Remote syslog server flooded with debug messages regardless of severity level selected in log settings

  • 1
  • Question
  • Updated 2 years ago
I set up a Splunk server to index syslog messages from a SmartZone 100. I enabled syslogs in the Smartzone Web GUI and immediately started getting about 5000 messages per minute.  This continues even if I set the minimum severity level to critical.  

Example message:
...sshd[26692]: debug1: connect_next: host localhost ([]:514) in progress, fd=8
It seems like it's sending debug messages and ignoring the log severity setting in the GUI.  I have also tried setting this in the CLI but there was no difference in behavior.

Has anyone had a similar experience?  At the current rate, I will exhaust my Splunk license.  I need to be able to filter out these debug messages.   
Photo of Robert Nattoo

Robert Nattoo

  • 1 Post
  • 0 Reply Likes
  • frustrated

Posted 2 years ago

  • 1
Photo of Ravi Teja

Ravi Teja, Employee

  • 11 Posts
  • 1 Reply Like
Hi Robert,

What version of software is running on SZ100 ?
We have come across this issues before and we do have KSP patch available to address this. Request you to log a ticket with Ruckus Support Team for the patch file.

Ravi Teja