
Hello,
Thre´s a way to ignore/filter some event log like this (flooding, in this case):
8h 30m 57s GE0/0/5 MAC changed: xxx.xxx.xxx.xxx : 00:0c:29:51:1e:76 -> 00:0c:29:9f:26:47 14h 30m 37s GE0/0/5 MAC changed: xxx.xxx.xxx.xxx : 00:0c:29:9f:26:47 -> 00:0c:29:51:1e:76 4d 14h 30m GE0/0/5 MAC changed: xxx.xxx.xxx.xxx : 00:0c:29:9f:26:47 -> 00:0c:29:51:1e:76 4d 20h 30m GE0/0/5 MAC changed: xxx.xxx.xxx.xxx : 00:0c:29:51:1e:76 -> 00:0c:29:9f:26:47 5d 20h 30m GE0/0/5 MAC changed: xxx.xxx.xxx.xxx : 00:0c:29:51:1e:76 -> 00:0c:29:9f:26:47 7d 8h 31m GE0/0/5 MAC changed: xxx.xxx.xxx.xxx : 00:0c:29:9f:26:47 -> 00:0c:29:51:1e:76 7d 20h 31m GE0/0/5 MAC changed: xxx.xxx.xxx.xxx : 00:0c:29:51:1e:76 -> 00:0c:29:9f:26:47 8d 2h 30m GE0/0/5 MAC changed: xxx.xxx.xxx.xxx : 00:0c:29:9f:26:47 -> 00:0c:29:51:1e:76 8d 8h 30m GE0/0/5 MAC changed: xxx.xxx.xxx.xxx : 00:0c:29:51:1e:76 -> 00:0c:29:9f:26:47 8d 14h 31m GE0/0/5 MAC changed: xxx.xxx.xxx.xxx : 00:0c:29:9f:26:47 -> 00:0c:29:51:1e:76 8d 20h 30m GE0/0/5 MAC changed: xxx.xxx.xxx.xxx : 00:0c:29:51:1e:76 -> 00:0c:29:9f:26:47 9d 8h 30m GE0/0/5 MAC changed: xxx.xxx.xxx.xxx : 00:0c:29:9f:26:47 -> 00:0c:29:51:1e:76 10d 8h 31m GE0/0/5 MAC changed: xxx.xxx.xxx.xxx : 00:0c:29:51:1e:76 -> 00:0c:29:9f:26:47
.... ....
some servers share same loopback address (dns anycast).
regars,