I am facing an issue with logTarget ( rather weird one, I should say).
Firmware - 22.214.171.124
1. I have custom event(log) category 'mqDuration'
2. I have 3 Log targets subscribing to above category with priority as NOTICE.
3. XSLT generates mqDuration event with NOTICE priority.
So far so good.
4. 3 Log Targets for this event are
a. syslog - TargetType = Syslog
b. file( local file) - targetType=File
c. SNMP - targetType=SNMP
5. Out of these 3, FILE and SNMP log targets BOTH are receiving events and are logging it.
6. BUT 'syslog' log Targe is NOT receiving any event.
Other settings for sysLog target
FeedBack detection - OFF
Identical Event Detection- ON and suppression period=60
syslog Facility - USER.
The frequency of 'mqDuration' log category is very HIGH, almost every second.
I understand that identical events will be suppressed till 60 seconds, but there SHOULD be atleast ONE entry every minute.
But on the syslog - I DO NOT see any entry for said log category.
1. As syslog is UDP - it MAY be dropping few events (delivery is not guaranteed ) but FEW; how come nothing is getting logged?
2. remote Syslog server is filtering events at its side. As the event category in the question is of priority 'NOTICE', could it be the case that syslog filters these events???
Also, what does syslog Facity (set at 'user') mean - does it has anything to do with dropping events.
NOTE - we DO NOT have any event filters/object filters or IP address filters setup.
HermannSW 2700006U544647 Posts
Re: Issue with LogTarget - Syslog2013-01-31T22:18:57ZThis is the accepted answer. This is the accepted answer.
- SystemAdmin 110000D4XK
If the problem still exists on supported firmare, please create a PMR.
It seems nobody can help just based on what you did state.
Level2 support will collect your config and other data needed to decided whether it is a configuration issue or a bug.