Solved

Rsyslog

Posted on 2010-11-16
3
1,094 Views
Last Modified: 2012-05-10
Hi

I'm looking at rsyslog and have got our Cisco ASA firewall logging to it. We are using a dhcp server, so need the ip addresses in the event logs converted the the clients ip address. Is there a way I can edit the rsyslog.conf to do dns lookups on the message field? I'm using a Mysql fb
0
Comment
Question by:COMPSUPP
3 Comments
 
LVL 29

Expert Comment

by:Alan Huseyin Kayahan
Comment Utility
Hello COMPSUPP,
    Your request cant be answered in the zones you listed your question in. Rather choose zones about scripting and database, post the sample logs and database tables so programmers can advice.

Ask for changing your question's zones

Regards
0
 
LVL 9

Accepted Solution

by:
expert_tanmay earned 500 total points
Comment Utility
Hi COMPSUPP,
I am trying to understand what you are looking for. Is it that you want a reverse dns i.e. convert from IP addresses to their host names.
Do you use MS windows active directory? If you are using the DNS of ADS then you can query the host names of the IP addresses in your log.

regards
0
 

Author Closing Comment

by:COMPSUPP
Comment Utility
-
0

Featured Post

Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

Join & Write a Comment

Have you experienced traffic destined through a Cisco ASA firewall disappears and you do not know if the traffic stops in the firewall or somewhere else? The solution is the capture feature. This feature was released in 6.2(1) and works in all firew…
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
Learn how to find files with the shell using the find and locate commands. Use locate to find a needle in a haystack.: With locate, check if the file still exists.: Use find to get the actual location of the file.:
Connecting to an Amazon Linux EC2 Instance from Windows Using PuTTY.

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now