129&t=a&EA=ralbach%40cisco.com&ET=85576c2dbfd6dca4b756de40b6728a2b&ETR=5d7e40b0e38f564be0a8bd55114369fc&RT=MiM3&p
    2. Click "Register".
    3. On the registration form, enter your information and then click "Submit".
    Once the host approves your registration, you will receive a confirmation email message with instructions on how to join the event.

    Sadly we did not get the recording done. The presentation and the example pcaps  however are on this forum now.
    -Robert

  • Clarification on the SHOW TOP command

    Does anyone know much about the Show Top command? I am trying to get specs on the bandwidth utilization of a port. When
    I do the Top command it tells me a percent of utilization. However it looks to be too low. I verified the util using a traffic generator test set and it has results of almost double the util. that the Top command stated. So my thoughts are that if the port is set for 100/Full then the Top stats for Util show only half Dux. Is this so??? I think that I need to double the Top results for util and that will be the true Util for the port. Can anyone verify this????

    you are kind of correct, that it will look like a half duplex utilization because process actually bundles the TX AND rx into the same counter and it also looks at the full duplex bandwidth when calculating the % utilization. So a GE port is really 2000Mbps full-duplex. so, from the traffic generator you are sending at line rate of 1 Gig, the TOP will see that as 50% utilization. Does that make sense. This is how I understand it.

  • "SHOW ALL" command in RMAN

    Hi
    I need to understand, what does RMAN use to read configuration info in case of No Recovery catalog.
    We all know that it read from Control file about backup information.
    But, when my database is in NOMOUNT mode, I connect to rman target /
    Then I run show all; command.
    It displays RMAN configuration, Where is this information stored?
    Any idea?
    Thanks in advance

    Hi,
    Did you compare the output of the <show all ;> commands in nomount and mount (or open) mode?
    In nomount you get the defaults :
    RMAN configuration parameters are:
    CONFIGURE RETENTION POLICY TO REDUNDANCY 1; # default
    CONFIGURE BACKUP OPTIMIZATION OFF; # default
    CONFIGURE DEFAULT DEVICE TYPE TO DISK; # default
    CONFIGURE CONTROLFILE AUTOBACKUP OFF; # default
    CONFIGURE CONTROLFILE AUTOBACKUP FORMAT FOR DEVICE TYPE DISK TO '%F'; # default
    CONFIGURE DEVICE TYPE DISK PARALLELISM 1 BACKUP TYPE TO BACKUPSET; # default
    CONFIGURE DATAFILE BACKUP COPIES FOR DEVICE TYPE DISK TO 1; # default
    CONFIGURE ARCHIVELOG BACKUP COPIES FOR DEVICE TYPE DISK TO 1; # default
    CONFIGURE MAXSETSIZE TO UNLIMITED; # default
    CONFIGURE ENCRYPTION FOR DATABASE OFF; # default
    CONFIGURE ENCRYPTION ALGORITHM 'AES128'; # default
    CONFIGURE ARCHIVELOG DELETION POLICY TO NONE; # default
    In mount mode you get the actual settings:
    using target database control file instead of recovery catalog
    RMAN configuration parameters are:
    CONFIGURE RETENTION POLICY TO REDUNDANCY 1; # default
    CONFIGURE BACKUP OPTIMIZATION OFF; # default
    CONFIGURE DEFAULT DEVICE TYPE TO DISK; # default
    CONFIGURE CONTROLFILE AUTOBACKUP ON;
    CONFIGURE CONTROLFILE AUTOBACKUP FORMAT FOR DEVICE TYPE DISK TO '%F'; # default
    CONFIGURE DEVICE TYPE DISK PARALLELISM 1 BACKUP TYPE TO BACKUPSET; # default
    CONFIGURE DATAFILE BACKUP COPIES FOR DEVICE TYPE DISK TO 1; # default
    CONFIGURE ARCHIVELOG BACKUP COPIES FOR DEVICE TYPE DISK TO 1; # default
    CONFIGURE CHANNEL DEVICE TYPE DISK FORMAT '/backup/DB10G/%U';
    CONFIGURE MAXSETSIZE TO UNLIMITED; # default
    CONFIGURE ENCRYPTION FOR DATABASE OFF; # default
    CONFIGURE ENCRYPTION ALGORITHM 'AES128'; # default
    CONFIGURE ARCHIVELOG DELETION POLICY TO NONE; # default
    CONFIGURE SNAPSHOT CONTROLFILE NAME TO '/u01/appl/ora102/product/10.2.0/dbs/snapcf_DB10G.f'; # default
    Regards,
    Tycho

  • "Show logging" displays the switch UP time not the Date & time

    Hi,
    i have cisco 2950 switch, when i type the show logging, what ever event has happend i am getting like this "26w6d: %LINK-3-UPDOWN: Interface FastEthernet0/24, changed state to down" but it is not showing the date & time when the event has occured, so every time i need to check the show version & have to see the switch up time & then i need to calculate. is there any configuration has to be done where i should get the information of the date & time in place of switch up time eg. like this...
    "Sep4 4:15: %LINK-3-UPDOWN: Interface FastEthernet0/24, changed state to down"

    what you could do is to enable timestamping if not already done so.
    2950(config)# service timestamp debug datetime msec
    2950(config)# service timestamp log datetime msec
    or you can use SNMP to provide traps of the 'events' that occur on the device.
    these SNMP traps will provide the date, time and trap.
    what version IOS on that device? have you enabled timestamping? have you upgrade lately? perhaps an upgrade could be of assistance. i'll verify the operation on some 2950s i have to confirm if i have the same issue or not and what version is being used. i'll post the result when available.

  • "Show Diag" command on 3750 IOS 12.1(19)EA1c

    Hi,
    I'm trying to run the "show diag" command on a 3750 with IOS 12.1(19)EA1c and the command is not recongised. I'm in enable mode and cannot find an equivalent command.
    I need to do this as the Cisco Software Advisor is asking for a copy of the output.
    Any pointers gladly recived.
    Cheers,
    Gareth

    Hi,
    The tool you need is the "Feature Navigator" which can be found here:
    http://tools.cisco.com/ITDIT/CFN/jsp/index.jsp
    Launch the tool by selecting "Search by Feature"
    Searching for "802.1x" gives a list of all those features, select "Wake on LAN support" (for example) and click add, then continue.
    The platform box gives a list of all platforms that support the feature, so select 3750.
    The lowest feature set is IP Base (you might have something else but worth checking this first as it's the lowest feature set)
    This gives a list of about 20 versions of software which support the feature so you can see you need at least 12.2(25)SEC to get this particular feature.
    The process is pretty much the same for any feature. If you know the actual command you need (in this case it's "dot1x control-direction" then you could get the same info by just looking it up in the latest command reference as that will also tell you when the feature first appeared.
    Finally, if you just want a list of features for a particular release then use the same link and choose search by platform, but be aware this will be a *long* list.
    HTH
    Andrew.

  • Cisco ACE - "show conn" command queries

    Hi all,
    i have some queries regarding the "show conn" command in Cisco ACE.
    Working Scenario:
    VIP : 10.10.10.1
    Server 1 : 10.10.20.1
    Server 2 : 10.10.20.2
    Client: 30.30.30.1
    When a client 30.30.30.1 initiates a connection to the VIP on 10.10.10.1, the ACE load balances it to Server 1, 10.10.20.1. Looking at the "show conn" table, it shows that Server 1 is replying back to the Client 30.30.30.1 through the ACE.
    Now, my question is when the ACE returns the traffic to the Client, should the Client be seeing the source IP coming from the VIP or Server 1? My understanding is that the Client should be seeing traffic returning from the VIP. But the show conn table does not seem to suggest so.
    show conn table
    conn-id    np dir proto vlan source                destination           state
    ----------+--+---+-----+----+---------------------+---------------------+------+
    1768       1  in  TCP   10   30.30.30.1:9221   10.10.10.1:80       ESTAB
    41         1  out TCP   52    10.10.20.1:80    30.30.30.1:9221   CLOSED

    Daniel,
    The client is expecting a response from the VIP otherwise there would be an asymmetrical routing problem and conns will never complete.
    The fact that you're seeing 30.30.30.1 as the destination address is just that the server is able to see client's IP address on the request, when your backend servers sends the reply back to the client this response is forced to go through the ACE, when the ACE looks at the packet it matches with a previously conn created on the flow table so it "NATs"  the reply so now the source of the packet is the VIP and destination is 30.30.30.1.
    This is a expected behavior as you're not using S-NAT on your network.
    HTH.
    Pablo

Maybe you are looking for

  • Report for CRM-Opportunities - Open CRMD_ORDER for selected ALV row

    Hello, i created a report which can be used to find the relevant opportunities and list them in a ALV table. I have the requirement that by doubleclick on the table line the selected opportunity shall open in tx crmd_order. I have the GUID and the ob

  • Preview won't display certain pdf files

    I have Preview 3.0.9 (409) on Mac OS 10.4.11. I have never had any problems opening pdf files with Preview before, but I have come accross a couple recently that wouldn't work. One opened with just a blank white page while another said: File error. C

  • Windows vista installed,can't install Mac OS XLeopard

    I have a macbook and am trying to install a clean version of leopard. this macbook had vista installed on it. I have tried to do a clean install of mac leopard.The message comes up" it cannot be installed on this computer. As far as I know there is n

  • Apps not showing up in notification center

    As the title said, not sure since when, every apps i installed does not show up in notification center

  • Song skipping

    Hi I'm a PC and I would like to DOWNGRADE my nano 2nd gen and 3rd gen to software version 1.0.1 0r 1.0.2 I have had nothing but song skipping since installing 1.0.3 I have had ipod mini,ipod nano 2nd gen and never had a problem. This skipping song pr