LINUXOR.SK ... open source notes ...

NetApp - ONTAP: EMS events to syslog

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

NetApp Solution · Config document · referenced from Logging, monitoring and AutoSupport

The commands that send EMS events of a cluster to the central syslog server: a destination, a filter by severity and a notification that joins them. The deprecated destination-and-route method that the notes also hold is at the end.

ItemValue
Runs onThe cluster shell, as admin
Shown here forDC1-A-XNAS001
Also applied toDC1-B-XNAS001, with the same commands and the same syslog server
Syslog serverdc1-s-xcsys001.adm.example.net, 10.11.17.113, addressed by IPv4
ONTAP version at the time9.1

The command set

bash
# --- 1. First configuration, on both clusters -------------------------------
# A syslog destination and a notification that uses the built-in filter
# "important-events".
event notification destination create -name syslog -syslog 10.11.17.113
event notification create -filter-name important-events -destinations syslog

# --- 2. A filter of our own: everything except DEBUG -------------------------
# The design: include INFORMATIONAL, NOTICE, ERROR, ALERT, EMERGENCY,
# exclude DEBUG.
event filter create -filter-name all-events
event filter rule add -filter-name all-events -type include -severity INFORMATIONAL,NOTICE,ERROR,ALERT,EMERGENCY
event filter rule add -filter-name all-events -type exclude -severity DEBUG

# --- 3. Use the new filter ---------------------------------------------------
# The notes give two alternatives: create the notification with the new filter
# (on a cluster that has none yet) ...
event notification create -filter-name all-events -destinations syslog
# ... or point the existing notification (ID 2) at the new filter.
event notification modify -ID 2 -filter-name all-events

# --- 4. Check ----------------------------------------------------------------
# Expected: ID 1 default-trap-events -> snmp-traphost, ID 2 all-events -> syslog
event notification show
event notification destination show

# --- 5. The old way (marked "deprecated" in the notes) -----------------------
# List the existing destinations, add a syslog destination and route every
# message name to it. The destination was named after the organisation.
event destination show
event destination create -name example-syslog -syslog 10.11.17.113
event route add-destinations -messagename * -destination example-syslog

Section 5 is in the notes as the earlier method. The state that the notes show as final is the output of section 4: one notification with the filter all-events to the destination syslog.

DifferenceSite 1Site 2
Syslog server10.11.17.11310.12.17.113, dc2-s-xcsys001.adm.example.net

The notes hold the commands for site 1 only. The design also asks for TCP without TLS; no command in the notes sets a protocol, and cluster log-forwarding does not appear in them.

Checked against ONTAP 9.19.1

As builtToday
event notification destination create -name syslog -syslog 10.11.17.113, no transport chosenStill the command. It now has -syslog-port, -syslog-transport with the values udp-unencrypted, tcp-unencrypted and tcp-encrypted, and -syslog-message-format. The default transport is udp-unencrypted; TLS is available from ONTAP 9.12.1, default port 6514, with the server certificate validated
event filter create, event filter rule add, event notification createStill in the command reference
event destination create, event route add-destinationsDeprecated since ONTAP 9.0. The command pages exist up to the 9.10.1 reference and are absent from 9.11.1 on, although a concept page still says the commands continue to be available; a conversion guide to the notification model exists
cluster log-forwarding, not usedForwards the audit and command-history logs, with -protocol including tcp-encrypted and -verify-server. The vendor recommends offloading syslog information securely

The design's "TCP" needs an explicit -syslog-transport today, and encrypted transport is possible where the syslog server supports it. The last release for the FAS8200 is ONTAP 9.16.1, which already has all of this.

← solutionz