I got a centralized syslog box (centos 5, syslog-ng) setup and have added some syslog feeds (via evtsys.exe from purdue university) from windows servers.
Code:
[hh@box1 conf]$ sudo logwatch --logfile /var/log/HOSTS/aaa.bbb.ccc.ddd/2008/10/15/windows --debug medium --service windows
Logwatch is not configured to use logfile: /var/log/hosts/aaa.bbb.ccc.ddd/2008/10/15/windows
I keep getting an error messaging saying logwatch is not configured to use the logfile. Is their anything special which needs to be configured for logwatch to process windows syslog events? I checked the logwatch 'services' directory and can see the 'windows' perl script and also the window.conf is on the box.
Logwatch processes all my other logs without issues or configuration.
regards