Solved

Advice on settinng up a syslog server

Posted on 2011-02-16
11
334 Views
Last Modified: 2012-05-11
I need to setup a syslog server and need some advice.  I need something that can record log entries for Windows desktops and servers, Unix servers, Linux desktops and servers, as well as network devices such as routers, switches etc.  

So my questions are:

1. What is a good, cross platform, syslog server that can be setup.  I prefer open source options but am open to all ideas.

2. For a syslog server to correctly record log data, do I have to configure all the clients to send their log data TO the syslog server or does the syslog server go out and collect data FROM the clients?

3.  Can I have windows send all event logs to a syslog server or does it only record certain types of entries?

Thanks in advance!
0
Comment
Question by:arstacey
  • 4
  • 3
  • 3
  • +1
11 Comments
 
LVL 11

Accepted Solution

by:
sysreq2000 earned 250 total points
ID: 34909346
1. Kiwi is a decent free syslog server. Google kiwi syslog you will find it.

2. You must configure devices to send to the syslog, it is push not a pull system.

3. Dunno.  8)  I'm not aware of a way to redirect event viewer to syslog but there might be a way.
0
 
LVL 3

Assisted Solution

by:Richard2k4
Richard2k4 earned 250 total points
ID: 34909354
There is a free utility that I used to use called Snare.  It will send a copy of all event logs to a syslog server or their own free server.
0
 

Author Comment

by:arstacey
ID: 34909365
I have heard of kiwi but in reading I wasn't sure if it accepted syslog entries from all devices or just certain types.
0
Easy, flexible multimedia distribution & control

Coming soon!  Ideal for large-scale A/V applications, ATEN's VM3200 Modular Matrix Switch is an all-in-one solution that simplifies video wall integration. Easily customize display layouts to see what you want, how you want it in 4k.

 
LVL 3

Expert Comment

by:Richard2k4
ID: 34909368
0
 
LVL 11

Expert Comment

by:sysreq2000
ID: 34909378
OK looks like no native way to send windows events to syslog but there are utilities to do it:

http://www.google.ca/#hl=en&biw=1266&bih=734&q=how+to+send+windows+events+to+syslog&aq=f&aqi=g-v1&aql=&oq=&fp=e1d57483344a3fed
0
 
LVL 11

Expert Comment

by:sysreq2000
ID: 34909395
haha, EE needs to refresh more often  8)
0
 
LVL 11

Expert Comment

by:sysreq2000
ID: 34909411
Hmmm, I think Kiwi is pretty much across the board. I've used it for 3com and cisco but I'd be surprised if anything didn't work on it.
0
 

Author Comment

by:arstacey
ID: 34909432
Awesome guys.  Thanks for the advice.  I am going to check out kiwi over the next few days and see how it goes.  Thanks for the link too Richard.  That is exactly what I want.  I am a lone sys admin and don't have time to manually review event logs all day lol.
0
 
LVL 3

Expert Comment

by:Richard2k4
ID: 34909451
You will love Kiwi.  You can configure it to look for specified event log or syslogs and it will alert you via email or any other way you configure.
0
 
LVL 1

Expert Comment

by:Pedram-z
ID: 34921628
I also suggest to use free version of Splunk. Such a great tool!
0
 

Author Closing Comment

by:arstacey
ID: 35149036
Thanks guys.  Kiwi looks great and snare may take care of my event log issues as well.
0

Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

If you are thinking of adopting cloud services, or just curious as to what ‘the cloud’ can offer then the leader according to Gartner for Infrastructure as a Service (IaaS) is Amazon Web Services (AWS).  When I started using AWS I was completely new…
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question