Wednesday, May 27, 2020

Cisco MDS Syslog to ELK

I want to forward Syslog messages generated by Cisco MDS switches to ELK. I'm unable to send via the default Syslog port (514) since ELK already listens for messages on that port for other devices. No problem, I can alter the default port via:

logging server <IP> 6 port 6599 facility syslog

However, this command only seem to work on newer MDS 9700 hardware. On older MDS 9500, it looks there is no option to specify a port and thus using the default one. MDS 9500 runs on 6.2.23 image. Could this be solved by updating the firmware? I noticed the newest version is 6.2.31.

I went through the release notes of each version but didn't saw anything mentioned regarding adding a port option. PS: this is al running production so unable to test.



No comments:

Post a Comment