Brightwater Outfitters — Network Operations Lab
edge appliance · bw-edge-01 · mgmt 172.22.10.1
N10-007 · 3.3 N10-009 · 3.2 (prov.) AP NET · 4.5.C

brief Centralize the Logs

You run the network for Brightwater Outfitters, a small outdoor-gear shop. The edge appliance bw-edge-01 keeps logs only on the box, and its local file rolls over so fast that yesterday's events were already gone by morning. If the appliance reboots — or someone tampers with it — the evidence vanishes with it.

Set sane local retention, then forward the events that matter to the shop's central log collector, logvault.brightwater.lan at 10.20.5.40, so the logs survive off-box. Forward only the System and Firewall facilities — not the chatty everyday noise.

console bw-edge-01 · Logging

tasks Completion checklist

  • Sign inAuthenticate to bw-edge-01.
  • Set entries per page to 50Local log view.
  • Set max local log size to 512000 bytesRetention cap.
  • Forward to 10.20.5.40Enable remote syslog to the collector.
  • Forward System + Firewall onlyNo other facilities selected.

questions Check your understanding

Q1. By default, which transport and port does syslog use to ship messages to a collector?

Q2. What is the main reason to forward logs to a separate collector instead of keeping them only on the appliance?

Score 0/7

submit Turn in your lab

Your callsign is a pseudonym. This lab collects no real name, email, or student ID. A screenshot of your work and a timestamp are sent to your instructor's Drive.

© 2026 <ADD AUTHOR / ORG> — clean-room build · N10-007 3.3 · N10-009 3.2 (provisional) · AP NET 4.5.C