Syslog is a method of logging router activity. When enabled, the router continuously outputs syslog event messages; these can be captured by a syslog daemon (a listening/capturing program) and displayed or logged to a file.
The latest version of the DrayTek Syslog Utility can be downloaded here. It is a standalone application that does not require installation. It can be set to on startup (runs as an application, not a service). Syslog output from the router is in a standard format and can be captured with other Syslog applications if required.
Syslog has many different methods to collect logs from the router; sent locally (stored in a log file or a database), stored on USB storage connected to the router or sent over the internet.
This uses UDP Port 514 by default, which needs to be allowed through any software firewalls if sending to a PC, or forwarded through NAT if forwarding syslog over the internet.
| Sending Syslog to a PC - Log File | This is recommended for quick diagnostics or investigating configuration issues, for instance determining which rule in the firewall is blocking traffic. This can be used to record syslog messages from multiple routers and access points. |
| Sending Syslog to a PC - Database | This can be used for collecting log information from the router over a longer period of time. The Database can be loaded into the DrayTek Syslog Utility to read the contents. This records syslog messages from a single router. |
| Storing Syslog via USB Storage | This can be used for collecting log information from the router over a longer period of time and makes reading the logs remotely more easily possible. This stores log files in text format that can be loaded in the Syslog Utility. |
| Web Syslog | This can be used to view recent syslog messages from the router. It can be useful for quick diagnostics when accessing the router remotely. |
{tab Sending Syslog to a PC - Log File}
Go to [System Maintenance] > [Syslog / Mail Alert Setup] to enable the Syslog access and click OK to apply the setting.
a. Check the Enable state.
b. Check the Syslog Server state so that the router will send Syslog messages to an IP address.
c. Enter the Server IP Address as the IP of your computer. The server IP address can be a local IP or remote IP/Host name.
The router will begin to send syslog messages as soon as the OK button is clicked.

Now the PC needs to be set up to save the syslog messages. Launch the Syslog Utility on your computer, it should show the router's IP in d., if it does not, check whether the Windows Firewall is blocking UDP port 514 and make sure that either the application or that traffic is unblocked. Also check whether any other utilities on the computer could be using that port, if they are, that will also stop syslog from working.
a. Click this icon to set up Syslog to save a log file.
b. Click this icon to set up Syslog to save logs to a database.
c. Click this icon to search the database that the utility has saved or open a syslog database file.
d. Select the router's IP, if there are multiple routers that the computer is receiving syslog from.
e. Select the WAN interface to show details for each WAN interface.
Click on the button marked a. to save the log file output.

That will pop-up a window to set how the log files are saved:

a. Select the saving mode:
Save current log to a file - This will save the currently displayed content of the Syslog utility's logs to a file. This is recommended for short logs, because the utility will not save syslog entries that are no longer displayed in the utility.
Record log to a file in real time - This will save the log file as a single file for as long as the record time limit is set to. If No Record Time Limit is set, it will log until the utility is closed or the Stop button is pressed, the Stop button will appear in the utility when this log saving method is active.

Record log to multiple files - This will save the syslog output to multiple files depending on the Save to a file every (x) Hours setting, which will make a new log file every (x) hours. It will record for as long as the Record Time Limit is set to. If No Record Time Limit is set, it will log until the utility is closed or the Stop button is pressed, the Stop button will appear in the utility when this log saving method is active.
Selecting Auto Launch will make the DrayTek Syslog utility start when the computer starts up, once a user logs in to the computer.

Set the Log File name location manually or click the "..." box to the right of it to specify the location.
Click OK to start the logging, the pop-up window will close and if the utility is set to Record log to a file in real time or Record log to multiple files, the utility will show a Stop button in place of the Save button icon. Clicking the Stop button will stop the log file from continuing to save.
{tab Sending Syslog to a PC - Database}
Go to [System Maintenance] > [Syslog / Mail Alert Setup] to enable the Syslog access and click OK to apply the setting.
a. Check the Enable state.
b. Check the Syslog Server state so that the router will send Syslog messages to an IP address.
c. Enter the Server IP Address as the IP of your computer. The server IP address can be a local IP or remote IP/Host name.
The router will begin to send syslog messages as soon as the OK button is clicked.

Now the PC needs to be set up to save the syslog messages. Launch the Syslog Utility on your computer, it should show the router's IP in d. and if it does not:
- Check whether the Windows Firewall is blocking UDP port 514 and make sure that either the application or that traffic type is unblocked.
- Check for any other utilities on the computer could be using that port, if they are, that will also stop syslog from working. The Windows Resource Monitor displays this information in the [Network] > [Listening Ports] section.

a. Click this icon to set up Syslog to save a log file.
b. Click this icon to set up Syslog to save logs to a database.
c. Click this icon to search the database that the utility has saved or open a syslog database file.
d. Select the router's IP, if there are multiple routers that the computer is receiving syslog from.
e. Select the WAN interface to show details for each WAN interface.
Click on the button marked b. to set up the utility to save to a database.
That will pop-up a window to configure the database log storage:
Tick the Enable Database Record button.
a. From the tickboxes available in this section, select which log types will be saved.
b. Select the router IP that will be recorded.
c. Click the "..." box to set the location that the database will be saved to.
Click OK and the utility will begin saving syslog output to the database location specified.

To view the database logs, from the main window of the Syslog Utility, click button c.

That will pop-up a window to view the database logs with options to select the time period displayed and specify Keywords such as IP addresses or host names:
a. Click Load database to choose the database file.
Set the Start Time and End Time for the intended search period.
b. Click Search Database to search for the specific log entries in the syslog database.

{tab Storing Syslog via USB Storage}
Instead of the router sending syslog message to a PC and running a sylog utility on that PC, some DrayTek router models can store syslog to an attached USB Disk. DrayTek routers with a USB port support this functionality from firmware 3.3.3 and later, check the product specification for your specific model.
Syslogs saved to the router's USB storage can be viewed either by downloading them to a PC or by using the Web Syslog facility in [Diagnostics] > [Syslog Explorer].
USB Syslog Setup
To enable the router to send syslog message to an attached USB Disk instead of an IP Address, enable the checkbox in the [System Maintenance] > [Syslog / Mail Alert Setup] menu. The setting can only be saved if the router has detected that a USB storage device is connected to its USB port. After enabling the setting, the router will create a syslog directory and .log file on the USB disk when it needs to write output to the USB Disk.
The router does not immediately write the output to the USB Disk, it stores in memory first and then, once the log reaches 32KB, it writes the file to the .log file on the USB drive. Once the .log file on the USB drive reaches 1MB, the router will create a new .log with an incremented filename.

{tab Web Syslog}
Go to [Diagnostics] > [Syslog Explorer] to access the web interface syslog functionality. The Web Syslog tab shows the syslog messages that the router generates once it is enabled.
NOTE: Web Syslog has limited storage so for some purposes (for example in-depth diagnostics) the PC syslog is more suitable

The Syslog Type setting corresponds to the different syslog categories, it defaults to User and can be set to display All categories if required.
It has a buffer for the display of messages and the Display Mode is used to set how that is handled:
If it's set to Stop record when full, it will store the messages from when the Web Syslog function is enabled up until the point where the message buffer is full, at which point, it will show no new messages.
If it's set to Always record the new event, the router will continue to display new messages and discard old messages.
The USB Syslog tab shows syslog files stored on the router's USB storage - which needs to be enabled before the router will save messages to that location. This makes it possible to display the contents of stored log files remotely.
This will only show logs that have finished saving i.e. have reached a size of 1024KB/1MB, it has options to select which log is displayed and can limit the display to a specific category:

{/tabs}
Comments
0 comments
Please sign in to leave a comment.