Back to How-To Guides
Advanced Features Syslog Monitoring & Analysis

Syslog Monitoring & Analysis

Monitor, analyze, and gain intelligent insights from millions of syslog messages across your network

Intermediate 20 minutes

Step 1: View Real-Time Syslog Messages

Navigate to Syslog Messages → Overview to see all incoming log messages from your network devices in real-time.

Key features of the Syslog Messages view:

  • Live Mode: Watch messages arrive in real-time with automatic updates
  • Total Messages: See how many messages have been collected (handles millions efficiently)
  • Last 24 Hours: Quick stat showing recent activity (e.g., 3.2M messages)
  • Active Devices: Number of devices currently sending logs

Powerful Filtering Options:

  • Severity: Filter by EMERGENCY, ALERT, CRITICAL, ERROR, WARNING, NOTICE, INFO, DEBUG (color-coded badges)
  • Device: View messages from specific devices
  • Subsystem: Filter by protocol (LINK, LINEPROTO, MAB, DOT1X, etc.)
  • Time Range: Select from Last Hour, 6 Hours, 24 Hours, 7 Days, 30 Days, or Custom
  • Search: Full-text search across all message fields

Step 2: Understanding Message Details

Each syslog message displays comprehensive information to help you troubleshoot network issues:

  • Timestamp: Precise time when the event occurred
  • Device: Source device name or IP address
  • Severity: Color-coded badges (ERROR=red, WARNING=orange, NOTICE=blue, INFO=cyan)
  • Subsystem: Network protocol or service that generated the message
  • Message: Full parsed message with relevant details (interfaces, MAC addresses, session IDs)

Message Types You'll See:

  • Interface State Changes: "UPDOWN", "changed state to up/down"
  • Authentication Events: "Authentication failed", "sessiongrd" messages
  • Security Violations: MAC address violations, unauthorized access attempts
  • Protocol Events: LINEPROTO, DOT1X, MAB, STORM_CONTROL, and more

Use the severity filter to focus on critical issues (ERROR + WARNING) or routine information (INFO + NOTICE).

Step 3: Monitor with Syslog Dashboard

Navigate to Syslog → Overview to access the visual dashboard with real-time charts and statistics.

Key Metrics (Top Cards):

  • Server Status: Confirms syslog server is running with port and IP information
  • Total Messages: Number of messages in selected time period (updates in real-time)
  • Messages/Sec: Current message rate showing network activity level
  • Active Devices: How many devices are currently sending logs

Interactive Time Range Buttons:

  • 1 Hour: View last hour of activity (default, fastest loading)
  • 6 Hours / 12 Hours / Day: Short-term analysis
  • 3 Days / 5 Days / 7 Days: Weekly trend analysis
  • 14 Days / Month: Long-term historical analysis

Note: The dashboard auto-refreshes every 60 seconds to show the latest data. All charts update dynamically when you change the time range.

Step 4: Analyze Charts and Visualizations

The Syslog Dashboard includes 5 powerful visual analytics widgets:

1. Messages by Severity (Pie Chart):

  • Visualizes the distribution of message severities
  • Color-coded: Red (ERROR), Orange (WARNING), Blue (NOTICE), Green (INFO)
  • Helps identify if your network has abnormal error rates

2. Messages Over Time (Line Chart):

  • Shows message volume trends over the selected time period
  • Helps spot activity spikes, outages, or patterns
  • Hourly granularity for short ranges, daily for longer periods

3. Top Facilities (Horizontal Bar Chart):

  • Shows which network protocols/subsystems are most active
  • Examples: DOT1X (auth), MAB (MAC auth), LINEPROTO (interfaces), SESSION_MGR
  • Helps identify busy services or troublesome protocols

4. Top Devices by Message Count (Horizontal Bar Chart):

  • Identifies devices generating the most log messages
  • High message count may indicate issues or high activity
  • Click device names to drill down into specific device logs

5. Severity Trends (Multi-Line Chart):

  • Shows how different severity levels trend over time
  • Color-coded lines for each severity (ERROR, WARNING, NOTICE, INFO)
  • Helps identify if errors are increasing, decreasing, or stable

All charts are interactive! Hover over data points to see detailed information, and charts update instantly when changing time ranges.

Step 5: Use Intelligent Insights & Patterns

Navigate to Syslog → Intelligent Insights & Patterns for network analysis and proactive monitoring.

Key Insight Cards (Top):

  • Anomalies Detected: Unusual events requiring immediate attention
  • Network Health Score: Overall health rating (0-100) based on error ratios
  • Correlated Events: Related events that occurred across multiple devices
  • Devices Requiring Attention: Devices with high error rates or unusual behavior

Smart Insights Panel:

  • Critical Alerts: Interface flapping detection, security violations
  • Warning Messages: Failed login attempts, potential brute force attacks
  • Info Messages: Network operating normally, health status updates
  • Success Messages: Confirmation when network is healthy

Example insights you'll see:

  • "Multiple Failed Login Attempts - 1920 failed login attempts detected - possible brute force attack"
  • "Network Operating Normally - Network health is excellent with minimal errors"
  • "Interface Flapping Detected - 5 interfaces showing instability"

Note: The system automatically analyzes millions of messages and highlights only the most important insights for your attention.

Step 6: Investigate Event Correlations

The Event Correlation Timeline visualizes related events across multiple devices to help identify network-wide issues.

How It Works:

  • Timeline View: Shows when critical/error events occurred across all devices
  • Device Grouping: Each row represents a different device
  • Color-Coded Dots: Each device has a unique color for easy identification
  • Interactive: Hover over events to see full message details, severity, and timestamp

Use Cases:

  • Network-Wide Outages: See if multiple devices experienced issues at the same time
  • Cascading Failures: Identify which device failed first, causing others to fail
  • Coordinated Attacks: Detect if multiple devices are under attack simultaneously
  • Configuration Impact: See if a configuration change affected multiple devices

Example: If you see a vertical line of events at the same timestamp, that indicates a network-wide event (power failure, core switch issue, etc.).

Step 7: Monitor Flapping Interfaces and Top Errors

Scroll down to see additional diagnostic widgets that help identify specific network problems:

Top Flapping Interfaces:

  • Lists interfaces that frequently change state (up/down)
  • Shows device name, interface name, and flap count
  • Displays last flap time for each interface
  • Why it matters: Flapping interfaces indicate bad cables, failing hardware, or configuration issues

Top Error Messages:

  • Shows most frequent error messages across your network
  • Includes affected device count and device list
  • Color-coded by severity (CRITICAL=red, ERROR=orange)
  • Example: "Switch 1 R0/0: fman_fp_image: WRClient 0x195a500e download..." appearing on 1 device

Most Active Devices:

  • Ranked list of devices by message volume
  • Message count shown next to each device
  • Helps identify chatty devices or devices with issues

If a device suddenly appears at the top of "Most Active Devices" with high message count, investigate immediately - it may indicate a problem!

Step 8: Detect Recurring Patterns and Anomalies

The bottom section of the Intelligent Insights page provides advanced pattern detection and anomaly analysis:

Recurring Patterns Detected:

  • Hourly Patterns: Events that occur at the same minute past each hour
  • Daily Patterns: Events that happen at the same time every day (e.g., backup schedules)
  • Weekly Patterns: Events that occur on specific days of the week
  • Flapping Patterns: Interfaces that flap at predictable times
  • Each pattern shows confidence level (percentage) and next occurrence prediction

Anomaly Detection:

  • CRITICAL Anomalies: Emergency/Critical severity messages (red badge)
  • WARNING Anomalies: Silent devices (stopped reporting), message volume spikes (orange badge)
  • INFO Anomalies: New error patterns not seen before (blue badge)
  • Each anomaly shows device IP, description, status, and detection time

Example Anomalies You Might See:

  • "New error pattern: Switch 1 R0/0: fman_fp_image: WRClient..." (Status: New)
  • "No messages received since 2025-11-29 14:58:01" (Status: Silent)
  • "Message volume increased by 150% in last hour" (Status: Active)

Silent device warnings help you catch devices that have crashed or been disconnected from the network!

Step 9: Using Filters for Targeted Analysis (Example)

Back in the Syslog Messages → Overview, use the powerful filtering system to drill down into specific issues. This is just one example of many filtering strategies you can use:

Severity Filtering Strategies:

  • ERROR only: Focus on serious problems requiring immediate action
  • ERROR + WARNING: See all potentially problematic events
  • NOTICE + INFO: View routine operational messages
  • All Severities: Complete visibility for comprehensive analysis

Subsystem Filtering Use Cases:

  • LINK + LINEPROTO: Troubleshoot interface connectivity issues
  • DOT1X + MAB: Investigate authentication problems
  • SESSION_MGR + AUTHMGR: Monitor user sessions and authorization
  • STORM_CONTROL: Check for broadcast storms or network loops

Time Range Best Practices:

  • Last Hour: Real-time troubleshooting, immediate issues
  • Last 24 Hours: Daily activity review, pattern identification
  • Last 7 Days: Weekly trends, recurring issues
  • Last 30 Days: Monthly analysis, long-term health assessment
  • Custom Range: Incident investigation, compliance audits

Combine multiple filters! For example, select "ERROR" severity + specific device + "Last 24 Hours" to investigate why a particular device is having problems.

Step 10: Best Practices for Syslog Monitoring

Daily Monitoring Routine:

  • Morning: Check Syslog Dashboard → "Last 24 Hours" for overnight issues
  • Review Intelligent Insights: Look for new warnings or critical alerts
  • Check Anomaly Detection: Investigate any silent devices or new error patterns
  • Monitor Health Score: Should be 90+ for healthy network; < 80 needs attention

Troubleshooting Workflow:

  • Step 1: User reports problem → Note the time
  • Step 2: Go to Syslog Messages → Set custom time range around the incident
  • Step 3: Filter by severity (ERROR + WARNING)
  • Step 4: If specific device known, filter by that device
  • Step 5: Review messages, look for patterns or root cause indicators
  • Step 6: Check Event Correlation Timeline for related events on other devices

Security Monitoring:

  • Watch for "Multiple Failed Login Attempts" insights (possible attacks)
  • Monitor authentication failures (DOT1X, MAB, SESSION_MGR)
  • Check for security violations and unauthorized MAC addresses
  • Review Anomaly Detection for unusual patterns

Capacity Planning:

  • Use Messages/Sec metric to understand network load
  • Review Messages Over Time chart for growth trends
  • Check Most Active Devices to identify high-traffic devices
  • Plan device upgrades or network segmentation based on data

Step 11: Understanding Severity Levels

Syslog messages use standardized severity levels based on RFC 5424. Understanding these helps you prioritize your response:

Severity Levels (Most to Least Critical):

  • EMERGENCY (0): System is unusable (entire device down) - Dark Red
  • ALERT (1): Action must be taken immediately (critical component failure) - Crimson
  • CRITICAL (2): Critical conditions (major service failure) - Red
  • ERROR (3): Error conditions (service degradation) - Tomato
  • WARNING (4): Warning conditions (potential issues) - Orange
  • NOTICE (5): Normal but significant (state changes) - Blue
  • INFO (6): Informational messages (routine operations) - Green
  • DEBUG (7): Debug-level messages (verbose logging) - Gray

Response Priority Guide:

  • 0-2 (EMERGENCY/ALERT/CRITICAL): Immediate action required - network outage or critical failure
  • 3-4 (ERROR/WARNING): Investigate within 1-4 hours - potential service impact
  • 5 (NOTICE): Review during daily monitoring - informational state changes
  • 6-7 (INFO/DEBUG): No action needed - normal operations or verbose logging

Network Health Interpretation:

  • Health Score 95-100: Excellent - mostly INFO/NOTICE messages
  • Health Score 80-94: Good - some warnings but under control
  • Health Score 60-79: Fair - multiple errors, needs investigation
  • Health Score < 60: Poor - high error rate, immediate action needed

In the Intelligent Insights dashboard, a health score of 100/100 with "Network Operating Normally" indicates everything is working perfectly!

Syslog Monitoring Mastered!

You now have complete visibility into your network infrastructure with real-time monitoring, intelligent insights, and proactive anomaly detection. Backup Manager & Network Operations Suite's syslog features help you maintain network health, troubleshoot issues faster, and detect security threats before they become critical.