LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-15-2008, 06:30 AM   #1
hattori.hanzo
Member
 
Registered: Aug 2006
Posts: 168

Rep: Reputation: 15
logwatch 'windows' service


I got a centralized syslog box (centos 5, syslog-ng) setup and have added some syslog feeds (via evtsys.exe from purdue university) from windows servers.

Code:
[hh@box1 conf]$ sudo logwatch --logfile /var/log/HOSTS/aaa.bbb.ccc.ddd/2008/10/15/windows --debug medium --service windows
Logwatch is not configured to use logfile: /var/log/hosts/aaa.bbb.ccc.ddd/2008/10/15/windows
I keep getting an error messaging saying logwatch is not configured to use the logfile. Is their anything special which needs to be configured for logwatch to process windows syslog events? I checked the logwatch 'services' directory and can see the 'windows' perl script and also the window.conf is on the box.

Logwatch processes all my other logs without issues or configuration.

regards
 
Old 11-15-2008, 06:35 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Check windows.conf for the right names slash globbing?
 
Old 11-15-2008, 07:30 AM   #3
hattori.hanzo
Member
 
Registered: Aug 2006
Posts: 168

Original Poster
Rep: Reputation: 15
Thanks. I got logwatch to parse the files. Looks like logwatch doesnt like directories named as 'all caps' in the path to the log files.

Unfortuantely, the logwatch report doesnt not make sense. Looks like the parsing did not like the format of the windows syslog file.

I am using syslog-ng, I wonder if this could be a problem.

edit: looks like this format is required:

Quote:
($month, $day, $time, $host, $process, $eventid, $msg) = split(/\s+/, $line, 7);
regards,

Last edited by hattori.hanzo; 11-15-2008 at 07:54 AM.
 
Old 12-29-2008, 09:54 AM   #4
cmnorton
Member
 
Registered: Feb 2005
Distribution: Ubuntu, CentOS
Posts: 585

Rep: Reputation: 35
Additional Information

I found some interesting links relating to this topic:

http://lists.sans.org/pipermail/unis...ly/026571.html
http://lists.sans.org/pipermail/unis...ly/026572.html
 
Old 12-30-2008, 07:35 PM   #5
hattori.hanzo
Member
 
Registered: Aug 2006
Posts: 168

Original Poster
Rep: Reputation: 15
Thanks. Those are good alternatives.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
restarting network service in windows nick021 Linux - General 1 12-16-2006 04:20 AM
how to add service in windows ajkannan83 General 3 09-12-2005 01:36 PM
Add service in windows ajkannan83 Linux - Software 2 09-12-2005 09:32 AM
Add service in windows ajkannan83 General 2 09-12-2005 03:14 AM
Windows XP service pack 2 Murdock1979 General 10 07-12-2005 11:24 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:57 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration