LinuxQuestions.org
LinuxAnswers - the LQ Linux tutorial section.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices

Reply
 
Search this Thread
Old 03-29-2010, 12:01 AM   #1
gutiojj
LQ Newbie
 
Registered: Feb 2010
Posts: 5

Rep: Reputation: 0
How to config rsyslog on Fedora 10 to collect the log from Cisco ASA5510 ?


Dear all,

I have set up one Fedora 10 server.
I found that rsyslog service is running on Fedora 10 server.

How to configure rsyslog on Fedora 10 to collect the log from Cisco ASA5510 ?

Thanks !


Rgds,
Gutio
 
Old 03-29-2010, 02:43 AM   #2
John VV
Guru
 
Registered: Aug 2005
Posts: 12,901

Rep: Reputation: 1713Reputation: 1713Reputation: 1713Reputation: 1713Reputation: 1713Reputation: 1713Reputation: 1713Reputation: 1713Reputation: 1713Reputation: 1713Reputation: 1713
Quote:
I have set up one Fedora 10 server.
First
STOP right there
Fedora 10 IS not supported any longer !
There will NEVER be any updates to it ever!
No security updates, and NO support.

and UNLESS YOU LIKE reinstalling a server EVERY 6 MONTHS do not but fedora on it!

i would install a long life like CentOS 5.4
 
Old 03-30-2010, 03:08 PM   #3
CmdoColin
Member
 
Registered: Jul 2009
Posts: 31

Rep: Reputation: 17
As a router / firewall engineer 16 months ago I knew nothing about Linux. To be fair, at the time I really couldn't give a hoot about anything Linux / Unix based. It was all about the next Cisco certification. I used completely the wrong distro of Linux to use as a syslog server then. Yes it was Fedora 10, and the reason I picked it was because my girlfriend lived in Cambridge at the time. Since then I've learned a huge amount, and I still know nothing - but you know what, I actually care about my operating system now.

Yes, you are using the wrong operating system, but you like me 16 months ago don't care. You will learn, and I hope you have as much fun learning as I still am. =) We all need somewhere to start, so:

Config the asa:

Code:
logging enable
logging timestamp
logging monitor notifications
logging buffered informational
logging trap notifications
logging asdm notifications
logging host inside X.X.X.X
Replace the X.X.X.X with the IP address of the fedora server. Hopefully you've worked out how to nail down a fixed IP address with fedora - took me sometime, the default was DHCP when I installed. It's not as *pretty* as the "show interface ip brief"; but "ifconfig" will give you the IP address if you haven't worked that out.

Now, most guides out there tell you to modify your rsyslog config. I don't remember having to do this - and it worked... A file to check if you are having trouble is: /etc/rsyslog.conf This file should have these lines looking like this:

Code:
$ModLoad imudp.so  
$UDPServerRun 514
If you've have a # in front of them they are "commented" out, so they will need removing. If you do need to change this file, then the rsyslog will need restarting to apply this:

Code:
system rsyslog restart
A couple of checks for syslog (and good for faulting it) are; first see if it is running:

Code:
ps aux | grep -i rsyslog
You'll see the "grep" line and hopefully syslog running.

What you'll also want to check is to see if Fedora is listening for syslog messages. You can check to see if it's *listening* to the syslog messages by running:

Code:
netstat -an | grep 514
514 as you'll know is the port number for syslog messages.

The final thing that can cause problems is the firewall within Fedora. This is known as IPtables, it a mild pain to get your head around, But is a solid firewall the more you learn about it =) The way to check this is to run this command:

Code:
more /etc/sysconfig/iptables
A line your looking for is:

Code:
-A INPUT -m state --state NEW -m udp -p udp --dport 514 -j ACCEPT
If that is all there - then you should be able to see the syslog messages in the log file. You can read this via using the command:

Code:
more /var/log/messages
A really useful command when setting up syslog for the first time is to have a terminal open with this command running:

Code:
tail -f /var/log/messages
It updates dynamically in real time - great to see when the first messages start rolling in. =) Think of it in Cisco command terminology as having "term mon on"

Sure there is a whole lot more that you can do with syslog and where those files go. This will hopefully get you started. If you are in the same place I was 16 months ago with no-one to help you learn, good luck. It ain't an easy road, but seriously satisfying - I seem to get more job satisfaction playing in Linux than with Cisco kit now. If you are as new to Linux as I was, I'd honestly look at Ubuntu as an operating system. Not telling you its a perfect distro - but their community has been really good to me as a linux virgin with lots of daft questions. That to me has been the biggest factor in sticking with Linux, rather than an ideal supported distro.

Any problems with it, definately shout, hopefully I can help out.

Cheers

CC
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
config.log shows failure in sanity check for wxGTK on Fedora platform rfee Linux - Software 1 10-25-2008 12:24 AM
Syslog-ng unable to log Cisco Logs Mohd Anis Linux - Server 3 09-03-2008 04:14 AM
how to write log data to disk when the server is down while using rsyslog prakash.akumalla Linux - Newbie 1 06-25-2008 01:15 AM
anyone using rsyslog? slackamp Slackware 1 10-16-2007 09:55 PM
how can i config. switches & cisco-routers. rahuldevalone Linux - Networking 2 02-19-2007 08:13 AM


All times are GMT -5. The time now is 04:54 AM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration