Logging, SNMP, and Telemetry

Learn to enable system logging, SNMP, and Telemetry on any of your MX204, MX301, MX304, MX10004, or MX10008 routers.

System Logging (Syslog)

You can configure system logging (syslog) to maintain network stability, security, and performance. Syslog configuration allows the network administrators to monitor, troubleshoot, and audit the device activities.

To configure syslog locally on a switch:

To configure remote syslog server (sending logs to an external syslog server):

To configure remote syslog while setting source interface:

SNMP

Simple Network Management Protocol (SNMP) helps to monitor network devices like switches, routers, and other IP based devices from a single management host. By default, this protocol is not enabled on any MX Series router. However, the operating system running on these routers, Junos OS Evolved, supports SNMPv1, SNMPv2c, and SNMPv3.

To enable SNMP, you need to add the configuration statements at the [edit] hierarchy level. The minimum configuration for SNMP is to enable SNMP polling.

To configure basic SNMP identity:

To limit SNMP queries to trusted management ports:

To configure SNMP traps:

To verify whether SNMP is running after configuration:

OR

Telemetry

Junos Telemetry is Juniper's telemetry solution, developed to stream telemetry data from a Junos device. Junos devices can use the telemetry infrastructure to stream real-time network data, such as traffic patterns, device status, error rates, and other metrics that provide insights into the network's health and behaviour. For more information, see Understanding Junos Telemetry. To configure gRPC and verify telemetry streaming, see Understanding Authentication and Authorization for gRPC-Based Services.

Follow the steps below to configure and verify telemetry streaming on a Junos devices using gNMI. Configure Mutual (Bidirectional) Authentication for gRPC Services, ensure that you have a device running Junos and a Linux machine or a VM that can reach one of the traffic ports on the Junos device.

When mutual authentication is configured:

  • The server provides its public key certificate when the channel is established.

  • The client uses the server's Root CA certificate to authenticate the server.

  • The client also provides its certificate when it connects to the server, and the server validates the certificate. If the certificate validation is successful, the client is allowed to make calls.

  1. Obtain X.509 Certificates (server root certificate authority and server key pairs). Run the following commands:

    Note:

    The gRPC server's certificate must define either the server’s hostname in the Common Name (CN) field (hostname in the above example command uses vJunosEvolved as server’s hostname), or it must define the server’s IP address in the Subject Alternative Name (subjectAltName or SAN) IP Address field in the server_ssl_cert_ext.cnf file. The client application must use the same value to establish the connection to the server. If the certificate defines the SubjectAltName IP Address field, the Common Name field is ignored during authentication.

    The server_ssl_cert_ext.cnf file contents are:

    Run the following commands:

  2. Enable gRPC service, run the following commands:

    To configure mutual authentication instead of server-only authentication, run the following commands at the edit system services extension-service request-response grpc ssl hierarchy:

    To configure authentication for the gRPC client directly in the network device configuration, run the following commands:

  3. Copy the certificates that you generated on the client to the gRPC server, run the following commands:

  4. Load the certificate on the server, run the following commands:

  5. Configure the User Account for gRPC Services, run the following commands:

  6. Select the sensor path by identifing the information you want to receive from the device. Information you want to stream through Junos telemetry is specified using a telemetry sensor path.

    A telemetry sensor path is the hierarchical path (defined using YANG) to the operational data or metrics to be monitored. Use the Juniper Networks Junos YANG Data Model Explorer to view all the supported sensor paths, their corresponding leaves, and the device platforms that support them.

    For example, the following sensor path streams administrative and operational status information for interfaces on the device:

  7. Download and install the gNMI client once you have identified what you want to monitor, download, install, and configure the gNMI Client to test telemetry streaming on your device. Junos devices support various subscription types, see Subscription Types to identify the subscription type and subscription mode for your network. In this example we have selected “stream” as the subscription type and “sample” as the mode.

  8. Test telemetry streaming on your Linux machine, from the command prompt, subscribe to telemetry data using the gNMI client. Run the following command:

    For example: root@controller:~$ gnmic sub -a 172.25.11.11:32767 -u gnoi-user -p gnoi123 --tls-ca serverRootCA.crt --tls-cert client.crt --tls-key client.key --format json subscribe --path /junos/system/linecard/interface --mode stream --stream-mode sample --sample-interval 10s

    Where:

    • format - Specifies the output format used by the gNMI client to display telemetry data. The json format presents telemetry data in JSON. Available options include JSON, BYTES, PROTO, ASCII, and JSON_IETF.
    • sub - Invokes the gNMI Subscribe RPC to establish a telemetry subscription with the device
    • path - Is the YANG sensor path to stream telemetry data
    • mode - Defines the subscription mode. The stream mode establishes a continuous subscription that sends telemetry updates over time.
    • stream-mode - Specifies the streaming behaviour for a stream subscription. The sample mode sends updates at regular intervals.
    • sample-interval- Sets the sampling interval for stream subscriptions when stream-mode sample is configured.
  9. Verify that telemetry data is received on the collector. A successful output confirms that the gNMI connection is established and that telemetry data is streaming from the device.

    Sample gNMI Telemetry Output (JSON format)

    Receiving continuous telemetry data indicates that gNMI telemetry streaming is functioning correctly on the Junos devices.

  10. Implement on OpenSource or Third-party collector. Now that you have verified that your telemetry setup is working, you can install one of the many available OpenSource or third-party collectors. Setup and configuration of these collectors is beyond the scope of this guide.

For more information on Junos Telemetry, see the Junos Telemetry User Guide.