<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ZD syslog / AP syslog - how useful? in Access Points - Indoor and Outdoor</title>
    <link>https://community.ruckuswireless.com/t5/Access-Points-Indoor-and-Outdoor/ZD-syslog-AP-syslog-how-useful/m-p/19475#M5116</link>
    <description>Ive was looking forward to sending useful syslog messages from our ZD which manages ~280 APs at 4x different buildings into our new Splunk setup.&amp;nbsp; However i think im missing something and was hoping for some help or others experiences:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;U alt="" name="" rel="" target="" title="" type="" value=""&gt;1-&lt;/U&gt;&amp;nbsp; The syslogs from the Managed APs do not contain the APs "device-name" (ie get device-name) , i do see the APs private IP address (as splunk is adding the host to each message).&amp;nbsp; However, How am i supposed to know which AP/building/area a message is related to.&amp;nbsp; (or for search / history purposes).&amp;nbsp; Every syslog source i use either includes the devices' name or allows the user to set the name to be included.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;U alt="" name="" rel="" target="" title="" type="" value=""&gt;2-&lt;/U&gt;&amp;nbsp; on the ZD if i set the Remote Syslog -&amp;gt; "Managed Ap Settings" to Priority Level="Err" (error) , i do get useful messages, however 99% of the messages are "lwapp_send_pkt(6423), sends packet out with length: 1321"&amp;nbsp; at a rate of about 200 of those per minute.&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;now if&amp;nbsp; set "Managed Ap Settings"&amp;nbsp; -&amp;gt; to Priority Level=Critical , i get 0 messages from the APs (even after 2 days of running at the Critical setting).&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;I know users are using remote syslog with their ZD setup,&amp;nbsp; so can anyone provide their experiences or info maybe?&amp;nbsp;&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;I really hope this post can get a reply (or even someone confirming this is the way it is),&amp;nbsp; i have yet to get any replies to nearly 20 posts across 5 months here on the forums.&amp;nbsp;&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Thanks!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;(im also about to start adding some new APs to our vSZ so will report on how syslog works on that newer platform)&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;( for those that see this in the future-&amp;nbsp; a rough workaround would be to have Splunk drop any input with "lwapp_send_pkt"&amp;nbsp; or i have even tested using a mikrotik with /firewall filter content="lwapp_send_pkt"&amp;nbsp; &amp;nbsp;to filter out the syslog msgs as they are ofcourse not encrypted,&amp;nbsp; but there has be a better way for those who use syslog with ZD / Ruckus.)</description>
    <pubDate>Fri, 28 Sep 2018 23:39:47 GMT</pubDate>
    <dc:creator>stephen_hall_60</dc:creator>
    <dc:date>2018-09-28T23:39:47Z</dc:date>
    <item>
      <title>ZD syslog / AP syslog - how useful?</title>
      <link>https://community.ruckuswireless.com/t5/Access-Points-Indoor-and-Outdoor/ZD-syslog-AP-syslog-how-useful/m-p/19475#M5116</link>
      <description>Ive was looking forward to sending useful syslog messages from our ZD which manages ~280 APs at 4x different buildings into our new Splunk setup.&amp;nbsp; However i think im missing something and was hoping for some help or others experiences:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;U alt="" name="" rel="" target="" title="" type="" value=""&gt;1-&lt;/U&gt;&amp;nbsp; The syslogs from the Managed APs do not contain the APs "device-name" (ie get device-name) , i do see the APs private IP address (as splunk is adding the host to each message).&amp;nbsp; However, How am i supposed to know which AP/building/area a message is related to.&amp;nbsp; (or for search / history purposes).&amp;nbsp; Every syslog source i use either includes the devices' name or allows the user to set the name to be included.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;U alt="" name="" rel="" target="" title="" type="" value=""&gt;2-&lt;/U&gt;&amp;nbsp; on the ZD if i set the Remote Syslog -&amp;gt; "Managed Ap Settings" to Priority Level="Err" (error) , i do get useful messages, however 99% of the messages are "lwapp_send_pkt(6423), sends packet out with length: 1321"&amp;nbsp; at a rate of about 200 of those per minute.&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;now if&amp;nbsp; set "Managed Ap Settings"&amp;nbsp; -&amp;gt; to Priority Level=Critical , i get 0 messages from the APs (even after 2 days of running at the Critical setting).&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;I know users are using remote syslog with their ZD setup,&amp;nbsp; so can anyone provide their experiences or info maybe?&amp;nbsp;&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;I really hope this post can get a reply (or even someone confirming this is the way it is),&amp;nbsp; i have yet to get any replies to nearly 20 posts across 5 months here on the forums.&amp;nbsp;&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Thanks!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;(im also about to start adding some new APs to our vSZ so will report on how syslog works on that newer platform)&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;( for those that see this in the future-&amp;nbsp; a rough workaround would be to have Splunk drop any input with "lwapp_send_pkt"&amp;nbsp; or i have even tested using a mikrotik with /firewall filter content="lwapp_send_pkt"&amp;nbsp; &amp;nbsp;to filter out the syslog msgs as they are ofcourse not encrypted,&amp;nbsp; but there has be a better way for those who use syslog with ZD / Ruckus.)</description>
      <pubDate>Fri, 28 Sep 2018 23:39:47 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Access-Points-Indoor-and-Outdoor/ZD-syslog-AP-syslog-how-useful/m-p/19475#M5116</guid>
      <dc:creator>stephen_hall_60</dc:creator>
      <dc:date>2018-09-28T23:39:47Z</dc:date>
    </item>
  </channel>
</rss>

