networking-forum.com
Community BlogCommunity Wiki * Register  * Search  * Login
View unanswered postsView active topics

All times are UTC - 6 hours [ DST ]



Post new topic Reply to topic  [ 9 posts ] 
Author Message
 Post subject: Collecting syslogs
PostPosted: Mon Jun 18, 2012 7:39 pm 
Offline
Post Whore
Post Whore
User avatar

Joined: Sat Dec 19, 2009 11:52 pm
Posts: 1162
Location: Central Florida
Certs: CCNP, JNCIA, MCSA
What do you guys use to collect syslogs?

The syslog functionality of my server is very basic. It can only receive the message, look at the facility number, and make a decision to alert us or not (based on the facility we configure it to alert on). It can't analyze the syslogs and trigger emails based on the message content, which is what I'd like.

Example: Facility 4 (or 3) include duplex mismatch and link up/down alerts. Well, I really don't care if there's a duplex mismatch between an IP phone and a switch, or if a workstation is unplugged...but I do care if those events occur to a server or router.

Thanks


Top
 Profile  
 
 Post subject: Re: Collecting syslogs
PostPosted: Mon Jun 18, 2012 7:44 pm 
Offline
Ultimate Member
Ultimate Member
User avatar

Joined: Wed Sep 16, 2009 3:16 pm
Posts: 917
Location: Iowa
We just started using it for some server functions, but I know it can do more. Check out Splunk.

Outside of that I normally just use kiwi syslog. Not as granular as you probably want


Top
 Profile  
 
 Post subject: Collecting syslogs
PostPosted: Mon Jun 18, 2012 8:12 pm 
Online
Senior Member
Senior Member

Joined: Wed Sep 01, 2010 9:46 pm
Posts: 355
Location: USA
Certs: CCNA, 642-642, 642-627
We use Solarwinds LEM. It's really powerful but you're going to pay dearly.


Top
 Profile  
 
 Post subject: Re: Collecting syslogs
PostPosted: Mon Jun 18, 2012 9:19 pm 
Offline
Post Whore
Post Whore
User avatar

Joined: Thu Apr 29, 2010 6:12 pm
Posts: 2079
Location: Texas
Certs: CCNP, CCDP, CCIP
Im building a solarwinds NMS and syslog is doing alright. I might need to spends more time with it to tweak. In the past i have always been very happy with Zenoss, but its a full blow NMS and might be overkill for just needing syslog monitoring.

_________________
http://blog.movingonesandzeros.net/


Top
 Profile  
 
 Post subject: Re: Collecting syslogs
PostPosted: Tue Jun 19, 2012 2:30 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Thu Oct 14, 2010 4:39 am
Posts: 1003
Certs: CCNP (R&S, Security), ITILv3 Foundation
I'm surprised no-one has posted about Logzilla - http://www.logzilla.pro/
There's an interesting read on syslogging amongst the documents for Cisco Live London 2012 as well if anyone's curious.


Top
 Profile  
 
 Post subject: Re: Collecting syslogs
PostPosted: Tue Jun 19, 2012 9:32 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Thu Apr 29, 2010 6:12 pm
Posts: 2079
Location: Texas
Certs: CCNP, CCDP, CCIP
Halo wrote:
There's an interesting read on syslogging amongst the documents for Cisco Live London 2012 as well if anyone's curious.

I am! do you have a link?

_________________
http://blog.movingonesandzeros.net/


Top
 Profile  
 
 Post subject: Re: Collecting syslogs
PostPosted: Tue Jun 19, 2012 10:38 am 
Offline
Senior Member
Senior Member
User avatar

Joined: Thu Nov 17, 2011 6:09 pm
Posts: 487
Location: Portland, OR
Linux - syslogd/syslogng
Windows - Kiwi (free and more robust than SolarWinds syslog module), else Splunk (expensive).

If you already have the SolarWinds NMS, then it makes sense to integrate your syslogs with that whole package.


Top
 Profile  
 
 Post subject: Re: Collecting syslogs
PostPosted: Wed Jun 20, 2012 2:45 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Thu Oct 14, 2010 4:39 am
Posts: 1003
Certs: CCNP (R&S, Security), ITILv3 Foundation
that1guy15 wrote:
Halo wrote:
There's an interesting read on syslogging amongst the documents for Cisco Live London 2012 as well if anyone's curious.

I am! do you have a link?


Sure thing dude.
https://www.dropbox.com/s/v1zglvg0higs7 ... S-2031.pdf
I'd link you to in on the ciscolive365 site, but that thing's a ballache. Can't promise how long my dropbox link will stay alive for, so download it before I go off on a mad link-clearing frenzy.


Top
 Profile  
 
 Post subject: Re: Collecting syslogs
PostPosted: Fri Jun 22, 2012 3:20 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Sat Dec 19, 2009 11:52 pm
Posts: 1162
Location: Central Florida
Certs: CCNP, JNCIA, MCSA
Great link, that's the kind of filtering I was looking for!

Thanks


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 9 posts ] 

All times are UTC - 6 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 3 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group