[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Advice on settinng up a syslog server

Posted on 2011-02-16
11
Medium Priority
?
339 Views
Last Modified: 2012-05-11
I need to setup a syslog server and need some advice.  I need something that can record log entries for Windows desktops and servers, Unix servers, Linux desktops and servers, as well as network devices such as routers, switches etc.  

So my questions are:

1. What is a good, cross platform, syslog server that can be setup.  I prefer open source options but am open to all ideas.

2. For a syslog server to correctly record log data, do I have to configure all the clients to send their log data TO the syslog server or does the syslog server go out and collect data FROM the clients?

3.  Can I have windows send all event logs to a syslog server or does it only record certain types of entries?

Thanks in advance!
0
Comment
Question by:arstacey
  • 4
  • 3
  • 3
  • +1
11 Comments
 
LVL 11

Accepted Solution

by:
sysreq2000 earned 1000 total points
ID: 34909346
1. Kiwi is a decent free syslog server. Google kiwi syslog you will find it.

2. You must configure devices to send to the syslog, it is push not a pull system.

3. Dunno.  8)  I'm not aware of a way to redirect event viewer to syslog but there might be a way.
0
 
LVL 3

Assisted Solution

by:Richard2k4
Richard2k4 earned 1000 total points
ID: 34909354
There is a free utility that I used to use called Snare.  It will send a copy of all event logs to a syslog server or their own free server.
0
 

Author Comment

by:arstacey
ID: 34909365
I have heard of kiwi but in reading I wasn't sure if it accepted syslog entries from all devices or just certain types.
0
New Tabletop Appliances Blow Competitors Away!

WatchGuard’s new T15, T35 and T55 tabletop UTMs provide the highest-performing security inspection in their class, allowing users at small offices, home offices and distributed enterprises to experience blazing-fast Internet speeds without sacrificing enterprise-grade security.

 
LVL 11

Expert Comment

by:sysreq2000
ID: 34909378
OK looks like no native way to send windows events to syslog but there are utilities to do it:

http://www.google.ca/#hl=en&biw=1266&bih=734&q=how+to+send+windows+events+to+syslog&aq=f&aqi=g-v1&aql=&oq=&fp=e1d57483344a3fed
0
 
LVL 11

Expert Comment

by:sysreq2000
ID: 34909395
haha, EE needs to refresh more often  8)
0
 
LVL 11

Expert Comment

by:sysreq2000
ID: 34909411
Hmmm, I think Kiwi is pretty much across the board. I've used it for 3com and cisco but I'd be surprised if anything didn't work on it.
0
 

Author Comment

by:arstacey
ID: 34909432
Awesome guys.  Thanks for the advice.  I am going to check out kiwi over the next few days and see how it goes.  Thanks for the link too Richard.  That is exactly what I want.  I am a lone sys admin and don't have time to manually review event logs all day lol.
0
 
LVL 3

Expert Comment

by:Richard2k4
ID: 34909451
You will love Kiwi.  You can configure it to look for specified event log or syslogs and it will alert you via email or any other way you configure.
0
 
LVL 1

Expert Comment

by:Pedram-z
ID: 34921628
I also suggest to use free version of Splunk. Such a great tool!
0
 

Author Closing Comment

by:arstacey
ID: 35149036
Thanks guys.  Kiwi looks great and snare may take care of my event log issues as well.
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
A big percent of today’s marketing activity is performed through the online environment. The marketing strategies that have existed a decade ago no longer relate to what’s happening today. We’re currently facing a revolutionary era, called the digit…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…
Suggested Courses

868 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question