I work for a company that has thousands of Adtran devices deployed in the network and we offer a very robust Managed Router service option to many customers.
Most of our devices need to have "ip firewall" turned on due to using "ip ffe" and what we as repair technicians are running across is that our router logs are being filled with relatively unimportant log entries about TCP sessions transferring zero packets which pushes out earlier entries that would give us historical reference to any service issues that a customer may bring up.
I have enabled event-logging to report only priority 2 and higher log entries which has decreased the number of entries, but I still have priority 1 firewall entries that fill the log up daily so we can't see any historical log information.
Due to the private nature of MPLS with these devices, we are unable, at this time, to setup a syslog server for many of our circuits so I was wondering if there is another option to filter the firewall events specifically?
Any assistance is greatly appreciated.
By the way, this is in the 4000 section because that is the current router model that I am working with to try and figure something out.
Could you reply to this thread with your current configuration? (Please remember to remove any sensitive information). Also, I assume you are viewing the events in the event log of the router. If this is not correct, please let us know.
By setting the priority level to 2, you should not see any event messages that are of a priority level less than 2. However, we can filter event messages by anything else other than by setting the lowest priority level you wish to be supported.
Let us know if you have any questions.
I went ahead and flagged "Assumed Answered" on this post to make it more visible and help other members of the community find solutions more easily. If you feel like there is a better answer, feel free to come back to this post and select it with the applicable buttons. If you have any additional information on this that others may benefit from, please come back to this post to provide an update. If you still need assistance, we would be more than happy to continue working with you on this - just let us know in a reply.