Network Management

Set up real-time change detection in NCM based on syslog

This article describes how to set up Network Configuration Manager (NCM) real-time change detection with syslog messages if you have the SolarWinds Syslog Viewer.

First published date

10/11/2018 6:16 PM

Last published date

7/9/2025 6:00 PM

Overview

This article provides streamlined instructions for setting up NCM real-time change detection using syslog messages and the SolarWinds Syslog Viewer. If you use Log Analyzer or a different syslog server, or if you need more detailed information, see Configure real-time change detection in NCM in the NCM admin guide.

Product section

Network Configuration Manager

Resolution

  1. Configure the devices to send a syslog or trap to the NCM server. Include the source interface with the IP address of the device as it is added to NCM.
  2. Verify that the default rule in the syslog viewer has the correct location of the RTN forwarder. 

    Note: This is generally a good place to check if the application was migrated from one server to another.

  3. Verify that the rule is enabled.
  4. Log in to the SolarWinds Platform Web Console as an administrator.
  5. Click Settings.
  6. Under Product Specific Settings, click NCM Settings.
  7. Click Configure Real-Time Change Detection.
  8. Complete the steps as required.
  9. When completed, click Submit. 
    Not all rules will be applicable to all vendors or devices. It is likely that you will need to create a new rule based on the applicable syslog message from the particular device.