TotalView is designed to be a Syslog Collector.  Syslog needs to be enabled on the TotalView Host and the Devices you want to see syslog information need to be configured to send Syslog data to TotalView:


To Enable Syslog is enabled on the TotalView Server. :

  • Config Tool-> Network -> Syslog Tab
  • Select "Enable Syslog Server"
  • Select "Apply"
  • Service Will restart and you are ready to receive


To Enable Syslog on a Network Devices:

  • Configure the Device to Send Syslog to the TotalView Host:
    • On Cisco or HP from the Console:
    • Logging <IP Address of TotalView Server>
  • Syslog Configuration Varies across manufacturers (Consult Vendor Documentation)
  • Make sure the Syslog Source IP/Interface is the Same IP TotalView is using for SNMP Communications


You can review the syslog message that we do receive from a particular device by Clicking on the "Syslog" link next to the device on the Devices Tab or Opening the Syslog Viewer Application on the TotalView Host. 


Introduced in TotalView 14.2 (r14239) is the ability to change the Syslog Collector Listening Port on the TotalView Server.

(If not already in the Config Tool)

Create Registry Entries:

HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\NetLatency\SwitchMonitor

SyslogPort                     (REG_DWORD)             Decimal Value for New Syslog Listening Port  (Default 514)

SyslogAgentPort           (REG_DWORD)             Decimal Value for Source Port for Syslog Alert  (Default 514) used for Syslog Alerts going Upstream to other Syslog Server (&10.0.0.1 in alerts)

 

Also added the ability to Specify Syslog Listening Port on Syslog Alerts going Upstream  (&10.0.0.1:5141)