本文转自:http://hebe852.blog.163.com/blog/static/1207262482009525105613778/

本想把保存在思科交换机上的log buffer里的日志级别改一下,但确发现对facility 和trap的区别不太理解,所以在网上找到了以下的配置,根据以下的配置,我的理解是facility是可以自已定义的,发往syslog的,比如交换机 A可以设置成local0 交换机B可设置成local1 这样在日志服务器上便于区分是哪台交换机发来的日志,可能还有别的方面的用途。而trap控制交换机发出的日志级别。保存在log buffer里的日志级别通过别的命令设置。
logging facility local0          //配置日志存储的facility ,默认是local7,可以修改为其他,但推荐保存为local开头的facility里
logging trap debugging      //配置要发送到日志服务器的日志优先级,默认发送到日志服务器的优先级为Info

CISCO—SWITCH#show logging
Syslog logging: enabled (0 messages dropped, 45 messages rate-limited, 0 flushes
, 0 overruns)
Console logging: level debugging, 226 messages logged
Monitor logging: level debugging, 0 messages logged
Buffer logging: level debugging, 271 messages logged
Exception Logging: size (4096 bytes)
File logging: disabled
Trap logging: level informational, 274 message lines logged
Logging to 172.16.5.104, 274 message lines logged

Log Buffer (4096 bytes):
我发现命令
CISCO—SWITCH(config)#logging buffered ?
<0-7>              Logging severity level
<4096-2147483647>  Logging buffer size
alerts             Immediate action needed           (severity=1)
critical           Critical conditions               (severity=2)
debugging          Debugging messages                (severity=7)
emergencies        System is unusable                (severity=0)
errors             Error conditions                  (severity=3)
informational      Informational messages            (severity=6)
notifications      Normal but significant conditions (severity=5)
warnings           Warning conditions                (severity=4)
<cr>
在些处可设备存在buffer里的日志的级别