Direct syslog messages from solaris 10...plz...help...
Solaris / OpenSolarisThis forum is for the discussion of Solaris, OpenSolaris, OpenIndiana, and illumos.
General Sun, SunOS and Sparc related questions also go here. Any Solaris fork or distribution is welcome.
Notices
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Get a virtual cloud desktop with the Linux distro that you want in less than five minutes with Shells! With over 10 pre-installed distros to choose from, the worry-free installation life is here! Whether you are a digital nomad or just looking for flexibility, Shells can put your Linux machine on the device that you want to use.
Exclusive for LQ members, get up to 45% off per month. Click here for more info.
Direct syslog messages from solaris 10...plz...help...
hi
I want to direct my syslog messages (from all routers ans switches) to the remote machine. Currently I stored them in a /logs/cis file using solaris 10 server.
cat /logs/cis
Oct 31 16:01:52 [10.XX.XXX.2.99.245] 30219: 4d00h: %LINK-3-UPDOWN: Interface FastEthernet0/15, changed state to down
Oct 31 16:01:55 [10.XX.XXX.2.13.180] 331: Oct 31 10:31:54.919: %LINK-3-UPDOWN: Interface Cellular0/0/0, changed state to up
Oct 31 16:01:55 [10.XX.XXX.2.213.180] 331: Oct 31 10:31:54.919: %LINK-3-UPDOWN: Interface Cellular0/0/0, changed state to up
Oct 31 16:01:57 [10.XX.XXX.2.199.245] 30220: 4d00h: %LINK-3-UPDOWN: Interface FastEthernet0/15, changed state to up
Oct 31 16:01:57 [10.XX.XXX.2.199.245] 30220: 4d00h: %LINK-3-UPDOWN: Interface FastEthernet0/15, changed state to up
My requirement is to direct these log to remote syslog server (which use as a backup for syslog messages)
hi
I want to direct my syslog messages (from all routers ans switches) to the remote machine. Currently I stored them in a /logs/cis file using solaris 10 server.
My requirement is to direct these log to remote syslog server (which use as a backup for syslog messages)
But still I cannot receive the logs from my remote machine. How can I achieve this. Please be kind enough to reply me.
Not sure what your question is. You say you want to put all your router and switch syslog messages to one server, and say that you CURRENTLY are doing this. Then say you want to put the syslogs onto a remote server...which you said you're already doing. ??????
Do you mean that you want your current central syslog server to be mirrored?? If so, you need to check out syslog-ng for Solaris, which will give you lots of flexibility, and let you do this.
Not sure what your question is. You say you want to put all your router and switch syslog messages to one server, and say that you CURRENTLY are doing this. Then say you want to put the syslogs onto a remote server...which you said you're already doing. ??????
Do you mean that you want your current central syslog server to be mirrored?? If so, you need to check out syslog-ng for Solaris, which will give you lots of flexibility, and let you do this.
Sorry for inconvenience , I wants to achive this.
I have solaris 10 server which collects syslog from Network Devices. Now I want to direct this to another syslog server.
Oct 31 16:01:52 [10.XX.XXX.2.99.245] 30219: 4d00h: %LINK-3-UPDOWN: Interface FastEthernet0/15, changed state to down
Oct 31 16:01:55 [10.XX.XXX.2.13.180] 331: Oct 31 10:31:54.919: %LINK-3-UPDOWN: Interface Cellular0/0/0, changed state to up
Oct 31 16:01:55 [10.XX.XXX.2.213.180] 331: Oct 31 10:31:54.919: %LINK-3-UPDOWN: Interface Cellular0/0/0, changed state to up
Oct 31 16:01:57 [10.XX.XXX.2.199.245] 30220: 4d00h: %LINK-3-UPDOWN: Interface FastEthernet0/15, changed state to up
Oct 31 16:01:57 [10.XX.XXX.2.199.245] 30220: 4d00h: %LINK-3-UPDOWN: Interface FastEthernet0/15, changed state to up
I want same thing to be appeared in another syslog server(these messages). Hope now you clear with my requirement.
I got the things work for me except one issue.Here's the config I used in /etc/syslog.conf
local7.warn @<remote server ip>
Now I can receve the same messages from remote syslog server except one issue.
Here's the original message from solaris 10 - 192.168.1.1
Nov 1 11:17:18 [10.1.1.1.204.75] 58: Nov 1 05:47:17: %SEC_LOGIN-1-QUIET_MODE_ON: Still timeleft for watching failures is 11 secs, [user: ] [Source: XX.XX.XX.XX] [localport: 22] [Reason: Login Authentication Failed] [ACL: sl_def_acl] at 11:17:17 CST Tue Nov 1 2011
But in the remote syslog server message changed slightly. Device ip (10.1.1.1) changed to syslog server ip (192.168.1.1)
Date 11-01-2011
Time 11:17:18
Priority Local7.err
Hostname 192.168.1.1
Message 58: Nov 1 05:47:17: %SEC_LOGIN-1- etc...
But in here this should not be the solaris ip it should be the actual device ip(10.1.1.1) which original message contains.I want to retain original source ip address without change it to forward ip/hostname.
Please provide me a way to achieve this.
Thanks
Last edited by harshaabba; 11-01-2011 at 05:02 AM.
hi all,
I got the things work for me except one issue.Here's the config I used in /etc/syslog.conf
local7.warn @<remote server ip>
Now I can receve the same messages from remote syslog server except one issue. Here's the original message from solaris 10 - 192.168.1.1 But in the remote syslog server message changed slightly. Device ip (10.1.1.1) changed to syslog server ip (192.168.1.1)
But in here this should not be the solaris ip it should be the actual device ip(10.1.1.1) which original message contains.I want to retain original source ip address without change it to forward ip/hostname.
I did in my first reply...use syslog-ng, instead of standard syslog.
And you could also put two syslog entries in your routers/switches, too, and accomplish the same thing.
I did in my first reply...use syslog-ng, instead of standard syslog.
And you could also put two syslog entries in your routers/switches, too, and accomplish the same thing.
hi all,
Thanks a lot for your replies. Im having another syslog server which runs syslog-ng. I modified the /etc/syslog-ng.conf
But Still I didnt receive the logs from the remote syslog server.
I test the loggins from installing the kiwi syslog server in remote_log_server. It displays a error. " I/O error occured while reading fd='13' ,error=Bad file descriptor (9)"
Thanks
Last edited by harshaabba; 11-02-2011 at 04:29 AM.
hi all,
Thanks a lot for your replies. Im having another syslog server which runs syslog-ng. I modified the /etc/syslog-ng.conf
But Still I didnt receive the logs from the remote syslog server.
I test the loggins from installing the kiwi syslog server in remote_log_server. It displays a error. " I/O error occured while reading fd='13' ,error=Bad file descriptor (9)"
Ok...unless BOTH servers are running syslog-ng, you shouldn't expect any different behavior. Also, again, you could add a second syslog entry on your switches/routers, and that would also solve your problem.
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.