Syslog is the standard way network devices report events: an interface going down, a configuration change, a failed login, an OSPF neighbour change. Messages can be shown on the console, kept in a memory buffer, sent to SSH sessions, or sent to a central syslog server where they are stored, searched and correlated. Central logging is essential for troubleshooting and security investigations, because device buffers are small and their contents are lost on reload.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.