What problem does it solve? SRX logging fails in confusing ways because system syslog and security logs are produced by two independent subsystems (Routing Engine vs PFE) over different data paths, so logs silently never arrive at the collector. This Skill guides configuration and diagnosis of Juniper SRX/vSRX logging to an external collector or SIEM, covering fxp0 vs revenue-interface sourcing, mgmt_junos routing instances, stream/event modes, and the non-default-port trap. ## Core Features & Use Cases - Structured diagnosis workflow: A four-step outward-from-the-device method (generation, wire capture, subsystem comparison, second-host isolation test) plus a catalog of tested red herrings to avoid dead ends. - Mode- and transport-aware configuration: Working Junos configuration for system syslog, stream-mode security logs, UDP/TCP/TLS transports, and Security Director Cloud onboarding, with version-gated verification commands. - Use Case: A vSRX delivers security logs but zero system syslog events. The Skill walks you through confirming emission, isolating the variable with a second host entry, and identifying that a non-default syslog port is silently dropped on revenue-interface egress. ## Quick Start Use the srx-syslog-logging skill to diagnose why my SRX system syslog events are not reaching the SIEM collector.