Aruba AOS-CX and ArubaOS 8: send syslog, sFlow and SNMP traps to MobiObs
Aruba switches running AOS-CX can send syslog, sFlow and SNMP traps straight to the ports a MobiObs device listens on. Mobility Controllers and Instant access points on ArubaOS 8 are less flexible about destination ports, so this guide also covers how to bridge the gap.
MobiObs is not released yet. It is coming to Google Play first, then the App Store and desktop. Join the launch list to get one email when it is available.
Before you start
The MobiObs device is 10.20.4.9 in the examples; use the address from the app's Network screen. The collector ports are udp/5514 and tcp/5514 for syslog, udp/6343 for sFlow, udp/2055 for NetFlow and IPFIX, and udp/1162 for SNMP traps. A mobile app cannot open ports below 1024, so equipment must be told to use these ports rather than 514 and 162.
Aruba has two different operating systems with different command sets. The first half of this guide is for AOS-CX switches (6000 to 10000 series, AOS-CX 10.10 and later). The second half is for ArubaOS 8 Mobility Controllers and Instant APs. Command keywords shift between releases; if a line is rejected, check your release's CLI reference rather than guessing.
AOS-CX: syslog
AOS-CX 10.10+: syslog over UDP or TCP
logging 10.20.4.9 udp 5514 severity info vrf mgmt
! or TCP to the same port:
! logging 10.20.4.9 tcp 5514 severity info vrf mgmt
Use vrf mgmt when the MobiObs device is reached through the out-of-band management port, or vrf default for in-band. Choose TCP if the switch is busy and you do not want to lose messages in a burst. Each logging line adds a server; the switch supports several, so this does not replace the existing ones.
AOS-CX: sFlow
AOS-CX 10.10+: sFlow to udp/6343 (verify keywords on your release)
sflow
sflow collector 10.20.4.9 port 6343 vrf mgmt
sflow agent-ip 192.0.2.2
sflow sampling 4096
sflow polling 20
interface 1/1/1
sflow
The global sflow command enables the agent, and sflow under an interface enables sampling on that port. agent-ip should be an address configured on the switch. MobiObs scales flow samples by the sampling rate and also decodes the counter samples, which show interface utilisation and errors. Some AOS-CX models and releases can also export IPFIX with flow exporter and flow monitor configuration; availability depends on the platform, so check the feature guide before relying on it.
AOS-CX: SNMP traps
AOS-CX 10.10+: SNMPv2c and SNMPv3 traps to udp/1162
snmp-server vrf mgmt
snmp-server community MOBIOBS-RO
snmp-server host 10.20.4.9 trap version v2c community MOBIOBS-RO port 1162 vrf mgmt
!
snmpv3 user mobiobs auth sha auth-pass plaintext AuthPass-change-me priv aes priv-pass plaintext PrivPass-change-me
snmp-server host 10.20.4.9 trap version v3 user mobiobs port 1162 vrf mgmt
Enter the community string, or the SNMPv3 user with the same authentication and privacy settings, in MobiObs. SNMPv3 users are a Pro feature. Traps that fail the community or USM check are shown flagged rather than dropped, which makes a typo easy to find.
AOS-CX: verify and remove
AOS-CX: show commands
show running-config | include logging
show sflow
show snmp trap
show snmpv3 users
To remove the configuration, repeat each line with no in front, for example no logging 10.20.4.9 udp 5514 severity info vrf mgmt, no sflow collector 10.20.4.9 port 6343 vrf mgmt and no snmp-server host 10.20.4.9 trap version v2c community MOBIOBS-RO port 1162 vrf mgmt. Remove the sFlow interface statements and the SNMPv3 user as well if they were added only for this visit.
ArubaOS 8 controllers and Instant APs
SNMP traps: Mobility Controllers let you set the destination UDP port on the trap host, so traps can go to MobiObs directly:
ArubaOS 8.x Mobility Controller: SNMPv2c traps (verify on your release)
snmp-server enable trap
snmp-server host 10.20.4.9 version 2c MOBIOBS-RO udp-port 1162
Syslog: in the ArubaOS 8 and Instant releases we have checked, the syslog server command takes an address, facility and severity levels but no destination port, so messages go to udp/514. Check your release's CLI reference, because newer releases may add a port option. If there is none, use one of these approaches:
- Relay through a Linux host. Run rsyslog on a laptop or server that the controller can reach, listening on udp/514, and forward everything to 10.20.4.9 on udp/5514. The rsyslog guide has the configuration.
- Destination NAT on a router in the path. Translate udp/514 for the controller's source address to 10.20.4.9 udp/5514.
- Existing syslog infrastructure. If a syslog server already receives the controller's logs, add a forwarding rule there instead of touching the controller.
A relay rewrites the source address, so MobiObs will list the relay on its Sources screen; the original hostname remains in each message.
Checking the path
Wireless controllers are often on a management VLAN that mobile devices cannot reach, and venue SSIDs frequently isolate clients from each other. If nothing arrives, confirm that the controller has a route to the MobiObs address, and move the device to a staff SSID without client isolation or onto a wired port. The venue troubleshooting guide walks through a typical event-day capture with a controller, and the troubleshooting checklist covers firewalls and ports.