Network Management

Configure Real-time Configuration Change Detection Based on Syslog Messages

This article shows a simplified procedure in configuring Real-time Configuration Change Detection based on Syslog in NCM.

First published date

10/12/2018 5:11 PM

Last published date

11/7/2022 2:12 AM

Overview

This article shows a simplified procedure in configuring Real-time Configuration Change Detection based on Syslog in NCM.

For more detailed information, see Configure real-time change detection in the NCM Administrator Guide.

Product section

Network Configuration Manager

Cause

n/a

Resolution

Any device desired to be monitored by NCM Real-Time Change Detection (RTCD), must be configured to send Syslog or Trap messages relevant to when a user leaves from a configuration mode to your Orion server. 

The following is an example for most Cisco IOS devices and using the Legacy Orion Syslog Viewer

  1. Go to Start > All Programs > SolarWinds > Syslog and SNMP Traps > Syslog Viewer.
  2. Verify Syslog messages are being received by the Syslog Viewer relevant to a configuration modification.

    For example, a Cisco IOS device will send a SYS-5-CONFIG_I Message Type when a user exits config mode.

    The Message should contain *configured from console*.

  3. Enable NCM Rule: Cisco IOS Realtime Change Notifications by going to Syslog Viewer > View > Alerts/Filter Rules.
  4. Go to Web Console > Settings >  NCM Settings > Configure Real-Time Change Detection and complete the rest of the steps regarding email notifications and SMTP server.
  5. Verify if RTCD/RTN is enabled.
  6. Modify a configuration on one of your devices and check whether the change detection works. When a change is detected, aside from getting email notifications, you should be able to see new entries on the Last X Config Changes resource on the NCM Config summary page.
  7. If Email is set up to send if the event a change is detected, an email will only be sent if there is a change detected and is not a validation the rule was successful.
Note the user's name\account who made the configuration change would normally be sent from the device within the Syslog message. NCM does not provide this information but will only display this if the device sends the username/account that made the change.