When configured as a syslog server, {{page.adm-product-name-short}} receives all syslog messages from the configured Citrix Application Delivery Controller ({{page.citrix-adc-generic}}) instances. There might be many messages that you might not want to see. For example, you might not be interested in seeing all the informational-level messages. You can now discard some of the syslog messages that you are not interested in. You can suppress some of the syslog messages coming into {{page.adm-product-name-short}} by setting up some filters. {{page.adm-product-name-short}} drops all messages that match with the criteria. These dropped messages do not appear on the {{page.adm-product-name-short}} GUI and these messages are also not stored in the customer's {{page.adm-product-name-short}} database.
You can suppress some of the logged syslog messages coming into {{page.adm-product-name-short}} by setting up some filters. The two filters that can be used for suppressing syslog messages are severity and facility. You can also suppress messages coming from a particular {{page.citrix-adc-generic}} instance or multiple instances. You can also provide a text pattern for {{page.adm-product-name-short}} to search and suppress messages. {{page.adm-product-name-short}} drops all messages that match with the criteria. These dropped messages do not appear on the {{page.adm-product-name-short}} GUI and these messages are also not stored in the customer database. Therefore, a good amount of space is saved on the storage server.
Some use cases for suppressing syslog messages are as follows:
-
If you want to ignore all information level messages, suppress level 6 (informational)
-
If you only want to record firewall error conditions, suppress all levels other than level 3 (errors)