Syslog > email

Posted on 2013-12-08
Last Modified: 2014-01-06
I have a very modest "requirement".  I would like to see messages, etc. that are received by my syslog server.
Currently I'm using the free Kiwi Syslog Server and all I get is a 24-hour summary/statistics by email.
I'd like to get emails that show me the information beyond statistics, such as the actual messages.

Since I view this as a "nice to have" capability, I don't want to spend much, if anything, in implementing it.

How would you recommend approaching this?
Everything is Windows.... no Server OSs
Question by:Fred Marshall
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
LVL 57

Expert Comment

ID: 39705194
Need to clarify what you want.  

1) Receive an single e-mail that contains all the messages received in the last "x" minutes.
2) Receive an e-mail with each message received as it receives it?
3) Something else?

Number 2 could be a LOT of e-mails.
LVL 26

Author Comment

by:Fred Marshall
ID: 39706349
LVL 57

Expert Comment

ID: 39706822
How often do you have Kiwi rotate the logs?

If you have Kiwi do daily logs you could write a script to do the e-mail.

How much log data do you have?  Splunk is free for up to 500 MB daily, I will have to check but it may be able to do this without you writing a script.

However, even though it is only a single e-mail a day, depending on your logs that could be a large e-mail.  I would think logging on to the Kiwi server and just looking at the logs would be easier.
NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

LVL 26

Author Comment

by:Fred Marshall
ID: 39711758
I surely can log into the Kiwi server and look. But, I don't want to do that - rather, I'd like the emails to show up in one place for review.  Not too unusual I should think.

Are you sure that the free Kiwi server will do this?

While the *summaries* come daily, I'd be happy to receive emails of the messages x-hourly.  Things are set up so that the message volume is low - so that's not a worry.
LVL 57

Expert Comment

ID: 39712050
-->  Not too unusual I should think.

Yes it is.  If your an environment that does not have a lot of data, you would typically just access the files either through RDP or a file share.   If your an environment that gets logs of messages, you would not want that traffic in your inbox.  We have GB's of syslog data every day.

--> Are you sure that the free Kiwi server will do this?

Kiwi can send an e-mail for  any/all syslog messages it receives as it receives it, but I doubt you want that.  If it get 10 messages, you get 10 e-mails, if it gets 1 million messages, you get 1 million messages.

The script I mentioned would be a Windows batch file or VBScript that could do this and Kiwi will allow you to schedule it.
LVL 26

Author Comment

by:Fred Marshall
ID: 39712458
Using RDP or a file share requires overt action.  That can be a disadvantage.  Just a perspective.

The free version of Kiwi doesn't support scripting......
LVL 57

Expert Comment

ID: 39713129
Then I would suggest you have Kiwi rotate logs on a daily  basis and then have Task Scheduler run a VBScript or Windows batch file to e-mail you the file.

I have not had time to check Splunk, but I know it can do a lot more  than Kiwi.
LVL 32

Accepted Solution

Kamran Arshad earned 500 total points
ID: 39726094
some of the options are;

SolarWinds NetFlow Analyzer      NetFlow/SFlow
Scrutinizer NetFlow/Sflow Analyzer      NetFlow/SFlow
Caligare Flow Inspector      NetFlow/SFlow
PRTG      NetFlow/RRDTool
Adventnet Netflow Analyzer      NetFlow
NFSen      NetFlow
StealthWatch® Xe      SFlow
Traffic Sentinel      SFlow
Splunk      Propriety
LVL 26

Author Closing Comment

by:Fred Marshall
ID: 39761273
I ended up using PRTG as it is already in use here.

Featured Post

Retailers - Is your network secure?

With the prevalence of social media & networking tools, for retailers, reputation is critical. Have you considered the impact your network security could have in your customer's experience? Learn more in our Retail Security Resource Kit Today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
David Varnum recently wrote up his impressions of PRTG, based on a presentation by my colleague Christian at Tech Field Day at VMworld in Barcelona. Thanks David, for your detailed and honest evaluation!
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor ( If you're looking for how to monitor bandwidth using netflow or packet s…
Michael from AdRem Software outlines event notifications and Automatic Corrective Actions in network monitoring. Automatic Corrective Actions are scripts, which can automatically run upon discovery of a certain undesirable condition in your network.…

724 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question