To enable the gateway to write the contents of the application event log buffer to an external file, use the event-log
dump
ftp command in application configuration monitor configuration mode. To reset to the default, use the no form of this command.
event-log
dump
ftp
server
[
:port
]
/path
username
username
password
{
0
|
6
|
7
}
password
no event-log dump ftp
Syntax Description
|
server
|
Name or IP address of the FTP server where the file is
located.
|
|
:
port
|
(Optional) Specific port number on the server.
|
|
/
file
|
Name and path of the file.
|
|
username
|
Username required to access the file.
|
|
encryption-type
|
(Optional) The Cisco proprietary algorithm used to encrypt
the password. Values are 0 or 7. To disable encryption enter 0; to enable
encryption enter 7. If you specify 7, you must enter an encrypted password (a
password already encrypted by a Cisco router).
|
| password {0 | 6 | 7} |
Following are the password encryption types–
-
0– Specifies that the subsequent password is in plain text. Type 0 disables encryption.
-
6– Specifies that the subsequent password is encrypted using the AES algorithm. Ensure to provide a string in AES-encrypted
format.
-
7– Specifies that the subsequent password is hidden. You must enter a Cisco-proprietary encrypted password string.
-
LINE– The cleartext password.
|
|
password
|
Password required to access the file.
|
Command Default
By default, this feature is not enabled on the gateway.
Command Modes
Application configuration monitor configuration (config-app-monitor)
Command History
|
Release
|
Modification
|
|
12.3(14)T
|
This command was introduced to replace the
call application event-log dump ftp command.
|
|
Cisco IOS XE 26.2.1
|
This command was modified for the following:
|
Usage Guidelines
This command enables the gateway to automatically write the event log buffer to the named file either after an active application
instance terminates or when the event log buffer becomes full. The default buffer size is 4 KB. To modify the size of the
buffer, use the event-log
max-buffer-size command in application configuration monitor configuration mode.
Starting from Cisco IOS XE 26.2.1 release, it is recommended to use Type 6 (AES) for all credential provisioning to comply with security standards. Usage of
Type 0, or 7 triggers a syslog warning. Ensure password encryption aes and key config-key password-encrypt are enabled to support auto-conversion of Type 0, or 7 to Type 6 reversible encryption. If the encryption commands are not
enabled, 0 and 7 password types are not converted to type 6; they remain saved as type 0 and 7
Enabling the gateway to write event logs to FTP could adversely
impact gateway memory resources in some scenarios, for example, when:
-
The gateway is consuming
high processor resources and FTP does not have enough processor resources to
flush the logged buffers to the FTP server.
-
The designated FTP server
is not powerful enough to perform FTP transfers quickly
-
Bandwidth on the link
between the gateway and the FTP server is not large enough
-
The gateway is receiving
a high volume of short-duration calls or calls that are failing
You should enable FTP dumping only when necessary and not enable it
in situations where it might adversely impact system performance.

Warning
|
Starting with Cisco IOS XE 26.2.1, a warning message is displayed when insecure protocols such as HTTP, FTP, or TFTP are used, as they do not provide encryption
or authentication. Use secure alternatives such as HTTPS, SFTP, or SCP instead.
|
Examples
The following example shows type 6 encryption configuration, supported starting from Cisco IOS XE 26.2.1 release:
application
monitor
event-log dump ftp 10.10.10.101/elogs/app-elogs.log username myname password 6 B]hHYYZ_aJZUeYSfW]]ZTT_O]JXMN`
Examples
The following example enables type 0 to type 6 auto-conversion, starting from Cisco IOS XE 26.2.1 release:
Router(config)#password encryption aes
Router(config)#key config-key password-encrypt
Router(config)#application
Router(config-app)#monitor
Router(config-app-monitor)# event-log dump ftp 10.10.10.101/elogs/app-elogs.log username myname password 0 mypass
SECURITY WARNING - Module: APPLICATION_MONITOR, Command: event-log dump ftp 10.10.10.101/elogs/app-elogs.log username myname password 0 * ,
Reason: No encryption is configured, Description: Application monitor event log dump configured with insecure FTP protocol -
vulnerable to credential exposure, Remediation: Transition to secure file transfer methods using SCP, SFTP, HTTPS protocols
Router(config-app-monitor)# end
Router# show run | sec event-log
event-log
event-log dump ftp 10.10.10.101/elogs/app-elogs.log username myname password 6 CGiJD[EZAHKD^\aPDNe`baCN^Pf_X]AAB
Examples
The following example shows the warning being displayed for the usage of insecure FTP protocol:
Device(config)#application
Device(config-app)#monitor
Device(config-app-monitor)#event-log dump ftp 10.10.10.101/elogs/app-elogs.log username myname password 0 password
SECURITY WARNING - Module: APPLICATION_MONITOR, Command: event-log dump ftp ftp-server/elogs/app-elogs.log username myname password 0 *,
Reason: No encryption is configured, Description: Application monitor event log dump configured with insecure FTP protocol - vulnerable to credential exposure,
Remediation: Transition to secure file transfer methods using SCP, SFTP, HTTPS protocols
Device(config-app-monitor)#
Examples
The following example enables the gateway to write application event logs to an external file named app_elogs.log on a server
named ftp-server:
application
monitor
event-log dump ftp ftp-server/elogs/app-elogs.log username myname password 0 mypass
Examples
The following example specifies that application event logs are written to an external file named app_elogs.log on a server
with the IP address of 10.10.10.101:
application
monitor
event-log dump ftp 10.10.10.101/elogs/app-elogs.log username myname password 0 mypass