Interpret syslog facilities, severity levels, timestamps and remote logging behaviour.
SeverityFacilityRemote serverTimestampsBuffer
01 // Mental model
Start with the big picture.
A device records an event with timestamp, source/facility, severity and descriptive text.
CCNA focus: A configured threshold includes that severity and every more-severe level. A warning threshold (4) includes levels 0 through 4, not 4 through 7.
02 // Building blocks
Know what each part does.
01
Message
A device records an event with timestamp, source/facility, severity and descriptive text.
02
Severity
Levels run from 0 emergencies (most severe) to 7 debugging (least severe).
03
Facility
Categorises the subsystem or process that produced the event.
04
Destination
Messages may go to console, monitor lines, local buffer or a remote syslog server.
03 // Compare and recognise
Read the clues.
Item
What to remember
0
Emergencies — system unusable.
3
Errors — an error condition.
5
Notifications — normal but significant event.
7
Debugging — detailed diagnostic output.
04 // Remote logging baseline
Remote logging baseline.
R1(config)# service timestamps log datetime msecR1(config)# logging host 10.20.30.40R1(config)# logging trap warningsR1(config)# logging buffered 16384 informationalR1# show logging
Read the example from top to bottom, then verify the resulting state. Configuration is only complete when the output matches the intended design.
05 // Exam and troubleshooting
Turn facts into a method.
Emergencies — system unusable.
Errors — an error condition.
Notifications — normal but significant event.
Debugging — detailed diagnostic output.
Exam checkpoint: A configured threshold includes that severity and every more-severe level. A warning threshold (4) includes levels 0 through 4, not 4 through 7.
06 // Check yourself
Syslog quiz.
1. Which syslog severity is most urgent?
2. What does a logging threshold of warnings include?