Pardon me if this sounds like a stupid question, as I have very minimal experiences in switches or networking in general, but currently I am involved in a project trying to collect logs from Cisco Nexus 9000 series switches and so far we can only see configurations logs being sent to the syslog-ng server set up. As configuration changes are rarely done so 95% of the time the syslog-ng server does not receive any logs at all.
We were hoping to see some traffics logs from it and use the Cisco Networks App for Splunk Enterprise for monitoring, but the engineer in charge of the switches told our team that it only logs configuration logs.
I surfed through a couple of posts here and there and found out that people are actually able to monitor traffic logs through switches, so I am a little confused.
Using syslog you'll only be able to monitor the state of the switches. None of the switches allow you to actually output traffic logs, but the Nexus 9k App and Add-on for Splunk will let you show interface statistics. I'm not sure how well this app works as I haven't used it, but give it a shot.