Cisco :: W2K8 R2 - LMS 4.2 Maximum Records In Syslog Report Is 10000
Jul 31, 2012
LMS 4.2.1 W2K8 R2
I seem to be unable to generate a syslog report that contains > 10,000 records. And I don't mean with run type immediate either. I am scheduling them to run at the next 5 minute interval (incidentally, why not have an option that just says "run in background now"?)
I am facing an issue where a bunch of errors are being generated by a voice gateway and I want to determine when the problem started. My syslog contains 7 days of records. If I schedule a report to give me all syslog records for the last 1 week (or 7 days I have tried it both ways) for all devices at that location I get 10,000 records, and they are all for the current date. If I schedule a report and select a date range in the past, I get records within that date range, but only 10,000.
View 2 Replies
ADVERTISEMENT
May 17, 2011
I have an issue with rme 4.2 from LMS 3.1 When I try to generate a syslog report this shows me nothing. I locate SyslogCollector.log file and I see sometnig wrong.
View 4 Replies
View Related
Jul 12, 2012
LMS 4.2, W2K8 R2.I was having an issue with discovery adding devices to with corrupt information (seemingly random strings of characters in several fields). While I was trying to clean this up a scheduled discovery kicked off and further exacerbated the issues I was having. Frustrated, I deleted all entries from the discovery schedule until I could get things cleaned up.
Now I want to go back and troubleshoot the discovery process. Trouble is, I can't get discovery to do anything anymore. I disabled all modules but CDP. I added a single seed IP address under the CDP configuration. This is the address of a 3560V2 switch that is not in DCR. When I started discovery it completed in about 2 seconds and didn't discover anything, including the seed device. So I added another 3560V2 as a seed device under global settings. Same results. Thinking that it had been working using scheduled discovery, I set up a schedule and kicked it off that way. Same results. Finally I added one of these seed devices to DCR and let LMS fully learn about it. Ran another discovery. Still no joy.
I started an SNMP debug on the seed devices before starting discovery. I see the SNMP get coming from LMS, the switches respond and the discovery completes with 0 devices discovered.CS Discovery.log contains no meaningful information. Only messages about "No appenders could be found for logger".
View 1 Replies
View Related
Jul 17, 2012
Where did I need to go on the Concentrator to disable tcp 1723 and 10000? We don't require these to be open and our pen test shows these as being open.
View 1 Replies
View Related
Jul 7, 2012
Add the ability to send syslog events to multiple syslog servers in the SA500 Series routers. I know the functionality is currently in the RV220W because we utilized it. It would be great if you could configure the syslog servers by event type as well. For example, being able to send the kernel events to syslog server A, and all other events to syslog server B.
View 0 Replies
View Related
Jan 15, 2012
Recently i have upgraded the IOS of ASA5550 (in HA mode) to 8.4.2 from 8.0.5, after OS upgrade we found that the syslog from thses firewalls are not getting captured/transfered to centralised syslog server. The server is reachable from the firewalls.
View 3 Replies
View Related
Feb 3, 2011
I was wondering if the following scenario would work:
2 Microsoft TMG servers (could be any W2K8 R2 based server, e.g. UAG, Exchange etc.) configured for Unicast NLB. The servers are connected to separate L2 switches which are connected to a highly available central L3 switch (see attached drawing).
Unicast NLB works in such a way that it uses a shared virtual IP and a virtual MAC addres which is not used as Source MAC address when the TMG servers are respondign to requests.Basically it relies onto the fact that the switch does not learn the virtual MAC address and floods all packets destined to the virtual MAC on all ports. The L3 switch would learn the MAC through ARP. The question now is, what the L3 switch would do, if it receives a packet destined for the NLB VIP. It should do an ARP request in order to receive the virtual MAC. How would he decide on which port(s) to forward the packet as he does not know on which port the MAC is found. Can he make a decision based on Layer 3 (IP/VLAN based) therefore he knows that the VLAN for the TMGs is connected on those two uplink ports?
View 7 Replies
View Related
Apr 6, 2011
I have win 2008 server as DC, i have installed acs 4.2 on menber server (win 2003) , but it doesn't work, how to let this one work.
View 6 Replies
View Related
Jul 29, 2012
So I am trying to get traffic from 192.168.1.33 on UDP ports 10000-20000 and port 5222 (udp) to have DSCP set to EF and Forwarded accordingly.
Building configuration...
Current configuration : 32481 bytes!! Last configuration change at 22:52:11 UTC Mon Jul 30 2012!version 12.2no mls acl tcam share-globalmls netflow interfacemls qosmls cef error action freezevty-async!!spanning-tree mode pvstdiagnostic bootup level completeaccess-list 99 permit 192.168.1.51access-list 99 permit 192.168.1.9access-list 99 permit 192.168.1.8access-list 99 permit 192.168.1.12access-list 111 permit udp any any range 10000 20000access-list 111 permit udp any any range 1 9999access-list 111 permit tcp any anyaccess-list 111 permit udp any any range 20001 49151access-list 111 permit udp any any range 50000 65535access-list 150 permit udp any any eq 5060!redundancymain-cpu auto-sync running-configmode sso!ip access-list extended Modesto_Officeremark Wireless Linkpermit tcp any any establishedpermit icmp any anypermit udp host 65.214.162.12 host 99.24.26.84 eq tftppermit ip host 65.214.162.24 host
[code]....
View 1 Replies
View Related
Aug 30, 2012
I've several production Catalyst switches that are listening on the same IPv4 and IPv6 ports. The problem is I don't want the switches listening on the IPv6 ports.[code] How to shut down these listening ports?I also have a few production switches listening on UDP/10000 and I cannot determine why this port is listening. [code] I've seen where UDP/10000 is Network Data Management Protocol and is related to Storage networks ###, but I've also seen where UDP/10000 is the default port for IPSEC data.I don't believe UDP/10000 is related to either NDMP or IPSEC data, though I could be very wrong.
View 4 Replies
View Related
May 26, 2013
Following best practices on cisco documentations we did set aaa acounting update periodic 5 with 250 switches in the deployment every single switch is geneating and sending 9.990 acct records this is too much the new testing parameterswe are using is aaa acounting update newinfo periodic 15 and this lowered accts by 2/3 (3500) moreover from switch monitoring the most accts records sent by it are related to the trunk-port any suggestion to mitigate this informations storm rather than raising the 15 min period to higher values?are this records generating from the trunk port normal?
View 1 Replies
View Related
May 22, 2012
Can anyone recomend a CDR application which will allow user-friendly presentation of the CDR records and to be saved historically. I see there are a good number out there but not having used any I am hoping someone has some first hand experience with them. I'm going to see about giving this a go url... for my CUCME system to see how it is. Basic call tracking is all that is really needed. Email reports and costing is an added bonus.
View 1 Replies
View Related
Nov 29, 2011
I want to export the ACS local user's records.Then import to other ACS5.3 server.But the export file not the user's password record.I cannot import it well....
View 1 Replies
View Related
May 26, 2011
I do not see any start records in Radius Accounting reports but do see only Stop records ?
btw I am running ACS 5.2
View 2 Replies
View Related
Jun 19, 2011
I have a VPN connection to my office network. The VPN connection appears to work fine as it connects and logs me in successfully. In the connection box I have to provide a domain and my username to log in. Once the VPN is connected I am then able to ping my office computer as if I was on the same network. That is great. The problem is that there is a server on that network that defines a bunch of A records for web applications we are working on and I can't seem to hit any of those from my home computer, even though I can at work. If I remote into the office PC and navigate to these addresses they work fine. I also know that my co-worker can hit these a records from home so it has to be something I'm doing wrong.
[Code]....
View 2 Replies
View Related
Feb 13, 2012
I'm new to CiscoWorks and I inherited the system in my new job. We are running LMS 3.2 and I want to run a report to see what versions of IOS that are running on the network.
View 3 Replies
View Related
Apr 4, 2012
Unable to run Eos/EoL report, I get error that my cisco.com credential are not valid, I verified my credential and they work fine. I'm running RME4.3.2 on Solaris 10.
View 3 Replies
View Related
Mar 3, 2013
I have cisco acs 5.3 appliance. Issue is, when i view tacacs accounting it only shows 100 pages of records. So first kindly tell me if this is the limitation of acs 5.3 to only show 100 pages. Secondly if i want to export the report of last 30 days, its also not showing the last 30 days.
How to get the report of last 30 days
View 1 Replies
View Related
May 6, 2012
Is it possible to run an uptime report using CWLMS 3.2 ?
View 2 Replies
View Related
Aug 17, 2011
I am using LMS version 3.2 and i am not able to generate EOS/EOL report with error no connection to Cisco.Saw an update i LMS portal as this:
Now Available! LMS 3.2:Patch for un-interrupted service of Cisco.com download for Device/Software/PSIRT/EOX updates (To be applied on or before 15-June-2011)
so upgraded the patch cwcs33x-win-CSCto46927-0.zip and restarted the demeon as read in the read me file for the patch.Now the job execution status is always shows running, its neither fail nor pass.
View 6 Replies
View Related
Sep 29, 2009
My customer recently deployed WLCs and WCS in their environment. However, recently they experienced slow performance. To futher finding out the root cause, I generated the 802.11 counters report from the WCS and noticed the following parameters is shown. Tx/Rx Fragment Count/Sec and FCS Error Count/Sec
1. Can I make the assumptions that the overall transfer of packet rate in that interval is the Total of Tx/Rx Fragment Count/Sec and FCS Error Count/Sec?
2. If the output rate of Tx/Rx Fragment Count/Sec and FCS Error Count/Sec are the same, does it mean that 50% of the packet are corrupted and this high FCA Error Count/Sec will cause performance degradation to the wireless througphput?
3. What is the baseline of the FCS Error Count/Sec that is acceptable? As for the case with wired, 1% error rate is acceptable. Will wireless have the same baseline?
View 2 Replies
View Related
Nov 6, 2011
when running Credential Verification Report, I get following notification: "None of the devices have credential verification data".I have made different Default Device Credential sets that I'm using when I add devices to LMS. I could not see wether this is bug in LMS 4.1 or if I have to do this a different way?
View 1 Replies
View Related
Jun 22, 2011
I'm polling a few thousand locations using IP SLA, I have responder enabled on all destinations, and I'm using 60 byte voice packets with a QoS policy.When I run an IP SLA Summary availability report, I have a bunch of locations showing 9% availability 8.5% etc. When I go to the actual collector, and pull up a graph of the same time period, that graph shows 100% availability.
Same collector, same data, just different views giving completely different results. I have to assume that the IP SLA summary report is wrong, these sites were not down 90% of the time.
Just a random though to go with that, I do have the IP SLA to only pull information during the locations operational hours, and I did pull the report from midnight to 11am, the statistics should have been gathered for 4 hours of the 11, which is still higher than 9%, and I would expect all of my locations to report like that, not just a few hundred.
All of the devices are similar in hardware and IOS, and I have verified on a handful that IP SLA responder is enabled, and I see the connections, I have also verified the source configuration via command line.
View 5 Replies
View Related
Sep 26, 2011
I am running CiscoWorks LMS 4.0.1 since 6 months and I wanted to generate today a report about the interface utilization on 2 Cisco switches (Catalyst 3750G). The corresponding job is created, it runs and then i get "succeeded with info" in the "Run Status" column. When I want to click then on the "View Report" link, I get the following error: "Could not generate the report. Either data is not available for the specified duration or the report job failed."
I tried the same procedure with 2 other switches but I have got the same result.
View 1 Replies
View Related
Aug 22, 2011
We have a new 4507R-E Switch which RME keeps reporting as "CONFIG_CHANGE" each evening. When you click to see the change, the only thing that has changes is the "ntp clock-period".
However, we have configured "ntp clock-period" as an exclude command in RME Config Managment.
View 1 Replies
View Related
Jun 27, 2011
I need to understand why change audit report reports an unused username Name of the user who performed the change. This is the name entered when the user logged in. It can be the name under which the LMS application is running, or the name using which the change was performed on the device. #The User Name field may not always reflect the user name. The User Name is reflected only when: A config change was performed using LMS. #A config change was performed outside of LMS, but the network has username-based AAA security model, wherein authentication is performed by an AAA server, which could be TACACS/RADIUS or local.
View 2 Replies
View Related
Nov 9, 2010
Just looked at report after having upgraded to WCS 7.0. It is reporting that SSH is disabled. It is enabled on the controller. The timeout value was set to zero for telnet access. No indication was given that the telnet timeout value also affected SSH as well. I set the timeout value to a non-zero number and reran the task that generated the report. The Enable SSH line item on the report no longer shows up.
View 2 Replies
View Related
Sep 6, 2011
I have just started to discover the power of EEM and am already monitoring config changes on our switches with EEM.I would like to be notified of any interface going up and possibly down. on our 6509's and 3750's This is just to be aware of anyone patching anything in.
View 1 Replies
View Related
Dec 12, 2011
I am unable to generate bug summary report in RME. Even I can not generate PSIRT report as well..LMS always gives error "incorrect cisco.com credential. enter correct credential" I have checked my credentials are correct... it gives me error no BTKT:0014..I am using LMS 3.1 attaaching snap shot of my patch level and application version running on LMS...
View 3 Replies
View Related
Jul 3, 2011
When i am in report generator to create a unused up report i have any of my devices in the devices selector menu. This a same for all reports of the switchport menu. But for the other menu like inventory performance my devices appeard. I make a reboot of my server but no change. I'm looking the logs.
View 4 Replies
View Related
May 14, 2013
I am setting up reports for tacacs accounting on ACS 5.3. However, accounting only seems to work after entering enable mode on the switch. I would like to see all commands, even the enable command when in privlage 1 mode.
View 2 Replies
View Related
Dec 5, 2012
How to generate a Report for all ur existence Subnet's using LMS 4.2?
View 2 Replies
View Related
Jan 3, 2012
I have a problem when doing this report. If I do a device credentials report on a user defined group (40 devices) 11 of these devices fails to connect via SSH. I can make an SSH connection to all 11 devices from the CiscoWorks server, but 11 devices still fails on the report
Device Name Read Community Read Write Community SSH
1. 149.212.XXX.164 Ok Ok Failed to connect.
2. 149.212.XXX.153 Ok Ok Failed to connect.
3. 149.212.XXX.152 Ok Ok Failed to connect.
4. 149.212.XXX.151 Ok Ok Failed to connect.
5. 149.212.XXX.150 Ok Ok Failed to connect.
[code]....
View 2 Replies
View Related