Cisco IOS, IOS XE and NX-OS: send syslog, NetFlow and SNMP traps to MobiObs

Updated 28 September 2026

This guide adds a MobiObs device as a temporary syslog host, Flexible NetFlow exporter and SNMP trap receiver on Cisco routers and switches, shows how to check that each one is sending, and how to remove it all again before you leave site.

MobiObs is not released yet. It is coming to Google Play first, then the App Store and desktop. Join the launch list to get one email when it is available.

Before you start

In the examples the MobiObs device is 10.20.4.9. Use the address shown on the app's Network screen. A mobile app cannot listen on ports below 1024, so every destination below uses the MobiObs defaults instead of 514 and 162:

DataSend to
Syslogudp/5514 or tcp/5514
NetFlow v9 and IPFIXudp/2055
sFlow (NX-OS)udp/6343
SNMP trapsudp/1162

Pick a source interface that has a route to the device, such as a loopback or the management VLAN interface, so that the messages arrive from one predictable address. The examples use Loopback0. Commands were written against IOS XE 17.x and classic IOS 15.x. Older trains accept most of them, but keywords do change, so check your release's configuration guide if a line is rejected.

Syslog

IOS / IOS XE 17.x: UDP (or TCP) syslog

service timestamps log datetime msec localtime show-timezone
logging source-interface Loopback0
logging host 10.20.4.9 transport udp port 5514
! or, for bursts, TCP instead of UDP:
! logging host 10.20.4.9 transport tcp port 5514
logging trap informational

logging trap sets the most verbose severity sent to remote hosts. Use debugging only for a short, controlled capture, because debug output can be very high volume. MobiObs parses the Cisco %FACILITY-SEVERITY-MNEMONIC tag and sequence numbers (service sequence-numbers) if you enable them.

To create a message on demand, use send log 6 "MobiObs test" in privileged EXEC mode where your release supports it, or simply enter and leave configuration mode, which logs %SYS-5-CONFIG_I.

Flexible NetFlow (v9 or IPFIX)

Flexible NetFlow needs a record, an exporter and a monitor applied to an interface. A user-defined record works on routers and on Catalyst 9000 switches, which do not accept every predefined record.

IOS XE 17.x: Flexible NetFlow to udp/2055

flow record MOBIOBS-REC
 match ipv4 source address
 match ipv4 destination address
 match ipv4 protocol
 match transport source-port
 match transport destination-port
 match interface input
 collect counter bytes long
 collect counter packets long
 collect timestamp absolute first
 collect timestamp absolute last
!
flow exporter MOBIOBS
 destination 10.20.4.9
 source Loopback0
 transport udp 2055
 export-protocol netflow-v9
 template data timeout 60
!
flow monitor MOBIOBS-MON
 exporter MOBIOBS
 record MOBIOBS-REC
 cache timeout active 60
!
interface GigabitEthernet1/0/1
 ip flow monitor MOBIOBS-MON input

For IPFIX, use export-protocol ipfix; MobiObs decodes both on the same port. template data timeout 60 resends the template every minute, so MobiObs can decode flows within a minute even if it started after the exporter. cache timeout active 60 exports long-lived flows every minute rather than waiting for the default of 30 minutes.

SNMP traps (v2c and v3)

IOS / IOS XE: SNMPv2c traps to udp/1162

snmp-server community MOBIOBS-RO RO
snmp-server trap-source Loopback0
snmp-server enable traps snmp authentication linkdown linkup coldstart warmstart
snmp-server host 10.20.4.9 version 2c MOBIOBS-RO udp-port 1162

Use a community string other than public, and enter the same string in MobiObs so that traps pass its community check. Traps that fail the check are still shown, flagged, so a mismatch is easy to spot.

IOS / IOS XE: SNMPv3 authPriv traps

snmp-server group MOBIOBS-GRP v3 priv
snmp-server user mobiobs MOBIOBS-GRP v3 auth sha AuthPass-change-me priv aes 128 PrivPass-change-me
snmp-server host 10.20.4.9 version 3 priv mobiobs udp-port 1162

Add the same user name, authentication and privacy protocols and passwords as an SNMPv3 user in MobiObs (a Pro feature). For traps, the router is the authoritative engine; show snmp engineID displays its engine ID if you need it. SNMPv3 users do not appear in the running configuration, so note the passwords before you leave.

Verify on the device

IOS / IOS XE: show commands

show logging | include 10.20.4.9
show flow exporter MOBIOBS statistics
show flow monitor MOBIOBS-MON cache
show snmp host
show snmp user

show logging lists the remote host with its message counters, and the exporter statistics show packets sent. If the counters rise but nothing appears in MobiObs, the problem is on the path: check routing, ACLs and client isolation using the troubleshooting checklist. The Sources screen in MobiObs lists every address it has received from.

NX-OS notes

Nexus switches use different keywords and usually reach the collector through the management VRF. NetFlow is only available on some Nexus 9000 and 7000 hardware, while sFlow is more widely supported. Check the feature matrix for your platform and NX-OS release.

NX-OS 9.3 / 10.x: syslog, sFlow and traps

logging server 10.20.4.9 6 port 5514 use-vrf management
!
feature sflow
sflow collector-ip 10.20.4.9 vrf management
sflow collector-port 6343
sflow agent-ip 192.0.2.10
sflow sampling-rate 4096
sflow data-source interface ethernet 1/1
!
snmp-server host 10.20.4.9 traps version 2c MOBIOBS-RO udp-port 1162
snmp-server host 10.20.4.9 use-vrf management

The 6 after the server address is the severity (informational). sflow agent-ip must be an address configured on the switch. For NetFlow on supported hardware, enable feature netflow and build an exporter, record and monitor as on IOS XE, with destination 10.20.4.9 use-vrf management and version 9 in the exporter.

Remove it afterwards

IOS / IOS XE: clean-up

interface GigabitEthernet1/0/1
 no ip flow monitor MOBIOBS-MON input
!
no flow monitor MOBIOBS-MON
no flow exporter MOBIOBS
no flow record MOBIOBS-REC
no logging host 10.20.4.9 transport udp port 5514
no snmp-server host 10.20.4.9 version 2c MOBIOBS-RO
no snmp-server host 10.20.4.9 version 3 priv mobiobs
no snmp-server user mobiobs MOBIOBS-GRP v3
no snmp-server group MOBIOBS-GRP v3 priv

The monitor must be removed from interfaces before it can be deleted. Remove the community too if you created it only for this visit, and save the configuration (copy running-config startup-config) only once the device is back to its intended state. On NX-OS, prefix the same lines with no and run no feature sflow if sFlow was not in use before.