CISCO-SYSLOG-MIB

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCISCO-SYSLOG-MIB

Organization: Cisco Systems, Inc.

Last Updated: 2005-12-03

Category: Alarm and Event Management, Cisco Devices, Device Management

Description: Covers syslog message history, severity-based filtering, and remote syslog server destinations on Cisco devices.

IPNetwork Monitor uses several OIDs from this MIB in network discovery and polling the applicable devices. Start monitoring CISCO-SYSLOG-MIB with a free 30-day trial of IPNetwork Monitor.

What Is CISCO-SYSLOG-MIB?

CISCO-SYSLOG-MIB is a Cisco enterprise MIB that manages and exposes system log (syslog) message history, severity filtering, and notification behavior on Cisco IOS and other Cisco OS devices. It provides objects for configuring maximum logged severity, history table size, counts of ignored/dropped messages, and a history table of recent syslog entries with sequence indices. It is used to monitor software/system status indirectly by tracking log message volume and integrity — dropped/ignored message counts reveal if the device is overwhelmed and discarding log messages, and the history table lets an admin review recent system events, which often report hardware faults, interface flaps, or configuration changes, without needing external syslog infrastructure. It complements Cisco's standard notification/trap infrastructure for sending syslog-triggered SNMP traps. It is deployed across Cisco routers and switches in enterprise and service-provider networks for centralized event/fault visibility via SNMP. Engineers searching vendor documentation for cisco-syslog-mib object definitions will find clogHistoryTable and its associated severity/drop counters are the primary objects of interest for SNMP-based log monitoring.

IPNetwork Monitor allows you to monitor SNMP objects defined in CISCO-SYSLOG-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • Cisco Catalyst 9300 Series — current flagship stackable access switch running IOS-XE, still receiving active software support into 2026

Monitoring Examples

An admin polls clogHistoryTable/clogHistoryEntry (indexed by clogHistIndex) to review recent syslog messages captured by the device, and checks clogMsgDrops/clogMsgIgnores to detect if messages are being lost due to rate limiting. clogMaxSeverity controls which severities are forwarded via SNMP notifications, and clogNotificationsSent/clogNotificationsEnabled confirm whether syslog-triggered SNMP traps are actively being generated, useful for validating alerting pipelines.

What Can Be Monitored

  • syslog history messages
  • max severity threshold
  • dropped/ignored message counts
  • notifications sent count
  • history table size and flush count
  • origin ID configuration
Imported Objects

From CISCO-SMI

ciscoMgmtOBJECT-IDENTITY

From INET-ADDRESS-MIB

InetAddress
InetAddressType

From SNMP-FRAMEWORK-MIB

SnmpAdminString

From SNMPv2-CONF

MODULE-COMPLIANCE
NOTIFICATION-GROUP
OBJECT-GROUP

From SNMPv2-SMI

Counter32
Integer32
MODULE-IDENTITY
NOTIFICATION-TYPE
OBJECT-TYPE
Unsigned32

From SNMPv2-TC

DisplayString
RowStatus
TEXTUAL-CONVENTION
TimeStamp
TruthValue
OIDs

RFC description

Manages syslog message history, severity filtering, and remote syslog server destinations on Cisco devices.

Start monitoring Cisco Catalyst 9300 series switch (syslog) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download CISCO-SYSLOG-MIB