Configure a Syslog Server

You can configure syslog server profiles for device log entry storage. The syslog administrator can then sort messages by facility and see all the ones relating to Extreme Networks devices. The administrator can further sort the messages by IP address and by severity.
Note

Note

Using NTP to synchronize the time stamp on messages from all syslog clients can ensure that all messages reported to the syslog server appear in their proper chronological order. Otherwise, it can be very difficult to interpret a series of events affecting multiple network devices, such as reconnaissance probes and network intrusion exploits. To further ensure synchronicity, all syslog clients should use the same NTP time server. See Configure an NTP Server.
  1. Go to Configure > Network Policies.
  2. Select an existing network policy, and then select Edit, or select Add to create a new policy.
  3. From the Policy Settings menu, select Syslog Server.
  4. Toggle the Syslog Server setting to ON.
  5. Optional: To use existing syslog server settings, choose a syslog server from the menu.
  6. Configure the Syslog Server Settings.
  7. Select the plus sign to add a syslog server.
  8. Select an existing syslog IP Address or host name, or use the add icon to create a new IP Address or host name.
  9. From the drop-down list, choose the minimum severity level of messages that devices will send to the syslog server.
    Devices send syslog messages for the severity level you choose, plus messages for all of the more severe levels above it.
  10. To add another syslog server, select the add icon, and repeat the previous steps.
    Note

    Note

    Use the up or down arrows to reorder the list of syslog servers in the table.
  11. To apply Syslog servers via classification, select an existing classification rule or select the add icon to add a new rule.
    To add a new rule, see Configure a Classification Rule.
  12. Select Save Syslog Server.