Posted on December 22, 2018 11:47 pm
 |  Asked by victor lin
Print Friendly, PDF & Email

Dear support,
we are using Infoblox NetMRI to capture NetWork device’s configuration , here is the process path:
device send syslog when it’s configuration changed > syslog server receive this message and forward to NetMRI > NetMRI will start capture device changed config.

below is logging related config from my Arista device, could you please let me know what need to be added so Arista can send syslog when configuration changed ?
logging level PWRMGMT errors
logging level QOS errors
logging level QUEUEMONITOR errors
logging level REDUNDANCY errors
logging level ROUTING errors
logging level SAND errors
logging level SPANTREE errors
logging level STRATA errors
logging level SYS errors
logging level SYSDB errors
logging level TRANSCEIVER errors
logging level VM errors
logging level VMTRACERSESS errors
logging level VRRP errors
logging level ZTP informational
Thank you very much!

Posted by Gerry
Answered on December 24, 2018 12:37 pm

Hi Victor:

write running-config into startup-config that generate %SYS-5 log message,
so you need to change “logging level SYS” to informational

logging level SYS informational

Dec 24 20:26:15 DUT1 ConfigAgent: %SYS-5-CONFIG_STARTUP: Startup config saved from system:/running-config by admin on vty3 (


Happy New Year Gerry!
Thank you so much for your expertize! sorry for the late replay, I have been taking vacation .
is it possible to add more detail after command , like “logging level SYS informational Config” ?
also what is the Arista command to setup device send syslog as snmp trap to monitoring tools ?

Best regards,

(victor lin at December 31, 2018 4:31 pm)
Posted by victor lin
Answered on December 31, 2018 4:05 pm

Happy New Year Gerry :-)
Thank you so much for your expertize!!!!!
sorry for the late reply! I have been taking vacation
is it possible to add more detail in “logging level SYS informational”, I meaning add SYS-5-CONFIG
also my engineer for Arista mentioned they have enabled syslog to trap ( sending syslog as trap to network monitoring tools) , but I am not sure which command been used for configuration ( I am able to see the configuration, didn’t find “logging trap system…” ) , could you please let me know if there is another command?
just want to make sure the logging level change not causing event flooding to my monitoring tool

Thanks again!

Posted by Gerry
Answered on April 26, 2019 11:07 am

Hi Victor:

I think the following commands should achieve your need.
aaa accounting commands all default start-stop logging
logging host x.x.x.x

command logging:
Apr 26 19:01:22 Leaf-7060CX-2 Aaa: %ACCOUNTING-6-CMD: admin vty3 stop task_id=14 start_time=1556276482.38 timezone=CST service=shell priv-lvl=15 cmd=show version
Apr 26 19:01:29 Leaf-7060CX-2 Aaa: %ACCOUNTING-6-CMD: admin vty3 stop task_id=15 start_time=1556276489.06 timezone=CST service=shell priv-lvl=15 cmd=show ip interface brief

Apr 26 19:01:41 Leaf-7060CX-2 Aaa: %ACCOUNTING-6-CMD: admin vty3 stop task_id=16 start_time=1556276501.41 timezone=CST service=shell priv-lvl=15 cmd=show arp


Post your Answer

You must be logged in to post an answer.