Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2InfrastructureHard
A network engineer troubleshooting a remote branch office router notices that the router's logs are not being sent to the central syslog server. Upon investigation, they find that the router's clock is significantly out of sync, displaying a date several years in the past. Which of the following is the most likely reason for the syslog messages not being received by the central server, assuming the server has correct time window configurations?
- AHigh CPU utilization on the router causing log drops.
- BIncorrect logging buffer size on the router.
- CThe syslog server is configured to drop messages with old timestamps.
- DMissing 'logging trap' configuration on the router.
Show answer & explanationAnswer & explanation
Correct answer: C. The syslog server is configured to drop messages with old timestamps.
Many syslog servers are configured with time window filters to prevent processing or storing logs with timestamps significantly outside the current time, especially older than a few minutes or hours. If the router's clock is years out of sync, the syslog server would likely discard these messages as invalid or too old, even if basic connectivity exists and the 'logging trap' is configured.
Why the other options are wrong
- A. High CPU could cause some drops, but a consistent 'not being sent' and 'years out of sync' strongly points to timestamp filtering as the primary cause.
- B. Incorrect logging buffer size affects local storage, not transmission to a remote server.
- D. Missing 'logging trap' would prevent any logs from being sent, but the question implies a specific issue with 'old timestamps' not being received, suggesting general logging is enabled but filtered.
Syslog Timestamp Filtering
The practice by syslog servers to discard incoming messages if their timestamps fall outside an acceptable time window, often to prevent processing old or invalid data.
- Crucial for data integrity and preventing 'log floods' from misconfigured devices.
- Requires accurate time synchronization (e.g., via NTP) on logging devices.
- Can lead to legitimate log messages being dropped if the source device's clock is severely out of sync.
Memory trick: Old Clock, No Logs: The Server's Trust is Gone.