A network administrator wants to collect logs from multiple routers and switches to a central server for analysis. Which protocol should be configured on the devices to send logs to the server?
Syslog is a standard protocol specifically designed for sending system log or event messages from network devices to a central server. Routers, switches, and other network components generate various operational messages, security alerts, and error notifications. By using Syslog, administrators can consolidate these diverse messages from multiple sources, enabling centralized log storage, analysis, and monitoring for efficient troubleshooting, security auditing, and compliance reporting.
Why this answer
Syslog (RFC 5424) is the standard protocol for sending event messages (logs) from network devices like routers and switches to a central log server. It uses UDP port 514 by default (or TCP 6514 for reliable delivery) and allows administrators to collect, store, and analyze system messages from multiple devices in one location.
Why the other options are wrong
SNMP is used for monitoring and managing network devices by polling or receiving traps, but it is not designed to collect and forward detailed log messages to a central server; syslog is the standard protocol for log collection.
NetFlow is designed for network traffic flow analysis and accounting, not for sending event logs from devices to a central server. It collects metadata about IP traffic flows, not system or event messages.
TFTP is a file transfer protocol used for transferring configuration files or firmware images, not for streaming log messages. It lacks the necessary mechanisms for reliable, timestamped log delivery.
When would these options actually be correct?
A network administrator needs to monitor device health metrics like CPU load and interface errors from routers and switches. Which protocol should be configured to allow a central server to poll these metrics?
A network administrator wants to monitor bandwidth usage and traffic patterns across the network to identify top talkers or detect anomalies. Which protocol should be configured on routers and switches to export traffic flow data to a collector?
A network administrator needs to back up router and switch configuration files to a central server. Which protocol should be used to transfer these files?
Why candidates pick the wrong answer
Candidates may confuse SNMP traps (which can send alerts) with syslog's log forwarding, or think SNMP's management capabilities include log collection.
Candidates may confuse NetFlow with syslog because both involve sending data to a central server, but NetFlow focuses on traffic statistics rather than log messages.