NetApp - ONTAP: EMS events to syslog
NetApp Solution · Config document · referenced from Logging, monitoring and AutoSupport
The commands that send EMS events of a cluster to the central syslog server: a destination, a filter by severity and a notification that joins them. The deprecated destination-and-route method that the notes also hold is at the end.
| Item | Value |
|---|---|
| Runs on | The cluster shell, as admin |
| Shown here for | DC1-A-XNAS001 |
| Also applied to | DC1-B-XNAS001, with the same commands and the same syslog server |
| Syslog server | dc1-s-xcsys001.adm.example.net, 10.11.17.113, addressed by IPv4 |
| ONTAP version at the time | 9.1 |
The command set
# --- 1. First configuration, on both clusters ------------------------------- # A syslog destination and a notification that uses the built-in filter # "important-events". event notification destination create -name syslog -syslog 10.11.17.113 event notification create -filter-name important-events -destinations syslog # --- 2. A filter of our own: everything except DEBUG ------------------------- # The design: include INFORMATIONAL, NOTICE, ERROR, ALERT, EMERGENCY, # exclude DEBUG. event filter create -filter-name all-events event filter rule add -filter-name all-events -type include -severity INFORMATIONAL,NOTICE,ERROR,ALERT,EMERGENCY event filter rule add -filter-name all-events -type exclude -severity DEBUG # --- 3. Use the new filter --------------------------------------------------- # The notes give two alternatives: create the notification with the new filter # (on a cluster that has none yet) ... event notification create -filter-name all-events -destinations syslog # ... or point the existing notification (ID 2) at the new filter. event notification modify -ID 2 -filter-name all-events # --- 4. Check ---------------------------------------------------------------- # Expected: ID 1 default-trap-events -> snmp-traphost, ID 2 all-events -> syslog event notification show event notification destination show # --- 5. The old way (marked "deprecated" in the notes) ----------------------- # List the existing destinations, add a syslog destination and route every # message name to it. The destination was named after the organisation. event destination show event destination create -name example-syslog -syslog 10.11.17.113 event route add-destinations -messagename * -destination example-syslog
Section 5 is in the notes as the earlier method. The state that the notes show as final is the output of section 4: one notification with the filter all-events to the destination syslog.
| Difference | Site 1 | Site 2 |
|---|---|---|
| Syslog server | 10.11.17.113 | 10.12.17.113, dc2-s-xcsys001.adm.example.net |
The notes hold the commands for site 1 only. The design also asks for TCP without TLS; no command in the notes sets a protocol, and cluster log-forwarding does not appear in them.
Checked against ONTAP 9.19.1
| As built | Today |
|---|---|
event notification destination create -name syslog -syslog 10.11.17.113, no transport chosen | Still the command. It now has -syslog-port, -syslog-transport with the values udp-unencrypted, tcp-unencrypted and tcp-encrypted, and -syslog-message-format. The default transport is udp-unencrypted; TLS is available from ONTAP 9.12.1, default port 6514, with the server certificate validated |
event filter create, event filter rule add, event notification create | Still in the command reference |
event destination create, event route add-destinations | Deprecated since ONTAP 9.0. The command pages exist up to the 9.10.1 reference and are absent from 9.11.1 on, although a concept page still says the commands continue to be available; a conversion guide to the notification model exists |
cluster log-forwarding, not used | Forwards the audit and command-history logs, with -protocol including tcp-encrypted and -verify-server. The vendor recommends offloading syslog information securely |
The design's "TCP" needs an explicit -syslog-transport today, and encrypted transport is possible where the syslog server supports it. The last release for the FAS8200 is ONTAP 9.16.1, which already has all of this.