Hello,
Could someone please clarify a couple of queries for me? Regarding logging in AOS8.6.0.6.
We have the following in our config:
*[mynode] #show logging level verbose
LOGGING LEVELS
--------------
Facility Level Sub Category Process
-------- ----- ------------ -------
arm warnings N/A N/A
network warnings N/A N/A
security warnings N/A N/A
security debugging N/A crypto
security warnings ids N/A
security warnings ids-ap N/A
system warnings N/A N/A
user warnings N/A N/A
wireless warnings N/A N/A
I recently added the crypto debugging for a TAC case we have open.
Our config has these entries:
logging x.x.x.x facility local3 severity warnings
logging x.x.x.x facility local3 severity warnings
logging security process crypto level debugging
logging security subcat ids-ap level warnings
logging security subcat ids level warnings
Two (and a half) questions really - we don't need the ids-ap and ids subcat entries, but I can't get rid of them, I get this:
*[mynode] (config) #no logging security subcat ids
Config deletion will not take effect: configuration is inherited.
I've tried running the command at different levels (/mm and /mm/mynode, as well as different levels in the md hierarchy (cluster members have the same logging config entries) ) in the hierarchy but no joy. Am I missing something?
Also I'm not quite sure how the remote logging will work now we have debug turned on for crypto, if we want to log the debug messages to the remote servers do I need to change the severity level in "logging x.x.x.x facility local3 severity warnings"? If so is that advisable or likely to cause a huge amount of traffic?
When looking at the GUI it is a little confusing as the logging levels for different components show as 'None' unless you select differently, but we certainly see plenty in our logs, so I assume everything is set to Warnings unless we tell it otherwise, is that right?
Thanks for your help,
Guy
------------------------------
Guy Goodrick
------------------------------