Cisco IOS, IOS XE and NX-OS: send syslog, NetFlow and SNMP traps to MobiObs
This guide adds a MobiObs device as a temporary syslog host, Flexible NetFlow exporter and SNMP trap receiver on Cisco routers and switches, shows how to check that each one is sending, and how to remove it all again before you leave site.
MobiObs is not released yet. It is coming to Google Play first, then the App Store and desktop. Join the launch list to get one email when it is available.
Before you start
In the examples the MobiObs device is 10.20.4.9. Use the address shown on the app's Network screen. A mobile app cannot listen on ports below 1024, so every destination below uses the MobiObs defaults instead of 514 and 162:
| Data | Send to |
|---|---|
| Syslog | udp/5514 or tcp/5514 |
| NetFlow v9 and IPFIX | udp/2055 |
| sFlow (NX-OS) | udp/6343 |
| SNMP traps | udp/1162 |
Pick a source interface that has a route to the device, such as a loopback or the management VLAN interface, so that the messages arrive from one predictable address. The examples use Loopback0. Commands were written against IOS XE 17.x and classic IOS 15.x. Older trains accept most of them, but keywords do change, so check your release's configuration guide if a line is rejected.
Syslog
IOS / IOS XE 17.x: UDP (or TCP) syslog
service timestamps log datetime msec localtime show-timezone
logging source-interface Loopback0
logging host 10.20.4.9 transport udp port 5514
! or, for bursts, TCP instead of UDP:
! logging host 10.20.4.9 transport tcp port 5514
logging trap informational
logging trap sets the most verbose severity sent to remote hosts. Use debugging only for a short, controlled capture, because debug output can be very high volume. MobiObs parses the Cisco %FACILITY-SEVERITY-MNEMONIC tag and sequence numbers (service sequence-numbers) if you enable them.
To create a message on demand, use send log 6 "MobiObs test" in privileged EXEC mode where your release supports it, or simply enter and leave configuration mode, which logs %SYS-5-CONFIG_I.
Flexible NetFlow (v9 or IPFIX)
Flexible NetFlow needs a record, an exporter and a monitor applied to an interface. A user-defined record works on routers and on Catalyst 9000 switches, which do not accept every predefined record.
IOS XE 17.x: Flexible NetFlow to udp/2055
flow record MOBIOBS-REC
match ipv4 source address
match ipv4 destination address
match ipv4 protocol
match transport source-port
match transport destination-port
match interface input
collect counter bytes long
collect counter packets long
collect timestamp absolute first
collect timestamp absolute last
!
flow exporter MOBIOBS
destination 10.20.4.9
source Loopback0
transport udp 2055
export-protocol netflow-v9
template data timeout 60
!
flow monitor MOBIOBS-MON
exporter MOBIOBS
record MOBIOBS-REC
cache timeout active 60
!
interface GigabitEthernet1/0/1
ip flow monitor MOBIOBS-MON input
For IPFIX, use export-protocol ipfix; MobiObs decodes both on the same port. template data timeout 60 resends the template every minute, so MobiObs can decode flows within a minute even if it started after the exporter. cache timeout active 60 exports long-lived flows every minute rather than waiting for the default of 30 minutes.
SNMP traps (v2c and v3)
IOS / IOS XE: SNMPv2c traps to udp/1162
snmp-server community MOBIOBS-RO RO
snmp-server trap-source Loopback0
snmp-server enable traps snmp authentication linkdown linkup coldstart warmstart
snmp-server host 10.20.4.9 version 2c MOBIOBS-RO udp-port 1162
Use a community string other than public, and enter the same string in MobiObs so that traps pass its community check. Traps that fail the check are still shown, flagged, so a mismatch is easy to spot.
IOS / IOS XE: SNMPv3 authPriv traps
snmp-server group MOBIOBS-GRP v3 priv
snmp-server user mobiobs MOBIOBS-GRP v3 auth sha AuthPass-change-me priv aes 128 PrivPass-change-me
snmp-server host 10.20.4.9 version 3 priv mobiobs udp-port 1162
Add the same user name, authentication and privacy protocols and passwords as an SNMPv3 user in MobiObs (a Pro feature). For traps, the router is the authoritative engine; show snmp engineID displays its engine ID if you need it. SNMPv3 users do not appear in the running configuration, so note the passwords before you leave.
Verify on the device
IOS / IOS XE: show commands
show logging | include 10.20.4.9
show flow exporter MOBIOBS statistics
show flow monitor MOBIOBS-MON cache
show snmp host
show snmp user
show logging lists the remote host with its message counters, and the exporter statistics show packets sent. If the counters rise but nothing appears in MobiObs, the problem is on the path: check routing, ACLs and client isolation using the troubleshooting checklist. The Sources screen in MobiObs lists every address it has received from.
NX-OS notes
Nexus switches use different keywords and usually reach the collector through the management VRF. NetFlow is only available on some Nexus 9000 and 7000 hardware, while sFlow is more widely supported. Check the feature matrix for your platform and NX-OS release.
NX-OS 9.3 / 10.x: syslog, sFlow and traps
logging server 10.20.4.9 6 port 5514 use-vrf management
!
feature sflow
sflow collector-ip 10.20.4.9 vrf management
sflow collector-port 6343
sflow agent-ip 192.0.2.10
sflow sampling-rate 4096
sflow data-source interface ethernet 1/1
!
snmp-server host 10.20.4.9 traps version 2c MOBIOBS-RO udp-port 1162
snmp-server host 10.20.4.9 use-vrf management
The 6 after the server address is the severity (informational). sflow agent-ip must be an address configured on the switch. For NetFlow on supported hardware, enable feature netflow and build an exporter, record and monitor as on IOS XE, with destination 10.20.4.9 use-vrf management and version 9 in the exporter.
Remove it afterwards
IOS / IOS XE: clean-up
interface GigabitEthernet1/0/1
no ip flow monitor MOBIOBS-MON input
!
no flow monitor MOBIOBS-MON
no flow exporter MOBIOBS
no flow record MOBIOBS-REC
no logging host 10.20.4.9 transport udp port 5514
no snmp-server host 10.20.4.9 version 2c MOBIOBS-RO
no snmp-server host 10.20.4.9 version 3 priv mobiobs
no snmp-server user mobiobs MOBIOBS-GRP v3
no snmp-server group MOBIOBS-GRP v3 priv
The monitor must be removed from interfaces before it can be deleted. Remove the community too if you created it only for this visit, and save the configuration (copy running-config startup-config) only once the device is back to its intended state. On NX-OS, prefix the same lines with no and run no feature sflow if sFlow was not in use before.