Back to blog

Cisco / IOS  ·  Monitoring  ·  October 2026

Cisco IOS
Syslog & Logging

A log entry that only lives in the router's RAM buffer is gone at the next reboot — and the first thing an intruder clears. Centralized logging gets every event off the box, in order, timestamped against real time, to a collector you control. This post covers the severity model, the NTP dependency nobody mentions, shipping to a collector, and killing the noise that makes logs useless. The MikroTik twin is MikroTik: Logging & Remote Syslog; for metrics rather than events see Cisco observability.

Cisco IOS Syslog Logging Monitoring Hardening

Logging on IOS is a pipeline with a filter in the middle. Every subsystem emits messages tagged with a severity 0–7 (emergency down to debug). Each destination — the console, your SSH session, the local buffer, a remote collector — has its own severity threshold, and only messages at or above it get through. Get the thresholds wrong and you either drown in debug noise or miss the %LINK-3-UPDOWN that explained the outage.

The goal is simple: send informational and above to a central syslog server, timestamped against NTP so events from forty devices line up on one timeline, over a transport an attacker can't quietly strip. Local buffers are a convenience; the collector is the record.

Prerequisites
DEVICE emits events 0–7 SEVERITY GATE trap ≤ 6 COLLECTOR rsyslog / SIEM UDP/TCP 514 passes filter debug (7) dropped ✕

01

Severity, Timestamps & the NTP Dependency

Before you log anywhere, make the timestamps real. A log with the wrong time is worse than no log — it sends you to the wrong five minutes.

IOS — timestamps that correlate across devices
# Timestamp every log line with date+time to the millisecond, in a
# named timezone, so forty devices share one timeline.
R1(config)# service timestamps log datetime msec localtime show-timezone
R1(config)# service timestamps debug datetime msec localtime show-timezone

# Number the messages so you can spot a gap (a cleared or dropped log).
R1(config)# service sequence-numbers

# The whole thing is worthless without a synced clock.
R1(config)# ntp server 10.0.0.1
R1(config)# clock timezone EET 2 0
LevelKeyword — meaning
0–2emergency / alert / critical — box is in trouble
3errors — %LINK-3-UPDOWN, interface/protocol failures
4–5warnings / notifications — config changes, thresholds
6informational — the sensible collector threshold
7debugging — firehose; never send to a collector in prod
⚠ Gotcha — Uptime Timestamps Are the Default, and They're Useless

Out of the box IOS stamps logs with uptime (%LINK-3-UPDOWN: 3w4d: ...), not wall-clock time. Correlating that against a firewall log or a packet capture is guesswork. service timestamps log datetime fixes the format, but it only tells the truth if NTP is actually synced — check show ntp status reads Clock is synchronized before you trust a single timestamp.

02

Ship It Off the Box

Point the device at a collector, set the threshold, and pin the source. The buffer stays as a local convenience; the collector is the system of record.

IOS — remote collector + local buffer
# Send informational-and-above to the collector.
R1(config)# logging host 10.0.0.5
R1(config)# logging trap informational        # level 6 — not debugging

# Pin the source so the collector always sees one IP (ACLs, parsing).
R1(config)# logging source-interface Loopback0

# Keep a decent local ring buffer too; survives link loss, not reboot.
R1(config)# logging buffered 128000 informational

# Stop logs spamming the console (it's synchronous and can hang the box).
R1(config)# logging console critical
R1(config)# logging monitor informational      # vty — 'terminal monitor' to see
💡 Pro Tip — Two Collectors, One Config

Add a second logging host and messages fan out to both — send a copy to the ops collector and a copy to the SIEM, so a retention purge on one never costs you the security trail. Pin the same source-interface and register that IP on both. This is the event-side twin of pinning your AAA and NTP sources.

03

Kill the Noise — Rate-Limit & Discriminators

A flapping interface or a chatty subsystem can bury the one line that matters. IOS can throttle volume and filter specific messages before they ever hit the collector.

IOS — throttle and filter
# Cap bursts so a flap storm can't DoS your own logging pipeline.
R1(config)# logging rate-limit 20 except errors   # keep all level ≤3

# A discriminator: drop a known-noisy message, keep everything else.
R1(config)# logging discriminator NO-FLAP msg-body drops UPDOWN
R1(config)# logging host 10.0.0.5 discriminator NO-FLAP

# Prefer fixing the flap. Filtering noise you should have cured just
# hides the problem from the collector too.
⚠ Gotcha — A Discriminator Can Silence Your Evidence

Discriminators match on message body/severity/facility and apply per host. It's easy to write one that drops more than you intended — filter on msg-body drops UPDOWN and you also lose a genuine flap during an incident. Scope them tightly, keep except errors on rate-limits so criticals always pass, and document every filter: a quiet collector because of a forgotten discriminator looks exactly like a quiet network.

04

Secure Transport & What to Actually Log

Plain syslog is UDP/514 — unauthenticated, unencrypted, trivially spoofed or dropped. On anything carrying security events, move to TLS.

IOS — syslog over TLS (where the platform supports it)
# TCP transport first (reliable), then TLS with a trustpoint for the
# collector's CA so logs are encrypted and the peer is authenticated.
R1(config)# logging host 10.0.0.5 transport tls port 6514
R1(config)# crypto pki trustpoint SYSLOG-CA
R1(config-pki)# enrollment terminal
# ...install the collector CA cert, then IOS validates the TLS peer.

# Make sure the events that matter are even generated:
R1(config)# login on-failure log              # failed logins
R1(config)# login on-success log              # successful logins
R1(config)# archive
R1(config-archive)# log config
R1(config-archive-log-cfg)# logging enable   # who changed what config

05

Verify Safe to Run

IOS — confirm the pipeline end to end
R1# show logging                    # thresholds, hosts, buffer, counts
R1# show ntp status                 # MUST read 'Clock is synchronized'
R1# show logging history
R1# send log level 6 "syslog test from R1"   # prove it reaches the collector

Takeaways

  1. Fix timestamps first — service timestamps log datetime msec localtime + synced NTP, or every log lies about when it happened.
  2. logging trap informational (6), never debugging (7) to a collector — and keep a local buffer for link-loss gaps.
  3. Pin logging source-interface to a loopback; register that IP on the collector.
  4. Rate-limit with except errors and scope discriminators tightly — a forgotten filter looks like a quiet network.
  5. Use TLS (6514) for anything security-relevant, and turn on login/config-change logging so the events you need exist at all.
  6. Two collectors — ops and SIEM — so one retention purge never costs you the trail.

Logs you can actually trust in an incident?

Most networks log to the void — wrong timestamps, nothing shipped off-box, the one useful line buried in flap noise. I build centralized logging across Cisco and MikroTik fleets, correlated to real time and fed into the collector or SIEM you already run. Let's make your logs tell the truth.

Book a Discovery Call →