» tagged pages
» logout

sorted by: recent | see : popular
Content Tagged with syslog + linux

Using Syslog information with SourceLabs Linux Self-Support

Below is documentation for using SourceLabs Self-Support Suite for Linux and Open Source Java to gather, organize, and search Syslog messages.

You can setup syslog to connect to the relay. In this release, we only support syslog over UDP. To set this up, you need to modify your syslogd config file. Often this is in /etc/syslog.conf

To get started, you can add

. @relayMachineName:4657

This will send all your syslog messages to a machine named relayMachineName over port 4657. Port 4657 is the default port the relay listens to for Syslog UDP messages. You can change this in the relay’s property file. This properties file is located in the ‘conf’ directory of your relay installation (e.g. /opt/sourcelabs/relay/conf).

To filter the syslog messages sent to the relay, please read the syslog documentation or man pages for more information.

Syslog-ng:

You can also setup syslog-ng to use the relay. For the current version of the relay, you will need to use UDP logging to the relay instead of TCP. To set this up, you need to modify your syslog-ng config file. Often this is in /etc/syslog-ng.conf

To get started, you can add
destination d_relay { udp("relayMachineName ", port(4657)); }; log { source(s_sys); destination(d_relay); };

Assuming that you are using a default syslog-ng configuration where source ‘s_sys’ represents all syslog messages (modify source as necessary for your configuration),this will send all your syslog messages to a machine named relayMachineName over port 4657. Port 4657 is the default port the relay listens to for Syslog UDP messages. You can change this in the relay’s property file. This properties file is located in the ‘conf’ directory of your relay installation (e.g. /opt/sourcelabs/relay/conf).

To filter the syslog messages sent to the relay, please read the syslog documentation or man pages for more information.

Find more information about SourceLabs Self-Support Suite for LInux and Open Source Java

syslogd supporting MySQL and TCP :: rsyslog

Rsyslog is an enhanced multi-threaded syslogd supporting, among others, MySQL, syslog/tcp, RFC 3195, permitted sender lists, filtering on any message part, and fine grain output format control

User:daveg: del.icio.us/daveg

Splunk > The IT search engine.

Splunk is the search engine for IT data. It's software that indexes and enables you to search all your logs and IT data from any application, server, or network device in real time.

User:daveg: del.icio.us/daveg

Hinemos | NTT data: The integrated operation management for computer groups in enterprise environment.

NTT data (located in Japan) releases Integrated operation management software "Hinemos" by open source software(JBoss, OpenLDAP, PostgreSQL and Eclipse).

JBoss: del.icio.us tag/jboss

Hinemos | NTT data: The integrated operation management for computer groups in enterprise environment.

NTT data (located in Japan) releases Integrated operation management software "Hinemos" by open source software(JBoss, OpenLDAP, PostgreSQL and Eclipse).

opensource: del.icio.us tag/opensource

Hinemos | NTT data: The integrated operation management for computer groups in enterprise environment.

NTT data (located in Japan) releases Integrated operation management software "Hinemos" by open source software(JBoss, OpenLDAP, PostgreSQL and Eclipse).

OpenLDAP: del.icio.us/tag/openldap

Prelude-IDS - The Hybrid IDS framework

Hybrid IDS framework, posiblemente sirva para la centralizacion de logs

snort: del.icio.us/tag/snort

psad

The Port Scan Attack Detector

snort: del.icio.us/tag/snort