LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 05-18-2005, 07:35 AM   #1
graycat
LQ Newbie
 
Registered: May 2005
Location: Leeds
Posts: 6

Rep: Reputation: 0
new project for work and could do with some help


hey all!

well i'm complete beginner when it comes to linux of pretty much any type (other than a few liveCDs) but i've decided on a challenge / project that'll hopefully resolve this.

basically what i'm going to try is to build a centralized event log monitoring system to pull all the logs from the windows servers on our network using linux and only free software. this may be expanded later on to cover IDS, but lets not get ahead of ourselves just yet!

as far as i can see, i'm going to have to break the project down into these sections:
find and install an OS
find some way of pulling event logs of a win2k server
look into database storage - i'm thinking mySQL or similar
develop the reporting and alerting side.

as i'm starting from fresh i could do with as many suggestions / comments as possible really, but my first questions are:

has this been done before?
what flavor of linux would you recommend for this kind of project?
how demanding on the hardware do you think this would be? i've got a few soon to be retired ex-NT4 desktops that i'm thinking of using
have i bitten off more than i can chew? lol

Cheers, all.

Tim.
 
Old 05-18-2005, 08:03 AM   #2
Crashed_Again
Senior Member
 
Registered: Dec 2002
Location: Atlantic City, NJ
Distribution: Ubuntu & Arch
Posts: 3,503

Rep: Reputation: 57
Well, at first glance I'm thinking you would use Samba to move the files from the win2k server to the linux machine. I don't think the distribution you use is that crucial here. Go with whatever distro you are comfortable with. Then you can write a little program to get the event logs and store them in mysql.

Not sure how or what you want to display from the events log. Do you want to write your own software for this or are you looking for pre existing software? Also, do you want this to be in real time or have it batch update every hour or 10 minutes or whatever?
 
Old 05-18-2005, 08:03 AM   #3
Kdr Kane
Member
 
Registered: Jan 2005
Distribution: SUSE, LFS
Posts: 357

Rep: Reputation: 30
find some way of pulling event logs of a win2k server

There is your problem. Better work on that before wasting your time on anything else.

Frankly, you're better off with a Windows solution in this case.
 
Old 05-18-2005, 08:34 AM   #4
graycat
LQ Newbie
 
Registered: May 2005
Location: Leeds
Posts: 6

Original Poster
Rep: Reputation: 0
Quote:
Originally posted by Crashed_Again
Well, at first glance I'm thinking you would use Samba to move the files from the win2k server to the linux machine. I don't think the distribution you use is that crucial here. Go with whatever distro you are comfortable with. Then you can write a little program to get the event logs and store them in mysql.

Not sure how or what you want to display from the events log. Do you want to write your own software for this or are you looking for pre existing software? Also, do you want this to be in real time or have it batch update every hour or 10 minutes or whatever?
One of the ways i've come across so far is to install something to push the logs out to a syslog server..... but i'm still looking into that bit lol i've found eventreporter so far.... but that cost money

ideally i'd like the logs to be dumped into a database so that they can be archived and I can run searches / queries against it looking for trends etc. on the running side, i'd love it to be real time but i think that might be asking a little much. If i can get it to run every few minutes then i'd be a happy bunny.

i've never writen software before from scratch so I think that'd be beyond me at the moment. I'd like to have a few bits of software that do the individaul sections and then work on getting them working together.



Kdr Kane, i know there's ways of doing it as i've run across a few bits and pieces of software that would fill the bill. so hopefully there'll be some freebe ones out there somewhere too I must admit, using a windows solution was my first idea but i'd like to give this linux lark a crack and see how it all shapes up. It'll probably be tricky, but i'm in no great rush and am looking forward to the challenge

Last edited by graycat; 05-18-2005 at 08:38 AM.
 
Old 05-18-2005, 08:47 AM   #5
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
i think if you have samba on the linux server you could make the windows server do all the logging to the samba server... or at least make it copy the logs to the samba server every few minutes... once you have the windows box logging to the linux box via samba, then you can focus on getting those logs into the mysql databse... anyways, it's just a thought...
 
Old 05-18-2005, 12:23 PM   #6
Genesee
Member
 
Registered: Dec 2002
Distribution: Slackware
Posts: 927

Rep: Reputation: 30
I'm not familiar with the topic so I can't suggest specifics, but freshmeat lists 361 projects related to "logging" and 8 also relating to ms environments - there might be something useful in there:

http://freshmeat.net/browse/148/

 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Looking for a programmer to work on a PAID project purelithium Programming 2 11-15-2005 07:09 AM
how does project blackdog work? netcrusher88 Linux - Hardware 0 11-11-2005 01:35 PM
Project for work rodneybeighle Programming 4 09-07-2005 03:45 AM
Beginning a big project - Need an Good Project Manager gamehack Programming 3 01-15-2004 11:49 AM
Cannot see Open GL project in KDevelop project wizard SparceMatrix Programming 2 08-07-2002 11:14 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 11:31 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration