Solved

Syslog > email

Posted on 2013-12-08
9
308 Views
Last Modified: 2014-01-06
I have a very modest "requirement".  I would like to see messages, etc. that are received by my syslog server.
Currently I'm using the free Kiwi Syslog Server and all I get is a 24-hour summary/statistics by email.
I'd like to get emails that show me the information beyond statistics, such as the actual messages.

Since I view this as a "nice to have" capability, I don't want to spend much, if anything, in implementing it.

How would you recommend approaching this?
Everything is Windows.... no Server OSs
0
Comment
Question by:Fred Marshall
  • 4
  • 4
9 Comments
 
LVL 57

Expert Comment

by:giltjr
ID: 39705194
Need to clarify what you want.  

1) Receive an single e-mail that contains all the messages received in the last "x" minutes.
2) Receive an e-mail with each message received as it receives it?
3) Something else?

Number 2 could be a LOT of e-mails.
0
 
LVL 25

Author Comment

by:Fred Marshall
ID: 39706349
#1
0
 
LVL 57

Expert Comment

by:giltjr
ID: 39706822
How often do you have Kiwi rotate the logs?

If you have Kiwi do daily logs you could write a script to do the e-mail.

How much log data do you have?  Splunk is free for up to 500 MB daily, I will have to check but it may be able to do this without you writing a script.

However, even though it is only a single e-mail a day, depending on your logs that could be a large e-mail.  I would think logging on to the Kiwi server and just looking at the logs would be easier.
0
 
LVL 25

Author Comment

by:Fred Marshall
ID: 39711758
I surely can log into the Kiwi server and look. But, I don't want to do that - rather, I'd like the emails to show up in one place for review.  Not too unusual I should think.

Are you sure that the free Kiwi server will do this?

While the *summaries* come daily, I'd be happy to receive emails of the messages x-hourly.  Things are set up so that the message volume is low - so that's not a worry.
0
New My Cloud Pro Series - organize everything!

With space to keep virtually everything, the My Cloud Pro Series offers your team the network storage to edit, save and share production files from anywhere with an internet connection. Compatible with both Mac and PC, you're able to protect your content regardless of OS.

 
LVL 57

Expert Comment

by:giltjr
ID: 39712050
-->  Not too unusual I should think.

Yes it is.  If your an environment that does not have a lot of data, you would typically just access the files either through RDP or a file share.   If your an environment that gets logs of messages, you would not want that traffic in your inbox.  We have GB's of syslog data every day.

--> Are you sure that the free Kiwi server will do this?

Kiwi can send an e-mail for  any/all syslog messages it receives as it receives it, but I doubt you want that.  If it get 10 messages, you get 10 e-mails, if it gets 1 million messages, you get 1 million messages.

The script I mentioned would be a Windows batch file or VBScript that could do this and Kiwi will allow you to schedule it.
0
 
LVL 25

Author Comment

by:Fred Marshall
ID: 39712458
Using RDP or a file share requires overt action.  That can be a disadvantage.  Just a perspective.

The free version of Kiwi doesn't support scripting......
0
 
LVL 57

Expert Comment

by:giltjr
ID: 39713129
Then I would suggest you have Kiwi rotate logs on a daily  basis and then have Task Scheduler run a VBScript or Windows batch file to e-mail you the file.

I have not had time to check Splunk, but I know it can do a lot more  than Kiwi.
0
 
LVL 32

Accepted Solution

by:
Kamran Arshad earned 500 total points
ID: 39726094
some of the options are;

SolarWinds NetFlow Analyzer      www.solarwinds.com      NetFlow/SFlow
Scrutinizer NetFlow/Sflow Analyzer      www.plixer.com      NetFlow/SFlow
Caligare Flow Inspector      www.caligare.com      NetFlow/SFlow
PRTG      www.paessler.com/prtg      NetFlow/RRDTool
Adventnet Netflow Analyzer      www.adventnet.com      NetFlow
NFSen      nfsen.sourceforge.net      NetFlow
StealthWatch® Xe       www.lancope.com      SFlow
Traffic Sentinel      www.inmon.com      SFlow
Splunk      www.splunk.com      Propriety
0
 
LVL 25

Author Closing Comment

by:Fred Marshall
ID: 39761273
I ended up using PRTG as it is already in use here.
0

Featured Post

Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
When it comes to security, there are always trade-offs between security and convenience/ease of administration. This article examines some of the main pros and cons of using key authentication vs password authentication for hosting an SFTP server.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now