Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Receive and query syslog messages from network devices via UDP.
.claude/skills/automateyournetwork-syslog-receiver/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-15 | ✗→✓ | ▲ Improved | -52% | 0% |
| case-16 | ✗→✓ | ▲ Improved | 17% | 0% |
| case-04 | ✗→✓ | ▲ Improved | -14% | 0% |
| case-07 | ✗→✓ | ▲ Improved | -30% | 0% |
| case-08 | ✗→✓ | ▲ Improved | -35% | 0% |
Receive and query syslog messages from network devices via UDP.
syslog-receiver
This skill enables NetClaw to receive syslog messages from network devices (routers, switches, firewalls) and query the collected data. It supports both RFC 5424 (modern) and RFC 3164 (BSD/Cisco) syslog formats.
syslog-mcp
| Tool | Purpose | |------|---------| | syslog_start_receiver | Start listening for syslog messages | | syslog_stop_receiver | Stop the receiver | | syslog_get_status | Check receiver status and statistics | | syslog_query | Search messages with filters | | syslog_get_message | Get full details of a specific message | | syslog_get_severity_counts | Get message counts by severity |
1. Use syslog_start_receiver with port 10514
2. Configure network devices to send syslog to this port
3. Use syslog_get_status to verify messages are being received1. Use syslog_query with severity_max=3 to find ERROR and above
2. Filter by hostname or source_ip if investigating specific device
3. Use message_contains to search for specific keywords
4. Use syslog_get_message for full details of interesting entries1. Use syslog_get_severity_counts to see distribution
2. Focus on CRITICAL, ERROR, WARNING counts
3. Query high-severity messages for detailsThe syslog-mcp server is configured via environment variables:
SYSLOG_PORT: UDP listening port (default: 514)SYSLOG_BIND_ADDRESS: Bind address (default: 0.0.0.0)SYSLOG_RETENTION_HOURS: Message retention (default: 24)SYSLOG_RATE_LIMIT: Max messages/second (default: 1000)SYSLOG_DEDUP_WINDOW: Dedup window in seconds (default: 5)snmptrap-receiver - SNMP trap collectionipfix-receiver - Flow data collectiongnmi-telemetry - Streaming telemetryOther measured skills in the registry, with their headline benchmark lift.