Solved

Syslog > email

Posted on 2013-12-08
9
314 Views
Last Modified: 2014-01-06
I have a very modest "requirement".  I would like to see messages, etc. that are received by my syslog server.
Currently I'm using the free Kiwi Syslog Server and all I get is a 24-hour summary/statistics by email.
I'd like to get emails that show me the information beyond statistics, such as the actual messages.

Since I view this as a "nice to have" capability, I don't want to spend much, if anything, in implementing it.

How would you recommend approaching this?
Everything is Windows.... no Server OSs
0
Comment
Question by:Fred Marshall
  • 4
  • 4
9 Comments
 
LVL 57

Expert Comment

by:giltjr
ID: 39705194
Need to clarify what you want.  

1) Receive an single e-mail that contains all the messages received in the last "x" minutes.
2) Receive an e-mail with each message received as it receives it?
3) Something else?

Number 2 could be a LOT of e-mails.
0
 
LVL 25

Author Comment

by:Fred Marshall
ID: 39706349
#1
0
 
LVL 57

Expert Comment

by:giltjr
ID: 39706822
How often do you have Kiwi rotate the logs?

If you have Kiwi do daily logs you could write a script to do the e-mail.

How much log data do you have?  Splunk is free for up to 500 MB daily, I will have to check but it may be able to do this without you writing a script.

However, even though it is only a single e-mail a day, depending on your logs that could be a large e-mail.  I would think logging on to the Kiwi server and just looking at the logs would be easier.
0
DevOps Toolchain Recommendations

Read this Gartner Research Note and discover how your IT organization can automate and optimize DevOps processes using a toolchain architecture.

 
LVL 25

Author Comment

by:Fred Marshall
ID: 39711758
I surely can log into the Kiwi server and look. But, I don't want to do that - rather, I'd like the emails to show up in one place for review.  Not too unusual I should think.

Are you sure that the free Kiwi server will do this?

While the *summaries* come daily, I'd be happy to receive emails of the messages x-hourly.  Things are set up so that the message volume is low - so that's not a worry.
0
 
LVL 57

Expert Comment

by:giltjr
ID: 39712050
-->  Not too unusual I should think.

Yes it is.  If your an environment that does not have a lot of data, you would typically just access the files either through RDP or a file share.   If your an environment that gets logs of messages, you would not want that traffic in your inbox.  We have GB's of syslog data every day.

--> Are you sure that the free Kiwi server will do this?

Kiwi can send an e-mail for  any/all syslog messages it receives as it receives it, but I doubt you want that.  If it get 10 messages, you get 10 e-mails, if it gets 1 million messages, you get 1 million messages.

The script I mentioned would be a Windows batch file or VBScript that could do this and Kiwi will allow you to schedule it.
0
 
LVL 25

Author Comment

by:Fred Marshall
ID: 39712458
Using RDP or a file share requires overt action.  That can be a disadvantage.  Just a perspective.

The free version of Kiwi doesn't support scripting......
0
 
LVL 57

Expert Comment

by:giltjr
ID: 39713129
Then I would suggest you have Kiwi rotate logs on a daily  basis and then have Task Scheduler run a VBScript or Windows batch file to e-mail you the file.

I have not had time to check Splunk, but I know it can do a lot more  than Kiwi.
0
 
LVL 32

Accepted Solution

by:
Kamran Arshad earned 500 total points
ID: 39726094
some of the options are;

SolarWinds NetFlow Analyzer      www.solarwinds.com      NetFlow/SFlow
Scrutinizer NetFlow/Sflow Analyzer      www.plixer.com      NetFlow/SFlow
Caligare Flow Inspector      www.caligare.com      NetFlow/SFlow
PRTG      www.paessler.com/prtg      NetFlow/RRDTool
Adventnet Netflow Analyzer      www.adventnet.com      NetFlow
NFSen      nfsen.sourceforge.net      NetFlow
StealthWatch® Xe       www.lancope.com      SFlow
Traffic Sentinel      www.inmon.com      SFlow
Splunk      www.splunk.com      Propriety
0
 
LVL 25

Author Closing Comment

by:Fred Marshall
ID: 39761273
I ended up using PRTG as it is already in use here.
0

Featured Post

3 Use Cases for Connected Systems

Our Dev teams are like yours. They’re continually cranking out code for new features/bugs fixes, testing, deploying, testing some more, responding to production monitoring events and more. It’s complex. So, we thought you’d like to see what’s working for us.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

David Varnum recently wrote up his impressions of PRTG, based on a presentation by my colleague Christian at Tech Field Day at VMworld in Barcelona. Thanks David, for your detailed and honest evaluation!
I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

803 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question