How to Set Up an Rsyslog Server on Debian for Cisco Switch Logs
- Last updated: Sep 5, 2026
Introduction
I recently needed to set up a Rsyslog server to centralize logs from several Cisco switches.
In this guide, I will show you how to configure Rsyslog on Debian to receive and store Syslog messages sent by Cisco network switches.
Network diagram
All Cisco switches will send their Syslog messages to the Debian server.
In this setup, the switches send their logs to the Rsyslog server over UDP using the standard Syslog port 514.
Configuring Cisco switches
- Configure the network settings of the Cisco switch:
Switch# conf t
Switch(config)# ip name-server 86.54.11.100
Switch(config)# ip domain lookup
Switch(config)# interface vlan1
Switch(config-if)# ip address 10.0.0.1 255.255.255.0
Switch(config-if)# no ip address dhcp
Switch(config-if)# ip default-gateway 10.0.0.254
- Configure the remote Rsyslog server as the Syslog destination:
Switch(config)# logging host 10.0.0.200 port 514
Debian server
First, install a Debian server that will act as the central Rsyslog server. We can then install and configure Rsyslog to receive logs from the Cisco switches.
Installing and configuring Rsyslog
- Install the rsyslog package:
root@host:~# apt update && apt install rsyslog
- Edit the
/etc/rsyslog.conffile:
# /etc/rsyslog.conf configuration file for rsyslog
#
# For more information install rsyslog-doc and see
# /usr/share/doc/rsyslog-doc/html/configuration/index.html
#################
#### MODULES ####
#################
module(load="imuxsock") # provides support for local system logging
module(load="imklog") # provides kernel logging support
#module(load="immark") # provides --MARK-- message capability
# provides UDP syslog reception
module(load="imudp")
input(type="imudp" port="514")
# Allow syslog from localhost and the 10.0.0.0/24 network only
$AllowedSender UDP, 127.0.0.1, 10.0.0.0/24
# On newer Rsyslog versions (rsyslog >= 8.2608.0) AllowedSender can be configured
# directly as an imudp module/input parameter.
# module(load="imudp" allowedSender=["10.0.0.0/24"])
# OLD version of rsyslog :
# $UDPServerRun 514
# provides TCP syslog reception
#module(load="imtcp")
#input(type="imtcp" port="514")
#$InputTCPServerRun 514
###########################
#### GLOBAL DIRECTIVES ####
###########################
#
# Set the default permissions for all log files.
#
$FileOwner root
$FileGroup adm
$FileCreateMode 0640
$DirCreateMode 0755
$Umask 0022
#
# Where to place spool and state files
#
$WorkDirectory /var/spool/rsyslog
#
# Include all config files in /etc/rsyslog.d/
#
$IncludeConfig /etc/rsyslog.d/*.conf
# template
# OLD version of rsyslog :
#$template Incoming-logs,"/var/log/%HOSTNAME%/logging.log"
# NEW version of rsyslog :
template(
name="Incoming-logs"
type="string"
string="/var/log/%HOSTNAME%/logging.log"
)
###############
#### RULES ####
###############
#
# First some standard log files. Log by facility.
#
auth,authpriv.* /var/log/auth.log
*.*;auth,authpriv.none -/var/log/syslog
#cron.* /var/log/cron.log
daemon.* -/var/log/daemon.log
kern.* -/var/log/kern.log
lpr.* -/var/log/lpr.log
mail.* -/var/log/mail.log
user.* -/var/log/user.log
local7.* -/var/log/cisco.log # store all local7 messages in this file
*.* ?Incoming-logs # store logs in separate directories by hostname
#
# Logging for the mail system. Split it up so that
# it is easy to write scripts to parse these files.
#
mail.info -/var/log/mail.info
mail.warn -/var/log/mail.warn
mail.err /var/log/mail.err
#
# Some "catch-all" log files.
#
*.=debug;\
auth,authpriv.none;\
news.none;mail.none -/var/log/debug
*.=info;*.=notice;*.=warn;\
auth,authpriv.none;\
cron,daemon.none;\
mail,news.none -/var/log/messages
#
# Emergencies are sent to everybody logged in.
#
*.emerg :omusrmsg:*
- Check the Rsyslog configuration for syntax errors with the
rsyslogdcommand:
root@host:~# rsyslogd -N1
rsyslogd: version 8.2504.0, config validation run (level 1), master config /etc/rsyslog.conf
rsyslogd: End of config validation run. Bye.
- If no configuration errors are reported, restart the Rsyslog service:
root@host:~# systemctl restart rsyslog.service
Checking the received logs
- After a few seconds, the Syslog messages sent by the Cisco switches should appear in the configured log files:
root@host:~# cat /var/log/cisco.log
Dec 25 16:25:03 10.0.0.2 %PNPAGENT-I-PNPSRVRDETECT: PnP Server devicehelper.cisco.com was detected
Dec 25 16:25:06 10.0.0.2 %PNPAGENT-I-RESPSUCCESS: PnP Response Success
Dec 25 16:25:22 10.0.0.2 %PNPAGENT-I-PNPSRVRDETECT: PnP Server devicehelper.cisco.com was detected
Dec 25 16:25:23 10.0.0.1 %PNPAGENT-I-PNPSRVRDETECT: PnP Server devicehelper.cisco.com was detected
root@host:~# cat /var/log/10.0.0.1/logging.log
Dec 25 16:25:23 10.0.0.1 %PNPAGENT-I-PNPSRVRDETECT: PnP Server devicehelper.cisco.com was detected