Solved

What do you use for centralized event log monitoring

Posted on 2010-11-18
3
534 Views
Last Modified: 2012-05-10
Currently we have about 30 servers and every Monday remote in to each and check event log for application and system warnings and alerts

In efforts to be proactive in catching things like:
1.      Disk space
2.      System battery recharges indicating the battery may need to be replaced as it occurs more and more.
3.      Application errors
4.      And more…

However accessing 30 servers is a time consuming process so what we are looking to accomplish:
1.      Consolidate Event monitoring into one area per location
2.      Have an at a glance look at what is going on
3.      Notifications on critical events

I've searched online for some options but am wondering what the user community is using that they highly recommend.
0
Comment
Question by:bergquistcompany
3 Comments
 
LVL 5

Accepted Solution

by:
rotech_IT earned 500 total points
ID: 34165759
If you're running an all DELL shop I'd recommend OpenManage.  Install Open Manage System Administrator on each of the servers.  Then install OpenManage IT Assistant on a single server to manage each of the OMSA's.  IT assistant acts as your administration console if you will.  You can find OpenManage on www.dell.com/support download site.  It will monitor the health of the system and you can specify email alerts or view health from a central console.

I use Nagios to monitor system health as well.  We've integrated OpenManage into it along with various other system checks.  We have over 700 checks.  Nagios is also able to fire an email for certain alerts that you specify.  You'll want to build a dedicated linux box to run Nagios.  We run it on OpenSuse 11.3.  Nagios is opensource and free.   http://www.nagios.org/   An alternative to Nagios would be something like http://www.activexperts.com/ , we used this for a few years before switching to Nagios.  ActiveXperts is not free.

As far as event log monitoring, there are several applications out there.  This is a large requirement for PCI compliance, so most of these applications are not free.  Here's one that I like: http://www.kiwisyslog.com/kiwi-syslog-server-overview/

Hope that helps!
0
 
LVL 7

Expert Comment

by:Mohamed Khairy
ID: 34166430
I recommend to use System Center Operation  Manager

http://www.microsoft.com/systemcenter/en/us/operations-manager.aspx
0
 
LVL 6

Expert Comment

by:JRoyse
ID: 34215339
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Log files are useful in diagnosing and repairing problems.  This is a list of common log files and their standard locations that I've compiled.   While this is not exhaustive, it is a pretty good list that I've found to be useful.  I may update it f…
The way I use Experts Exchange to assist me in analyzing and diagnosing a problem is I first enter a Verbose Question at Experts Exchange like: Office 2007 will hang when opening and saving files I then launch WordPad (any text editor will do) an…
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …

778 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question