ON THIS PAGE
Logging, SNMP, and Telemetry
Learn to enable system logging, SNMP, and Telemetry on any of your MX204, MX301, MX304, MX10004, or MX10008 routers.
System Logging (Syslog)
You can configure system logging (syslog) to maintain network stability, security, and performance. Syslog configuration allows the network administrators to monitor, troubleshoot, and audit the device activities.
To configure syslog locally on a switch:
set system syslog file system log any notice set system syslog file system log authorization info
To configure remote syslog server (sending logs to an external syslog server):
set system syslog host 192.168.1.1/24 any notice
To configure remote syslog while setting source interface:
set system syslog host 192.168.1.1/24 source-address 192.168.1.10
SNMP
Simple Network Management Protocol (SNMP) helps to monitor network devices like switches, routers, and other IP based devices from a single management host. By default, this protocol is not enabled on any MX Series router. However, the operating system running on these routers, Junos OS Evolved, supports SNMPv1, SNMPv2c, and SNMPv3.
To enable SNMP, you need to add the configuration statements at the [edit] hierarchy level. The minimum configuration for SNMP is to enable SNMP polling.
set snmp community public authorization read-only
To configure basic SNMP identity:
set snmp contact "Network Operation Center" set snmp location "California Office - Server Room" set snmp description "Internet Edge Router"
To limit SNMP queries to trusted management ports:
set snmp community public clients 192.168.1.100
To configure SNMP traps:
set snmp trap-group NMS targets 192.168.1.100
To verify whether SNMP is running after configuration:
show snmp statistics
OR
show snmp mib
Telemetry
Junos Telemetry is Juniper's telemetry solution, developed to stream telemetry data from a Junos device. Junos devices can use the telemetry infrastructure to stream real-time network data, such as traffic patterns, device status, error rates, and other metrics that provide insights into the network's health and behaviour. For more information, see Understanding Junos Telemetry. To configure gRPC and verify telemetry streaming, see Understanding Authentication and Authorization for gRPC-Based Services.
Follow the steps below to configure and verify telemetry streaming on a Junos devices using gNMI. Configure Mutual (Bidirectional) Authentication for gRPC Services, ensure that you have a device running Junos and a Linux machine or a VM that can reach one of the traffic ports on the Junos device.
When mutual authentication is configured:
-
The server provides its public key certificate when the channel is established.
-
The client uses the server's Root CA certificate to authenticate the server.
-
The client also provides its certificate when it connects to the server, and the server validates the certificate. If the certificate validation is successful, the client is allowed to make calls.
Obtain X.509 Certificates (server root certificate authority and server key pairs). Run the following commands:
user@nms:~$ openssl genrsa -out server.key 4096 user@nms:~$ openssl req -new -x509 -sha256 -key serverRootCA.key -out serverRootCA.crt -days 3650 -subj "/C=US/ST=CA/L=Sunnyvale/O=Juniper/CN=serverRootCA" user@nms:~$ openssl genrsa -out server.key 4096 user@nms:~$ openssl req -new -key server.key -out server.csr -sha256 -subj "/C=US/ST=CA/L=Sunnyvale/O=Juniper/OU=serverRootCAOrg/CN=vJunosEvolved" user@nms:~$ openssl x509 -req -in server.csr -CA serverRootCA.crt -CAkey serverRootCA.key -CAcreateserial -out server.crt -days 365 -extfile server_ssl_cert_ext.cnf
Note:The gRPC server's certificate must define either the server’s hostname in the Common Name (CN) field (hostname in the above example command uses vJunosEvolved as server’s hostname), or it must define the server’s IP address in the Subject Alternative Name (subjectAltName or SAN) IP Address field in the
file. The client application must use the same value to establish the connection to the server. If the certificate defines the SubjectAltName IP Address field, the Common Name field is ignored during authentication.server_ssl_cert_ext.cnfThe
file contents are:server_ssl_cert_ext.cnfuser@nms:~$ cat server_ssl_cert_ext.cnf #### include -extfile server_ssl_cert_ext.cnf in command to include extensions file #### openssl.cnf extensions = v3_sign [v3_sign] subjectAltName=IP:172.25.11.11
Run the following commands:
user@nms:~$ openssl genrsa -out clientRootCA.key 4096 user@nms:~$ openssl req -new -x509 -sha256 -key clientRootCA.key -out clientRootCA.crt -days 3650 -subj "/C=US/ST=CA/L=Sunnyvale/O=Juniper/CN=clientRootCA" user@nms:~$ openssl genrsa -out client.key 4096 user@nms:~$ openssl req -new -key client.key -out client.csr -sha256 -subj "/C=US/ST=CA/L=Sunnyvale/O=Juniper/OU=serverRootCAOrg/CN= client-desktop" user@nms:~$ openssl x509 -req -in client.csr -CA clientRootCA.crt -CAkey clientRootCA.key -CAcreateserial -out client.crt -days 365 -extfile server_ssl_cert_ext.cnf
Enable gRPC service, run the following commands:
set system services http servers server grpc-server port 32767 set system services http servers server grpc-server grpc gnoi set system services http servers server grpc-server grpc gnmi set system services http servers server grpc-server tls local-certificate grpc-server
To configure mutual authentication instead of server-only authentication, run the following commands at the
edit system services extension-service request-response grpc sslhierarchy:set system services extension-service request-response grpc ssl port 32767 set system services extension-service request-response grpc ssl local-certificate grpc-server
To configure authentication for the gRPC client directly in the network device configuration, run the following commands:
set system services extension-service request-response grpc ssl mutual-authentication certificate-authority grpc-client-CA set system services extension-service request-response grpc ssl mutual-authentication client-certificate-request require-certificate-and-verify set system services extension-service request-response grpc ssl hot-reloading set system services extension-service request-response grpc ssl use-pki set system services extension-service traceoptions file jsd set system services extension-service traceoptions flag all set security pki ca-profile grpc-client-CA ca-identity clientRootCA set security pki traceoptions file size 10m set security pki traceoptions file files 3
Copy the certificates that you generated on the client to the gRPC server, run the following commands:
user@nms:~$ scp -O server.crt lab@172.25.11.11:/var/home/lab user@nms:~$ scp -O server.key lab@172.25.11.11:/var/home/lab user@nms:~$ scp -O clientRootCA.crt lab@172.25.11.11:/var/home/lab
Load the certificate on the server, run the following commands:
user@host> request security pki local-certificate load certificate-id grpc-server filename /var/home/lab/server.crt key /var/home/lab/server.key user@host> request security pki ca-certificate load ca-profile grpc-client-CA filename /var/home/lab/client.crt
Configure the User Account for gRPC Services, run the following commands:
user@host# set system login user gnoi-user class super-user user@host# set system login user gnoi-user authentication plain-text-password user@host# set system login user gnoi-user full-name "gNOI client"
Select the sensor path by identifing the information you want to receive from the device. Information you want to stream through Junos telemetry is specified using a telemetry sensor path.
A telemetry sensor path is the hierarchical path (defined using YANG) to the operational data or metrics to be monitored. Use the Juniper Networks Junos YANG Data Model Explorer to view all the supported sensor paths, their corresponding leaves, and the device platforms that support them.
For example, the following sensor path streams administrative and operational status information for interfaces on the device:
/junos/system/linecard/interface
Download and install the gNMI client once you have identified what you want to monitor, download, install, and configure the gNMI Client to test telemetry streaming on your device. Junos devices support various subscription types, see Subscription Types to identify the subscription type and subscription mode for your network. In this example we have selected “stream” as the subscription type and “sample” as the mode.
Test telemetry streaming on your Linux machine, from the command prompt, subscribe to telemetry data using the gNMI client. Run the following command:
gnmic sub -a <device_ip>:<gnmi_port> -u <username> -p <password> --format json subscribe --path <sensor path> --mode stream --stream-mode sample --sample-interval <seconds>For example:
root@controller:~$ gnmic sub -a 172.25.11.11:32767 -u gnoi-user -p gnoi123 --tls-ca serverRootCA.crt --tls-cert client.crt --tls-key client.key --format json subscribe --path /junos/system/linecard/interface --mode stream --stream-mode sample --sample-interval 10sWhere:
format- Specifies the output format used by the gNMI client to display telemetry data. The json format presents telemetry data in JSON. Available options include JSON, BYTES, PROTO, ASCII, and JSON_IETF.sub- Invokes the gNMI Subscribe RPC to establish a telemetry subscription with the devicepath -Is the YANG sensor path to stream telemetry datamode -Defines the subscription mode. The stream mode establishes a continuous subscription that sends telemetry updates over time.stream-mode -Specifies the streaming behaviour for a stream subscription. The sample mode sends updates at regular intervals.sample-interval-Sets the sampling interval for stream subscriptions when stream-mode sample is configured.
Verify that telemetry data is received on the collector. A successful output confirms that the gNMI connection is established and that telemetry data is streaming from the device.
Sample gNMI Telemetry Output (JSON format)
{ "source": "172.25.11.11:32767", "subscription-name": "default-1782391912", "timestamp": 1782391912042548677, "time": "2026-06-25T05:51:52.042548677-07:00", "prefix": "interfaces/interface[name=et-0/0/0]", "updates": [ { "Path": "name", "values": { "name": "et-0/0/0" } }, { "Path": "state/hardware-port", "values": { "state/hardware-port": "FPC0:PIC0:PORT0" } }, { "Path": "state/transceiver", "values": { "state/transceiver": "FPC0:PIC0:PORT0:Xcvr0" } }, { "Path": "state/physical-channel", "values": { "state/physical-channel": { "element": [ { "Value": { "JsonVal": "MA==" } }, { "Value": { "JsonVal": "MQ==" } }, { "Value": { "JsonVal": "Mg==" } }, { "Value": { "JsonVal": "Mw==" } } ] } } }, { "Path": "name", "values": { "name": "et-0/0/1" } }, { "Path": "state/hardware-port", "values": { "state/hardware-port": "FPC0:PIC0:PORT1" } }, { "Path": "state/transceiver", "values": { "state/transceiver": "FPC0:PIC0:PORT1:Xcvr0" } }, { "Path": "state/physical-channel", "values": { "state/physical-channel": { "element": [ { "Value": { "JsonVal": "MA==" } }, { "Value": { "JsonVal": "MQ==" } }, { "Value": { "JsonVal": "Mg==" } }, { "Value": { "JsonVal": "Mw==" } } ] } } }, … truncatedReceiving continuous telemetry data indicates that gNMI telemetry streaming is functioning correctly on the Junos devices.
Implement on OpenSource or Third-party collector. Now that you have verified that your telemetry setup is working, you can install one of the many available OpenSource or third-party collectors. Setup and configuration of these collectors is beyond the scope of this guide.
For more information on Junos Telemetry, see the Junos Telemetry User Guide.