Forum Discussion

ESSZak's avatar
ESSZak
Icon for Nimbostratus rankNimbostratus
May 01, 2019

ASM logs to Splunk

hi everybody , i configured looging profile to send asm logs to splunk , but loggs is send from self ip address , Can i send logs from managment IP & and what's better ??

 

  • Hi,

    Yes you can send using mgmt interface:

    you just need to set route using cli:

    tmsh create /sys management-route  network / gateway 

    • destination network/ your syslog IP 1.1.1.1/255.255.255.255
    • server-syslog-1
    • will be the GW of your mgmt IP

    you have to add as much route as syslog server server

    once done save config

    tmsh save /sys config

    then check route:

    tmsh list /sys management-route

    you can send syslog logs through the interface that suits you (mgmt or business). if you have a license limitation (badwitch). it is indeed more advantageous to send it through the managemet interface because the restriction does not impact the mgmt interface...

    keep me in touch if you need more details

    regards