Q65Security
Which configuration prevents DOT1X messages in the format below from being sent to Syslog server `10.15.20.33`? `Nov 20 13:47:32/553 %DOT1X-5-FAIL:Authentication failed for client (e04f.438e.de4f) on interface Gi1/0/1 AudtiSessionID 0A0B50A5000004543910739E`
← → navigate · a answer
Community votes
Discussion · 11
A 5
Selected Answer: A
The syslog message "Nov 20 13:47:32/553 %DOT1X-5-FAIL:Authentication failed for client (e04f.438e.de4f) on interface Gi1/0/1 AudtiSessionID 0A0B50A5000004543910739E," includes these fields:
Nov 20 13:47:32/553 --> Timestamp (date & time)
%DOT1X --> Facility Code (always start with the '%' sign)
5 --> Severity (0-7)
FAIL --> mnemonics (categorizes the event within the facility code)
"Authentication failed for client (e04f.438e.de4f) on interface Gi1/0/1 AudtiSessionID 0A0B50A5000004543910739E" --> message-text (condition of the vent that triggered the system message)
"drops" keyword ---> used to drop the message that matches the pattern specified by the discriminator
"logging host 10.15.20.33 discriminator DOT1X" ---> assigns the discriminator with a Syslog server @ 10.15.20.33
A 4
Selected Answer: A
filters out facility=DOT1X messages and drops those
A 3
Selected Answer: A
Given answer is wrong. The message body doesn't have "DOT1X". However the logging facility is "DOT1X", so A seems right.
https://youtu.be/Lbb7vlQoGt0?feature=shared&t=154
A 3
Selected Answer: A
logging discriminator DOT1X facility drops DOT1X: This command creates a logging discriminator named "DOT1X" and sets it to drop syslog messages with the facility "DOT1X". So, any syslog messages with the facility "DOT1X" will be dropped (not logged).
logging host 10.15.20.33 discriminator DOT1X: This command says that syslog messages matching the criteria defined by the "DOT1X" discriminator are sent to the syslog server at the IP address 10.15.20.33. So, syslog messages that make it through the "DOT1X" discriminator (i.e., not dropped by the first command) will be sent to the specified syslog server.
3
DOT1X-5-FAIL:
facility: dot1x
severity: 5
mnemonic: fail
seq no:timestamp: %facility-severity-MNEMONIC:description
A 2
Selected Answer: A
A. logging discriminator DOT1X facility drops DOT1X
logging host 10.15.20.33 discriminator DOT1X
Explanation:
The logging discriminator command creates a discriminator named DOT1X.
The facility drops DOT1X part says that messages with a facility that includes DOT1X should be dropped.
The logging host 10.15.20.33 discriminator DOT1X command sends log messages to the Syslog server at 10.15.20.33, but only those that do not match the discriminator criteria (i.e., excluding DOT1X messages).
2
https://www.pearsonitcertification.com/articles/article.aspx?p=1636219
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/esm/command/esm-cr-book/esm-cr-a1.html#wp1888787448
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/esm/configuration/xe-16-12/esm-xe-16-12-book/reliable-del-filter.html#GUID-87920FBF-24C3-4D50-801F-1E0FAAFE7297
https://mrncciew.com/2013/07/27/suppress-a-syslog-msg/
1
I think the correct answer should be A).
logging discriminator DOT1X facility drops DOT1X
logging host 10.15.20.33 discriminator DOT1X
A 1
Selected Answer: A
I think it should be A
A 1
Selected Answer: A
Logging discriminator discr-name [ [facility] [mnemonics] [msg-body] { drops string | includes string } ] [ severity { drops sev-num | includes sev-num } ] [ rate-limit msglimit ]
A 1
Selected Answer: A
A is the correct answer