Remote syslog server flooded with debug messages regardless of severity level selected in log settings

  • 1
  • Question
  • Updated 3 months ago
I set up a Splunk server to index syslog messages from a SmartZone 100. I enabled syslogs in the Smartzone Web GUI and immediately started getting about 5000 messages per minute.  This continues even if I set the minimum severity level to critical.  

Example message:
...sshd[26692]: debug1: connect_next: host localhost ([127.0.0.1]:514) in progress, fd=8
It seems like it's sending debug messages and ignoring the log severity setting in the GUI.  I have also tried setting this in the CLI but there was no difference in behavior.

Has anyone had a similar experience?  At the current rate, I will exhaust my Splunk license.  I need to be able to filter out these debug messages.   
Photo of Robert Nattoo

Robert Nattoo

  • 1 Post
  • 0 Reply Likes
  • frustrated

Posted 3 months ago

  • 1
Photo of Ravi Teja

Ravi Teja, Employee

  • 7 Posts
  • 1 Reply Like
Hi Robert,

What version of software is running on SZ100 ?
We have come across this issues before and we do have KSP patch available to address this. Request you to log a ticket with Ruckus Support Team for the patch file.

Regards
Ravi Teja