Back to How-To Guides
Configuration Syslog Only Mode

Running in Syslog Only Mode

Transform Backup Manager into a dedicated syslog server with a streamlined, focused interface

Easy 5 minutes

Overview: What is Syslog Only Mode?

Syslog Only Mode transforms Backup Manager into a dedicated syslog monitoring solution by hiding all backup-related features and providing a streamlined interface focused entirely on log management.

Why Use Syslog Only Mode?

  • Dedicated Syslog Server: Perfect for organizations that already have backup solutions but need a powerful syslog server
  • Simplified Interface: Reduces clutter by hiding features you don't need
  • User Focus: Ideal for operators who only need to monitor logs, not manage backups
  • Resource Efficiency: Concentrate on syslog processing without backup overhead

Features Available in Syslog Only Mode:

  • Syslog Dashboard with real-time charts
  • Syslog Messages with filtering and search
  • Intelligent Insights & Patterns
  • Security Dashboard
  • Security Events monitoring
  • Failed Logins tracking
  • Network Devices (for adding syslog sources)
  • System Settings

Features Hidden in Syslog Only Mode:

  • Configuration Backup
  • Configuration Restore
  • Backup Profiles
  • SNMP Monitoring
  • Network Topology
  • Configuration Timeline
  • Reports

Step 1: Navigate to System Settings

To enable Syslog Only Mode, you need to access the System Settings page.

How to Get There:

  • Click on System Settings in the left sidebar menu
  • Or navigate directly to the settings page from any location

What You'll See:

  • Syslog Server Protection: Device whitelist filtering option
  • Syslog Only Mode: The toggle to enable/disable this mode
  • Syslog Data Retention: Configure how long to keep log messages

The Syslog Only Mode section includes a description explaining that when enabled, the interface will display only syslog-related features and all backup, device management, and other non-syslog menus will be hidden.

Step 2: Enable Syslog Only Mode

Click the toggle switch next to "Syslog Only Mode" to enable it.

What Happens:

  • The toggle will switch to the ON position
  • A modal dialog will appear asking you to confirm the change
  • The modal explains that you need to logout and login again for changes to take effect

Why Logout is Required:

  • The menu structure is built when you login
  • Logging out and back in refreshes the entire interface
  • This ensures all menu items are correctly hidden/shown

Options in the Modal:

  • Cancel: Reverts the change and keeps Syslog Only Mode disabled
  • Logout Now: Logs you out immediately so you can login with the new mode

Step 3: Login with Syslog Only Mode Active

After clicking "Logout Now", you'll be redirected to the login page. Enter your credentials as usual.

What's Different After Login:

  • The sidebar menu will show only syslog-related options
  • Backup, SNMP, and topology features are completely hidden
  • The interface is cleaner and more focused
  • You'll be automatically redirected to the Syslog Dashboard

Available Menu Items:

  • Syslog: Dashboard, Messages, Intelligent Insights
  • Security: Security Dashboard, Security Events, Failed Logins
  • Management: Network Devices, System Settings

Note: Network Devices remains accessible so you can add or manage devices that send syslog messages to your server.

Step 4: Use the Syslog Dashboard

The Syslog Dashboard works exactly the same in Syslog Only Mode, providing full monitoring capabilities.

Available Features:

  • Real-Time Statistics: Total messages, messages per second, active devices
  • Time Range Selection: 1 hour to 30 days of data
  • Interactive Charts: Severity distribution, message trends, top devices
  • Auto-Refresh: Dashboard updates automatically every 60 seconds

Key Metrics:

  • Server Status: Confirms syslog server is running
  • Total Messages: Count of messages in selected time period
  • Messages/Sec: Current incoming message rate
  • Active Devices: Number of devices sending logs

All syslog analysis features work identically whether in normal mode or Syslog Only Mode.

Step 5: Add Devices as Syslog Sources

Even in Syslog Only Mode, you can add and manage network devices to configure them as syslog sources.

Why Network Devices is Available:

  • You need to register devices to use the Device Whitelist Protection feature
  • Device registration helps identify and categorize incoming logs
  • Registered devices show friendly names instead of just IP addresses

Adding a Syslog Source:

  • Click Network Devices in the sidebar
  • Click Add Device button
  • Enter the device name and IP address
  • Optionally configure SSH/Telnet credentials (not required for syslog-only use)
  • Save the device

Configure Your Devices:

On your network devices, configure syslog to send messages to Backup Manager's IP address on port 514 (UDP). Example for Cisco IOS:

logging host <BackupManager-IP>
logging trap informational
logging source-interface <management-interface>

Step 6: Disabling Syslog Only Mode

If you need to access backup features again, you can easily disable Syslog Only Mode.

How to Disable:

  • Navigate to System Settings (still accessible in Syslog Only Mode)
  • Toggle Syslog Only Mode to OFF
  • A modal will appear asking you to logout
  • Click Logout Now
  • Login again to see the full interface

After Disabling:

  • All menu items will be restored
  • Backup, SNMP, topology, and all other features become available
  • Your syslog data and settings are preserved
  • No data is lost when switching modes

You can switch between modes as often as needed. All your data, configurations, and settings are preserved regardless of which mode you're using.

Best Practices for Syslog Only Mode

When to Use Syslog Only Mode:

  • Dedicated Syslog Server: When you already have backup solutions and need only syslog capabilities
  • Security Operations Center: For SOC operators who focus on security event monitoring
  • Limited User Access: For users who should only monitor logs, not perform backups
  • Resource-Constrained Systems: To simplify the interface on smaller deployments

Recommended Additional Settings:

  • Enable Device Whitelist Protection: Filters out syslog from unregistered devices
  • Configure Data Retention: Set appropriate retention period (30-90 days typical)
  • Register All Syslog Sources: Add all devices that send syslog for proper identification
  • Set Up Email Alerts: Configure alerting for critical syslog events

Performance Tips:

  • The syslog server can handle millions of messages efficiently
  • Use time range filters to focus on relevant data
  • Intelligent Insights automatically highlights important events
  • Set appropriate retention to manage database size

Syslog Only Mode Configured!

You now have a dedicated syslog monitoring solution with a streamlined interface. Backup Manager in Syslog Only Mode provides enterprise-grade syslog collection, analysis, and security monitoring without the complexity of backup features. Monitor millions of log messages, detect security threats, and gain intelligent insights into your network operations.