mediumMultiple Select
Syslog Message Delivery Failure Troubleshooting — Common Causes and Solutions
Which TWO symptoms indicate that syslog messages are not being sent to the remote syslog server? (Choose TWO.)
⚠ Common exam trap
The trap is confusing local logging symptoms with remote syslog symptoms; candidates may pick options that only indicate local logging is working or not working, rather than focusing on remote syslog configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The syslog server receives messages from other devices but not from this router.
Option B is correct because if the remote syslog server is receiving messages from other devices but not from this specific router, it directly indicates that this router's syslog messages are not reaching the server, isolating the fault to the router's logging configuration or connectivity. Option D is correct because the 'show logging' output includes a 'Logging to' section that lists configured remote syslog hosts; if the syslog server's IP address is absent there, no remote logging destination is configured, so messages cannot be sent to it. Option A does not indicate a problem, since messages appearing in the local buffer is normal and can coexist with successful remote logging. Option C is not a valid symptom because 'show log' is not a standard Cisco IOS command for verifying syslog destinations, and no output would not specifically prove remote syslog failure. Option E is not a reliable indicator because debug output appearing on the console is expected behavior and does not by itself show that syslog messages are failing to reach the remote server.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The 'show logging' command shows messages in the local buffer.
Why it's wrong here
Local buffer entries only prove the device generated and stored messages locally; they say nothing about remote delivery, which depends on the logging host and trap level. Tempting because buffered logging is configured alongside remote syslog, but it is the correct symptom when verifying local logging works.
- ✓
The syslog server receives messages from other devices but not from this router.
Why this is correct
The server accepting messages from other devices proves the collector, network path and port are functional, isolating the fault to this router's logging configuration. This satisfies the stem's requirement for a symptom indicating messages are not being sent from this specific device, rather than a server-side or transport failure.
- ✗
The 'show log' command returns no output.
Why it's wrong here
An empty 'show log' output reflects the local logging buffer, not remote transmission; messages may still reach the syslog server. It is tempting because no output suggests logging is broken, but this command is the right check when diagnosing local buffer or console logging issues.
- ✓
The 'show logging' output does not list the syslog server IP address under 'Logging to'.
Why this is correct
The 'Logging to' section of `show logging` lists every configured remote destination. If the syslog server's IP address is absent there, no remote host is configured, so messages cannot leave the device regardless of severity or source-interface settings. This directly satisfies the stem's requirement for a symptom proving remote syslog delivery is not occurring.
- ✗
Debug output appears on the console but not on the syslog server.
Why it's wrong here
Debug output reaching the console proves the logging process itself runs, but console logging and remote syslog destination are configured independently, so this symptom alone does not confirm remote delivery failure. It tempts because console output is often assumed to mirror syslog transmission, yet it would be the correct indicator only when verifying local logging severity levels.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.