Network Management

Discard syslogs in Syslog Viewer

This page provides a quick guide on how to discard syslogs in Syslog Viewer.

First published date

11/29/2018 10:48 PM

Last published date

6/20/2023 7:06 PM

Overview

A quick guide on how to discard syslogs in Syslog Viewer. Learn more about working with syslogs in Network Performance Monitor (NPM).

Product section

Network Performance Monitor

Cause

Too may syslogs being sent to the SolarWinds server.

Resolution

  1. Stop Orion Syslog Service. This stops the syslog table from growing again.
  2. Edit your Syslog Retention Settings to keep Syslogs for x Days. Also, adjust the severity levels for the Syslog output on your devices to Warning or above.
    • For 2019.4 and earlier:
      1. Go to "Settings" > "Polling Settings" under the  "Thresholds & Polling" heading.
      2. Scroll down to "Database Settings" and look for "Syslog Message Retention".
      3. Adjust the retention settings (2 days by default).
    • For 2019.4 and later versions::
      1. Go to your Orion Web Console.
      2. Go to Settings > All Settings > Log and Event.
      3. Adjust Syslog or Traps to default which is 7 or lower if possible.
  3. Disable sending of Syslog messages on your device.
  4. Syslog message comes to Orion Syslog Service. You can use rules/filters from Syslog Viewer to determine whether you want to store the syslog message in the database or discard it.

You can check the severity of syslogs here

Make sure that all rules that are set up to “Discard messages” also contain the line "Stop processing syslog rules". The Syslog and Traps filters/rules work very differently than the Orion Alerting Engine. Each time a syslog message or trap is received it will work through every rule, from the top, until it either gets to the end or hits a rule that specifically tells it to "stop processing rules".

To Discard Syslog Messages:

  1. Open Syslog Viewer (by default C:\Program Files (x86)\SolarWinds\Orion).
  2. Go to File > Syslog Server settings > Alert/Filter Rules Tab.

In here you can filter using various methods: by IP address, by Message Type Patterns, Syslog Message Patterns, Severity, etc.

Add the following Alert Actions to your Rule: "Discard Syslog Message" and "Stop processing syslog rules"

"Stop processing syslog rules" rearranges the Syslog Rules so that the ones that filter and discard messages are at the top of the list. This will ensure that they are processed first.