Solved

Advice on settinng up a syslog server

Posted on 2011-02-16
11
336 Views
Last Modified: 2012-05-11
I need to setup a syslog server and need some advice.  I need something that can record log entries for Windows desktops and servers, Unix servers, Linux desktops and servers, as well as network devices such as routers, switches etc.  

So my questions are:

1. What is a good, cross platform, syslog server that can be setup.  I prefer open source options but am open to all ideas.

2. For a syslog server to correctly record log data, do I have to configure all the clients to send their log data TO the syslog server or does the syslog server go out and collect data FROM the clients?

3.  Can I have windows send all event logs to a syslog server or does it only record certain types of entries?

Thanks in advance!
0
Comment
Question by:arstacey
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
  • 3
  • +1
11 Comments
 
LVL 11

Accepted Solution

by:
sysreq2000 earned 250 total points
ID: 34909346
1. Kiwi is a decent free syslog server. Google kiwi syslog you will find it.

2. You must configure devices to send to the syslog, it is push not a pull system.

3. Dunno.  8)  I'm not aware of a way to redirect event viewer to syslog but there might be a way.
0
 
LVL 3

Assisted Solution

by:Richard2k4
Richard2k4 earned 250 total points
ID: 34909354
There is a free utility that I used to use called Snare.  It will send a copy of all event logs to a syslog server or their own free server.
0
 

Author Comment

by:arstacey
ID: 34909365
I have heard of kiwi but in reading I wasn't sure if it accepted syslog entries from all devices or just certain types.
0
Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

 
LVL 11

Expert Comment

by:sysreq2000
ID: 34909378
OK looks like no native way to send windows events to syslog but there are utilities to do it:

http://www.google.ca/#hl=en&biw=1266&bih=734&q=how+to+send+windows+events+to+syslog&aq=f&aqi=g-v1&aql=&oq=&fp=e1d57483344a3fed
0
 
LVL 11

Expert Comment

by:sysreq2000
ID: 34909395
haha, EE needs to refresh more often  8)
0
 
LVL 11

Expert Comment

by:sysreq2000
ID: 34909411
Hmmm, I think Kiwi is pretty much across the board. I've used it for 3com and cisco but I'd be surprised if anything didn't work on it.
0
 

Author Comment

by:arstacey
ID: 34909432
Awesome guys.  Thanks for the advice.  I am going to check out kiwi over the next few days and see how it goes.  Thanks for the link too Richard.  That is exactly what I want.  I am a lone sys admin and don't have time to manually review event logs all day lol.
0
 
LVL 3

Expert Comment

by:Richard2k4
ID: 34909451
You will love Kiwi.  You can configure it to look for specified event log or syslogs and it will alert you via email or any other way you configure.
0
 
LVL 1

Expert Comment

by:Pedram-z
ID: 34921628
I also suggest to use free version of Splunk. Such a great tool!
0
 

Author Closing Comment

by:arstacey
ID: 35149036
Thanks guys.  Kiwi looks great and snare may take care of my event log issues as well.
0

Featured Post

Online Training Solution

Drastically shorten your training time with WalkMe's advanced online training solution that Guides your trainees to action. Forget about retraining and skyrocket knowledge retention rates.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In the world of WAN, QoS is a pretty important topic for most, if not all, networks. Some WAN technologies have QoS mechanisms built in, but others, such as some L2 WAN's, don't have QoS control in the provider cloud.
FAQ pages provide a simple way for you to supply and for customers to find answers to the most common questions about your company. Here are six reasons why your company website should have a FAQ page
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…

729 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question