LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 06-27-2014, 09:32 AM   #1
andrewhiggs
LQ Newbie
 
Registered: Apr 2010
Location: ZA
Distribution: Slackware 13, Ubuntu 9.10
Posts: 21

Rep: Reputation: 11
Windows -> syslog -> syslog


Hi all,

I have a Slackware router / firewall in each of our stores. These do remote logging to a Slackware server here at HO. I have windows machines in the stores which I have logging to the syslog on the router / firewall.

What I would like is for all the windows events arriving at the firewall syslog to also go through to the remote syslog at HO. Can this be done?

I thought getting the windows logging through to the firewall would automatically make it log to the remote server too.

Any assistance would be greatly appreciated. Thanks

Regards
 
Old 06-27-2014, 11:59 AM   #2
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 27,808

Rep: Reputation: 8225Reputation: 8225Reputation: 8225Reputation: 8225Reputation: 8225Reputation: 8225Reputation: 8225Reputation: 8225Reputation: 8225Reputation: 8225Reputation: 8225
Quote:
Originally Posted by andrewhiggs View Post
Hi all,
I have a Slackware router / firewall in each of our stores. These do remote logging to a Slackware server here at HO. I have windows machines in the stores which I have logging to the syslog on the router / firewall.

What I would like is for all the windows events arriving at the firewall syslog to also go through to the remote syslog at HO. Can this be done?

I thought getting the windows logging through to the firewall would automatically make it log to the remote server too.
Windows systems (by default), don't send anything to *nix syslog servers. You would have to load and configure some sort of syslog daemon on the Windows system, such as:
http://edoceo.com/creo/winlogd

If you are seeing Windows events on the Slack systems now, then you may just have to configure what's getting sent to the 'mirror' syslog server, so those events are passed along. They may look different than what's getting logged now.
 
1 members found this post helpful.
Old 06-27-2014, 01:26 PM   #3
Richard Cranium
Senior Member
 
Registered: Apr 2009
Location: McKinney, Texas
Distribution: Slackware64 15.0
Posts: 3,860

Rep: Reputation: 2230Reputation: 2230Reputation: 2230Reputation: 2230Reputation: 2230Reputation: 2230Reputation: 2230Reputation: 2230Reputation: 2230Reputation: 2230Reputation: 2230
From "man syslogd"...
Code:
       With  normal  syslogds  you would get syslog-loops if you send out mes-
       sages that were received from a remote host to the same host  (or  more
       complicated to a third host that sends it back to the first one, and so
       on).  In my domain (Infodrom Oldenburg) we accidently got one  and  our
       disks filled up with the same single message. :-(

       To  avoid  this no messages received from a remote host are sent out to
       another (or the same) remote host anymore.  If you experience are setup
       in  which  you  need  this  behaviour,  please  use the -h command line
       switch.  However, this option needs to be handled with caution since  a
       syslog loop can fill up hard disks quite fast.
Bolding added. I haven't checked to see if the man page is lying.
 
Old 06-27-2014, 06:52 PM   #4
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Collecting and forwarding logs from Windows
Syslog Agent
nxlog
syslog-ng

for starters.
 
Old 06-30-2014, 04:08 AM   #5
andrewhiggs
LQ Newbie
 
Registered: Apr 2010
Location: ZA
Distribution: Slackware 13, Ubuntu 9.10
Posts: 21

Original Poster
Rep: Reputation: 11
Hi TBOne, Richard and Habitual

Thanks all for the replies. I already had the windows machine logging to the first syslog server so the software on windows was already working.

Richard, your hit worked. I feel a bit embarrassed that the answer to my question was actually in the man page. But thank you very much for pointing it out so politely. :-) It worked so all is sorted now. You are a star.

Regards
 
1 members found this post helpful.
Old 06-30-2014, 09:04 AM   #6
TB0ne
LQ Guru
 
Registered: Jul 2003
Location: Birmingham, Alabama
Distribution: SuSE, RedHat, Slack,CentOS
Posts: 27,808

Rep: Reputation: 8225Reputation: 8225Reputation: 8225Reputation: 8225Reputation: 8225Reputation: 8225Reputation: 8225Reputation: 8225Reputation: 8225Reputation: 8225Reputation: 8225
Quote:
Originally Posted by andrewhiggs View Post
Hi TBOne, Richard and Habitual

Thanks all for the replies. I already had the windows machine logging to the first syslog server so the software on windows was already working.

Richard, your hit worked. I feel a bit embarrassed that the answer to my question was actually in the man page. But thank you very much for pointing it out so politely. :-) It worked so all is sorted now. You are a star.
Thanks for posting back with the solution, and letting folks know what worked for you.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
syslog-ng -> syslog-ng logging, how to troubleshoot sir-lancealot Linux - Server 1 01-24-2009 06:07 AM
LXer: OpenLDAP Quick Tips: Using syslog or syslog-ng with slapd for OpenLDAP logging LXer Syndicated Linux News 0 11-14-2008 08:41 PM
I need help getting syslog to log remotely, this is just the regular syslog. abefroman Linux - Software 2 06-05-2008 11:36 AM
syslog client to log to syslog-ng and itself noir911 Linux - Server 1 02-08-2008 09:51 AM
LXer: Centralized Syslog Server Using syslog-NG LXer Syndicated Linux News 0 04-28-2006 06:21 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 07:26 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration