rss logo

How to Set Up an Rsyslog Server on Debian for Cisco Switch Logs

Rsyslog Logo

Introduction

I recently needed to set up a Rsyslog server to centralize logs from several Cisco switches.

In this guide, I will show you how to configure Rsyslog on Debian to receive and store Syslog messages sent by Cisco network switches.

Network diagram

All Cisco switches will send their Syslog messages to the Debian server.

In this setup, the switches send their logs to the Rsyslog server over UDP using the standard Syslog port 514.

Network diagram showing a Debian Rsyslog server collecting Syslog messages from three Cisco switches over UDP port 514.
Debian Rsyslog server centralizing Syslog messages from multiple Cisco switches over UDP port 514.

Configuring Cisco switches

  • Configure the network settings of the Cisco switch:

💡 Note: I also configure the default gateway and DNS settings so that the switch can reach external services such as an NTP server. You can refer to this guide to learn how to configure NTP. Accurate time synchronization is important to ensure that Syslog messages are correctly timestamped.

Switch# conf t
Switch(config)# ip name-server 86.54.11.100
Switch(config)# ip domain lookup
Switch(config)# interface vlan1
Switch(config-if)# ip address 10.0.0.1 255.255.255.0
Switch(config-if)# no ip address dhcp
Switch(config-if)# ip default-gateway 10.0.0.254
  • Configure the remote Rsyslog server as the Syslog destination:
Switch(config)# logging host 10.0.0.200 port 514

Debian server

First, install a Debian server that will act as the central Rsyslog server. We can then install and configure Rsyslog to receive logs from the Cisco switches.

Installing and configuring Rsyslog

  • Install the rsyslog package:
root@host:~# apt update && apt install rsyslog
  • Edit the /etc/rsyslog.conf file:
# /etc/rsyslog.conf configuration file for rsyslog
#
# For more information install rsyslog-doc and see
# /usr/share/doc/rsyslog-doc/html/configuration/index.html


#################
#### MODULES ####
#################

module(load="imuxsock") # provides support for local system logging
module(load="imklog")   # provides kernel logging support
#module(load="immark")  # provides --MARK-- message capability

# provides UDP syslog reception
module(load="imudp")
input(type="imudp" port="514")
# Allow syslog from localhost and the 10.0.0.0/24 network only
$AllowedSender UDP, 127.0.0.1, 10.0.0.0/24
# On newer Rsyslog versions (rsyslog >= 8.2608.0) AllowedSender can be configured
# directly as an imudp module/input parameter.
# module(load="imudp" allowedSender=["10.0.0.0/24"])
# OLD version of rsyslog :
# $UDPServerRun 514

# provides TCP syslog reception
#module(load="imtcp")
#input(type="imtcp" port="514")
#$InputTCPServerRun 514

###########################
#### GLOBAL DIRECTIVES ####
###########################

#
# Set the default permissions for all log files.
#
$FileOwner root
$FileGroup adm
$FileCreateMode 0640
$DirCreateMode 0755
$Umask 0022

#
# Where to place spool and state files
#
$WorkDirectory /var/spool/rsyslog

#
# Include all config files in /etc/rsyslog.d/
#
$IncludeConfig /etc/rsyslog.d/*.conf

# template
# OLD version of rsyslog :
#$template Incoming-logs,"/var/log/%HOSTNAME%/logging.log"
# NEW version of rsyslog :
template(
    name="Incoming-logs"
    type="string"
    string="/var/log/%HOSTNAME%/logging.log"
)

###############
#### RULES ####
###############

#
# First some standard log files.  Log by facility.
#
auth,authpriv.*			/var/log/auth.log
*.*;auth,authpriv.none		-/var/log/syslog
#cron.*				/var/log/cron.log
daemon.*			-/var/log/daemon.log
kern.*				-/var/log/kern.log
lpr.*				-/var/log/lpr.log
mail.*				-/var/log/mail.log
user.*				-/var/log/user.log
local7.*				-/var/log/cisco.log # store all local7 messages in this file
*.*  ?Incoming-logs # store logs in separate directories by hostname

#
# Logging for the mail system.  Split it up so that
# it is easy to write scripts to parse these files.
#
mail.info			-/var/log/mail.info
mail.warn			-/var/log/mail.warn
mail.err			/var/log/mail.err

#
# Some "catch-all" log files.
#
*.=debug;\
	auth,authpriv.none;\
	news.none;mail.none	-/var/log/debug
*.=info;*.=notice;*.=warn;\
	auth,authpriv.none;\
	cron,daemon.none;\
	mail,news.none		-/var/log/messages

#
# Emergencies are sent to everybody logged in.
#
*.emerg				:omusrmsg:*
  • Check the Rsyslog configuration for syntax errors with the rsyslogd command:
root@host:~# rsyslogd -N1
rsyslogd: version 8.2504.0, config validation run (level 1), master config /etc/rsyslog.conf
rsyslogd: End of config validation run. Bye.
  • If no configuration errors are reported, restart the Rsyslog service:
root@host:~# systemctl restart rsyslog.service

Checking the received logs

  • After a few seconds, the Syslog messages sent by the Cisco switches should appear in the configured log files:
root@host:~# cat /var/log/cisco.log
Dec 25 16:25:03 10.0.0.2 %PNPAGENT-I-PNPSRVRDETECT: PnP Server devicehelper.cisco.com was detected  
Dec 25 16:25:06 10.0.0.2 %PNPAGENT-I-RESPSUCCESS: PnP Response Success  
Dec 25 16:25:22 10.0.0.2 %PNPAGENT-I-PNPSRVRDETECT: PnP Server devicehelper.cisco.com was detected  
Dec 25 16:25:23 10.0.0.1 %PNPAGENT-I-PNPSRVRDETECT: PnP Server devicehelper.cisco.com was detected

💡 Note: With the configuration above, Rsyslog stores messages in separate directories based on the hostname contained in each Syslog message. For network devices, this hostname may appear as the device IP address.

root@host:~# cat /var/log/10.0.0.1/logging.log
Dec 25 16:25:23 10.0.0.1 %PNPAGENT-I-PNPSRVRDETECT: PnP Server devicehelper.cisco.com was detected

References