show logging

Displays the syslog messages in the device local buffer.
Syntax
show logging
Modes

User EXEC mode

The show logging command displays the following information.

Output field Description
Syslog logging The state (enabled or disabled) of the Syslog buffer.
messages dropped The number of Syslog messages dropped due to user-configured filters. By default, the software logs messages for all Syslog levels. You can disable individual Syslog levels, in which case the software filters out messages at those levels. Each time the software filters out a Syslog message, this counter is incremented.
flushes The number of times the Syslog buffer has been cleared by the clear logging command or equivalent ICX Web Management Interface option.
Static log buffer A fixed-size buffer that retains logs until the buffer is full. Once capacity is reached, older logs are overwritten.
Dynamic log buffer A flexible log buffer that adjusts its size based on system activity and available resources.
overruns The number of times the dynamic log buffer has filled up and been cleared to hold new entries. For example, if the buffer is set for 100 entries, the 101st entry causes an overrun. After that, the 201st entry causes a second overrun.
level The message levels that are enabled. Each letter represents a message type and is identified by the key (level code) beneath the value. If you disable logging of a message level, the code for that level is not listed.
messages logged The total number of messages that have been logged since the software was loaded.
level code The message levels represented by the one-letter codes.
Examples

The following is a sample output from the show logging command.

device# show logging

    Syslog logging: enabled ( 0 messages dropped, 0 flushes, 0 overruns)
        Buffer logging: level ACDMEINW, 5 messages logged
        level code: A=alert C=critical D=debugging M=emergency E=error
    I=informational N=notification W=warning

    Static Log Buffer:
    Mar 07 15:14:42:I:System: Stack unit 1   Power supply 2  is up

    Dynamic Log Buffer (4000 lines):
    Mar 07 15:18:48:I:conf_archive:Succeeded to full revert
    Mar 07 15:18:47:I:conf_archive:Revert due to revert timeout
    Mar 07 15:17:40:A:Startup Config Parsing Returned Error. Please verify the system configuration.
    Mar 07 15:14:48:I:System: Interface ethernet mgmt1, state up
    Mar 07 15:14:42:I:System: Stack unit 1   Power supply 2  is up
    ICX7850-48FS Router#
The following example shows the ICX syslog messages generated when the OS configuration mode is entered for password recovery by executing commands such as reset_login, erase-startup-config, copy, and reboot. These log messages are generated with a severity level of “Warning” and are also displayed on the management platform for this device (specifically, the Events page of the RUCKUS One or SmartZone web UI). Syslog messages are not generated when an administrator enters the OS mode of a standby or member unit in a stacking setup.
device(config)# show logging

Sep 11 17:10:56:W:os_shell: Security: User executed erase_startup_config command in OS mode.
Sep 11 17:10:46:W:os_shell: Security: User entered into OS mode.
Sep 11 17:10:24:W:os_shell: Security: User executed reset_login command in OS mode.
Sep 11 17:10:05:W:os_shell: Security: User entered into OS mode.
Sep 11 17:10:00:I:Security: console login by super to PRIVILEGED EXEC mode
Sep 11 17:10:00:I:Security: console login by super to USER EXEC mode
The following example shows syslog messages with authentication attempts and failures on the switch. Log messages for login failures across TELNET, SSH, and Console sessions has now been changed from "Informational" to a severity level of "Warning" and are also displayed on the device's management platform (specifically, the Events page of the RUCKUS One or SmartZone web UI).
device(config)# show logging

Sep 11 05:48:35:W:login: TELNET access by user super rejected for incorrect login
Sep 11 05:47:09:I:Security: console login by super to PRIVILEGED EXEC mode
Sep 11 05:46:45:I:Security: console login by super to USER EXEC mode
Sep 11 05:44:51:W:login: Console access by user super failed
device(config)# show logging

Sep 11 05:48:26:W:sshd-session: SSH access by user super from src IP 10.246.201.89 rejected, 1 attempt(s)
Sep 11 05:48:22:W:sshd-session: Failed publickey SSH access by user super from 10.246.201.89
The following sample shows output from the show logging command when the RFC 5424 format has been enabled.
device(config)# show logging
Syslog logging: enabled (RFC: 5424, 0 messages dropped, 1 flushes, 0 overruns)
    Buffer logging: level ACDMEINW, 12 messages logged
    level code: A=alert C=critical D=debugging M=emergency E=error
I=informational N=notification W=warning

Dynamic Log Buffer (4000 lines):
2023-10-31T19:11:45Z:I: ruckuswireless.com device ICX7850_Router - General [meta sequenceId=12] BOM MGMT Agent: Failed to connect to network controller at 10.177.86.160 Error:  
2023-10-31T19:09:10Z:I: ruckuswireless.com device ICX7850_Router - System [meta sequenceId=11] BOM COPY COMPLETED 
2023-10-31T19:09:10Z:I: ruckuswireless.com device ICX7850_Router - System [meta sequenceId=10] BOM Security: startup-config was changed  
2023-10-31T19:09:10Z:I: ruckuswireless.com device ICX7850_Router - System [meta sequenceId=9] BOM COPY_CONFIGURATION_TO_FLASH 
2023-10-31T19:09:10Z:I: ruckuswireless.com device ICX7850_Router - General [meta sequenceId=8] BOM Security: startup-config was changed by super from CONSOLE
.
.
.
History
Release version Command history
09.0.10 The output of this command was modified to include details for Configuration Archive and Replace configurations.