Improve company productivity with a Business Account.Sign Up

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 341
  • Last Modified:

Advice on settinng up a syslog server

I need to setup a syslog server and need some advice.  I need something that can record log entries for Windows desktops and servers, Unix servers, Linux desktops and servers, as well as network devices such as routers, switches etc.  

So my questions are:

1. What is a good, cross platform, syslog server that can be setup.  I prefer open source options but am open to all ideas.

2. For a syslog server to correctly record log data, do I have to configure all the clients to send their log data TO the syslog server or does the syslog server go out and collect data FROM the clients?

3.  Can I have windows send all event logs to a syslog server or does it only record certain types of entries?

Thanks in advance!
0
arstacey
Asked:
arstacey
  • 4
  • 3
  • 3
  • +1
2 Solutions
 
sysreq2000Commented:
1. Kiwi is a decent free syslog server. Google kiwi syslog you will find it.

2. You must configure devices to send to the syslog, it is push not a pull system.

3. Dunno.  8)  I'm not aware of a way to redirect event viewer to syslog but there might be a way.
0
 
Richard2k4Commented:
There is a free utility that I used to use called Snare.  It will send a copy of all event logs to a syslog server or their own free server.
0
 
arstaceyAuthor Commented:
I have heard of kiwi but in reading I wasn't sure if it accepted syslog entries from all devices or just certain types.
0
Improve Your Query Performance Tuning

In this FREE six-day email course, you'll learn from Janis Griffin, Database Performance Evangelist. She'll teach 12 steps that you can use to optimize your queries as much as possible and see measurable results in your work. Get started today!

 
sysreq2000Commented:
OK looks like no native way to send windows events to syslog but there are utilities to do it:

http://www.google.ca/#hl=en&biw=1266&bih=734&q=how+to+send+windows+events+to+syslog&aq=f&aqi=g-v1&aql=&oq=&fp=e1d57483344a3fed
0
 
sysreq2000Commented:
haha, EE needs to refresh more often  8)
0
 
sysreq2000Commented:
Hmmm, I think Kiwi is pretty much across the board. I've used it for 3com and cisco but I'd be surprised if anything didn't work on it.
0
 
arstaceyAuthor Commented:
Awesome guys.  Thanks for the advice.  I am going to check out kiwi over the next few days and see how it goes.  Thanks for the link too Richard.  That is exactly what I want.  I am a lone sys admin and don't have time to manually review event logs all day lol.
0
 
Richard2k4Commented:
You will love Kiwi.  You can configure it to look for specified event log or syslogs and it will alert you via email or any other way you configure.
0
 
Pedram-zCommented:
I also suggest to use free version of Splunk. Such a great tool!
0
 
arstaceyAuthor Commented:
Thanks guys.  Kiwi looks great and snare may take care of my event log issues as well.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Improve Your Query Performance Tuning

In this FREE six-day email course, you'll learn from Janis Griffin, Database Performance Evangelist. She'll teach 12 steps that you can use to optimize your queries as much as possible and see measurable results in your work. Get started today!

  • 4
  • 3
  • 3
  • +1
Tackle projects and never again get stuck behind a technical roadblock.
Join Now