Recommended product for syslogging and snmp monitoring

Hi,
    We currently use KIWI syslog but can anyone recommend a better product for syslogs from Firewalls, Routers and Switches. Our current product creates a seperate text file per day per device. Ideally I would like all these to be combined (or combinable for display purposes) into one log that shows to update realtime and have the ability to filterout "background noise" - stuff we know is acceptable, as well as being able to run simple or quick searches and reports. Ideally for asbout 200+ devices.
     Am I too hopeful or is there a product out there that can do this (that also will not break my companies bank account).
     Also, recommended products for SNMP monitoring if better than we currently use would be useful - currently using Orion and SNMPc.
Regards
Adrian

Adrian,
We use syslog-ng for RHEL. It can do what you need as far as writing to files and filtering out background noise, but it is not a search/reporting tool. If KIWI does the latter, I imagine you could tell it to read from the file that syslog-ng creates.
It is open source for writing files through version 3.1.4. Later versions require licensing to write to files or if you are using a Windows OS.
http://www.balabit.com/downloads/files/syslog-ng/open-source-edition/3.1.4
Here are some other options:
Rsyslog: http://www.rsyslog.com/
Splunk: http://www.splunk.com/
Snare: http://www.intersectalliance.com/projects/index.html
Hope this helps.
Steve Lee
Emory University

Similar Messages

  • ACE and ANM, Syslog and SNMP Traps

    Hi guys.. another ACE/ANM question.
    I configured the ACE devices to send Syslog and SNMP messages to the ANM server. But i got a couple of questions:
    Whats the difference between using the:
    logging history 4 (this would send logging messages as SNMP traps according to doc)
    And:
    snmp-server host x.x.x.x traps version 2c public
    snmp-server trap-source vlan 1000
    This of course I think should do the same..
    The funny and weird thing, in the ANM Event viewer, I can only see syslog messages, not one snmp event.
    Thanks!
    Omar
    PS: ACE ver A2.4
          ANM Ver 4.2

    Hi Omar,
    Let's see if I can clarify your questions.
    As you mentioned, the "logging history 4" command specifies that, syslog messages of severity 4 and higher will be sent as SNMP traps. After you configure it, you need the "snmp-server host x.x.x.x traps version 2c public" command to specify what will be the destination IP and SNMP community for these traps.
    It would only make sense to use the "logging history 4" command if your monitoring application doesn't support receiving syslog messages. However, since ANM is able to get syslog messages from the ACE without issues, I would just configure a destination for syslog message instead (with "logging host x.x.x.x")
    I hope this makes this point more clear.
    Now, moving on to why you are not seeing any SNMP traps in your ANM, the first things you would need to check are:
    -- Did you enable traps? You would use the "ACE(config)# snmp-server enable traps" command for this
    -- Are traps being sent? You can use the "show snmp" command and check if the "Trap PDUs" counter increases
    -- Is ANM getting these traps? This is the most complicated step. For this, I would recommend getting a traffic capture on the ANM server (if it's installed on linux) or as close as possible to it if it's a ANM appliance
    I hope this helps
    Daniel

  • I want to design some products for resale and I want to know if I can use the included Fonts

    I want to design some products for resale and I want to know if I can use the included Photoshop Fonts and Images or do I have to pay additional licensing fees?  Very new to this and just looking for some basic information or a link to specifics.  Most of what I'm searching for brings up content for publishing and I'm really looking for information about reselling items in a product line.  For example Greeting Cards, Signs etc...  Thanks so much!

    As for fonts, you don't need to do anything as long as you don't try to sell the actual font files. In print or the screen your fine to do as you want. Most fonts include a license EULA for you to read when installing them anyway.
    As for images, that may be a different story, it will depend on the image. If there is a file that accompanies the image that states you can do as you please, that fine, but other wise, assume the image is copyrighted and require permission to use.
    Some programs provide clipart that is for public use this clicpart can be printed and sold. But as with the fonts, you can not sell the clipart files themselves.
    In the EULA that accompanies the software, it should state what can be done with any clipart or fonts that are included with the software.
    If you are still in doubt, contact the company and verify it.

  • What are the Best Recommended Products for Mac OS X Server (Apache and ???)

    I investigated Oracle and PHP combo for robust database services to be able to create forms, store employee applications, resumes, do financial requests, invoices, ecommerce stuff, document and lists collaboration like Microsoft Sharepoint using Internet Information Services (IIS) and SQL Server, etc. What are recommended products that I can easily develop in to code and do the requested stuff using Mac current (Apache and ????) technologies?

    Of course it depends on your needs, but the OS X server already comes with Apache, Ruby On Rails, Python, Perl and SQL.

  • What is the best product for music and gaming? I'm looking for an apple COMPUTER. Not iPod etc.

    Hi! I am looking for an apple computer that would be good for gaming and music, movies etc. So I would like some input on some different products I'd be able to buy? The types of games I play are downloaded also. Any help would be good! Thank YOU!
    P.S
        I'm looking for preferably a laptop.

    while the Air can play many games fine, it is not an idealized gaming machine.
    examine a macbook Pro model at your local Apple store for evaluation if you plan on much gaming.

  • Semifin Production for internal AND external customers

    One of our plants produces semifin goods that are then transferred via Stock Transport Orders to other plants that finish them up.
    That plant would like to be able to also sell these same materials to outside customers. Normally, we would use PIRs for that purpose, however, these materials are all set up as dependent requirements, to be produced against STOs entered at the other plants.
    How could we create some additional requirements for production for external customers? Right now we have been using a defunct plant and created STOs from there, but it doesn't really work, especially the billing side of it. We considered creating a Sales Order Type that can be entered ahead of time to produce against. I don't know much about the S&D side, and the dude that tried that finally gave up.
    Is there an easier solution that would take care of this situation?
    Thanks,
    MMPP

    This sounds strange. STOs - independently from planning startegy - are present as requirements in standard system.
    Perhaps in your standard system. Our standard system for FG production is set up as MTS strategy 11, and no, STO's are not taken into account there, as strange as it sounds.
    If you use planning strategy 40 you can work with PIRs, SOs, STOs paralelly. You can even achieve to force STOs to behave as SOs (I mean to consume PIRs based on master data settings) in this strategy.
    Stock transport orders in planning strategy 40 - consume PIR
    Yes, but I can not use strategy 40. Like I mentioned, we deal with perishable goods, and can not make existing stock part of the MRP calculation.
    In my opinion you should revise your way of thinking / current pratice since you would gain more profit if you applied standard scenarios instead of force something that cannot be defined exactly.
    I am sorry that our situation is different from what you define as your standard scenario.
    I mean if your SFGs are considered as FGs (because you sell them to external customers) you should handle them accordingly.
    It is probably a bit difficult to understand. But these are semifinished goods that we want to sell to outside customers (who might treat them as raw materials). Not everything in this world can be clearly divided into three categories. Again, I apologize that our situation doesn't conform to what you consider standard.
    Why do you want to work only with DepReqs? I cannot understand this...
    98% of what that plant will produce are DepReqs = semifinished goods to fulfill STOs from other plants. Does that explain it somewhat?
    As I said you should handle the materials as they are handled in reality.
    I appreciate your reply... it's a good answer, just not to my question.

  • Ports for LOM and Server Monitor?

    I have an Xserve setup behind a firewall (local IP), and I'm trying to access LOM and Server Monitor from outside of the network .... which ports should I forward to the Xserve?
    google comes up semi-empty :P
    Thanks!

    The entry for port 623 says "Used by Intel Xserves' Lights-Out-Monitoring (LOM) feature; used by Server Monitor". Server Admin uses port 311; it's possible Server Monitor may also use that port for some functions, though I'm not sure.
    Regards.
    Message was edited by: Dave Sawyer

  • Any possibility to get SYSLOG and SNMP support for the E8350?

    Hi,
    It would be so nice to get some more basic functionality "OR more advance ones" to be able to se what is happening on the router, what it is doing and how the status of it is!
    Couldn't Linksys add support for a syslog server or snmp to the E8350 router, would help alot to determine what's going on!
    Or to enable some more / better logging support to a local attached USB stick or similar...
    I remember from one of the old watchguard firewalls i had, it was superb in displaying in and outgoing traffic and what was blocked..
    So a more advanced live traffic view lor ogging option would be greate!
    /J

    I think you are at the point where you are asking for advanced tools but even though its a very pricey router, its still considered a home router. Linksys needs to evaluate their business model on this stuff. Prices more in line with SoHo Business equipment but features of a home router. To me it seems like they have crossed a line. Should reconsider their audience at this price point and open up access to more features but that may need to give out better access to the router instead of the GUI. Need to open up telnet or ssh to a shell that has those features available but would still not grant access to files that could brick the router. It couldn't be that hard. 

  • Any recommendations on productivity for database and project management, Bento was good but no longer sync with ical and address book

    I've unfortunately updated to the new Bento on MakBook and iPad and synced my data and in the process it tells me that iCal and Address books will not sync any more.  I have several projects I am working on and looking for something that will syn with iCal, address book and Busy Cal to manage my  time efficiently and seamlessly. Help?

    I think you're in the wrong forum - this is for developers, who write programs for apple products.
    As for Bento, their problem is due to Apple's changes in the API.  The code that syncs with calendars and contacts is now deprecated, which means at some point in the future, it will no longer work.  This problem will affect all developers, so you probably won't find any replacement for Bento.

  • WLC 5508 and SNMP monitoring

    Dear all,
    I'm a little bit confused about this piece of hardware.
    I wonder if there is possibility of monitoring power supply and fans status (like on the other Cisco devices)?
    This info is usually located in ENV-MIB, but seems to me, there is no support of this MIB. Even temperature of box is located in some weird OID.
    Does anyone know, where to find above mentioned?
    For start, power supply (to see through snmp, something like this via CLI):
    Power Supply 1................................... Present, OK
    Thanks for ideas.
    Pavel

    Hi Pavel:
    Please know that the wireless LAN controllers were developed by Airespace and prior to their acquisition by Cisco in 2005, they had already created their own SNMP MIBs (the OIDs start .1.3.6.1.4.1.14179).  Since the acquisition, several former Airespace objects have been obsoleted and replaced by CISCO-LWAPP-* or other Cisco objects, yet some former Airespace objects remain in use, depending on the software train in use on the wireless LAN controller.  There are wireless MIBs for each software train in the Software Center. 
    All the maintenance releases (i.e. 7.0.240.0, 7.0.230.0, 7.0.220.0, 7.0.172.0, etc.) within a given train (i.e. 7.0.something.something, 6.0.something.something, 5.2.something.something) should have the same objects since maintenance releases are only supposed to contain bug fixes, while trains introduce new features and/or functionality--which, in turn, would require new SNMP objects.
    Try walking agentSwitchInfo (.1.3.6.1.4.1.14179.1.1.3):
    nms-jasmine:~# snmpwalk 172.18.254.29 agentSwitchInfoAIRESPACE-SWITCHING-MIB::agentSwitchInfoLwappTransportMode.0 = INTEGER: layer3(2)AIRESPACE-SWITCHING-MIB::agentSwitchInfoPowerSupply1Present.0 = INTEGER: false(0)AIRESPACE-SWITCHING-MIB::agentSwitchInfoPowerSupply1Operational.0 = INTEGER: false(0)AIRESPACE-SWITCHING-MIB::agentSwitchInfoPowerSupply2Present.0 = INTEGER: false(0)AIRESPACE-SWITCHING-MIB::agentSwitchInfoPowerSupply2Operational.0 = INTEGER: false(0)nms-jasmine:~#

  • Recommended product for scratch removal?

    I have the black 60GB 5th Gen Ipod. I have been using it for years, but by now my screen has become scuffed and scratched. I want to purchase a product to remove the scratches, and then a film or cover to protect it (the previous cover I had is what left the scratches over time), but I want to know what everyone recommends as the best products? Any suggestions?

    Hey there,
    There are numerous products available for cleaning your iPod, but I have had great luck with PodShop iDrops. It is a cheap product, but requires a bit of work to remove scratches. Worth the effort in the end though. Here is a link to more information on it from amazon. I am not sure with protective cases though because I have never really had any luck any. For now, I just place a piece of the wider packaging tape over the front. It works great and keeps my iPod looking brand new. Hope this helps.
    http://www.amazon.com/PodShop-iDrops-Cleaner-Scratch-Remover/dp/B0006V7QAK
    B-rock
    Message was edited by: planb77

  • Which video card for Aperture and dual monitors?

    I have a G5 dual 2.0 with a GeForce FX 5200 video card that is driving one 23" Cinema display. I need to upgrade my card per the specs to run Aperture. I have also been thinking of getting a second 23" display. Can someone recommend the best video card for me. I know very little about video cards and have been reading a lot this morning. Thanks,
    Dave

    Hi Dave;
    No. PCIx and PCIe or PCI Express are not the same thing.
    PCIx is an extended or slight sped up version of PCI. While PCIe is a switched bus structure instead.
    Hence they are not the same. That is what all of the big news is about Apple has made the leap over to PCI Express.
    Allan

  • Recommended practice for adding and deleting from a Collection

    Are there any suggestions for updating a Collection in a OneToMany ( privateOwned ) Collection? Here is our use case:
    1. Retrieve a Source object from the database
    2. Remove 1 or more SourceLinks from the sourceLinks Set
    3. Add 1 or more new SourceLinks to the sourceLinks Set
    4. Update the Source object
    The SourceLink object has isPrivateOwned(true).
    Adding and Removing things from a Collection seems like a fairly common use case. Are there recommended ways of handeling the above case? I've tried doing the add/remove operation in one transaction as well as removing, then re-fetching, and then adding in separate transactions and haven't had any luck.
    Here is the code an test case.
    class Source
    @OneToMany(mappedBy = "source",
    fetch = FetchType.EAGER,
    cascade = { CascadeType.ALL })
    private Set<SourceLink> sourceLinks = new HashSet<SourceLink>();
    class SourceLink
    @ManyToOne
    @JoinColumn(nullable = false)
    private Source source;
    //~ Unit Tests
    @Test
    public void testMultiUpdateSourceLink()
    // typical set up.
    SourceLink sourceLink = new SourceLink( "junit1", 48, "mp3" );
    SourceLink sourceLink2 = new SourceLink( "junit2", 64, "mp3" );
    Source mySource = new Source( "http://www.site.com", SourceType.RSS );
    mySource.addSourceLink( sourceLink );
    mySource.addSourceLink( sourceLink2 );
    beginTransaction();
    sourceDao.persist( mySource );
    commitTransaction();
    Long sourceId = mySource.getId();
    Assert.assertEquals( 2, mySource.getSourceLinks().size() );
    // fetching what we just added, then deleting something from the set
    // with privateOwned this works.
    beginTransaction();
    Source fetched = sourceDao.find( sourceId );
    fetched.deleteSourceLink( sourceLink );
    sourceDao.update( fetched );
    commitTransaction();
    Assert.assertEquals( 1, fetched.getSourceLinks().size() );
    // now fetch again, try to add a new SourceLink
    // fails with an OptimisticLockException
    beginTransaction();
    Source updated = sourceDao.find( sourceId );
    Assert.assertEquals( 1, updated.getSourceLinks().size() );
    SourceLink sl = new SourceLink( "ryan", 64, "mp3" );
    updated.addSourceLink( sl );
    sourceDao.update( updated );
    commitTransaction();
    Assert.assertEquals( 2, updated.getSourceLinks().size() );
    The sourceDao.update() method simply calls entityManager.merge(source). Is it required to flush the entityManager as well?

    Hi,
    TMG MBE doesn't have the capability to add network topolgy routes via the TMG MMC. You have to use the ROUTE ADD /P command from a privileged command prompt
    regards Marc Grote aka Jens Baier - www.it-training-grote.de - www.forefront-tmg.de - www.galileocomputing.de/3276?GPP=MarcGrote

  • Recommended products for connection between buildings 50 meters apart

    Hi
    I have a client that requires a connection between their two buildings 50 meters apart. If possible they require bandwidth up to 54Mbps. Currently they only have a switch in either building.
    Can anyone recommend a solution for this? Will they need two bridges or do they need 1 bridge and 1 AP?
    Many thanks

    In europe the best way to do this is to use a cisco 2 x 1300 if you are in the states you can use 2 x 1400. However the 1300 is more flexible.

  • IP SLA and SNMP monitoring

    Hello All,
    I want to create a IP SLA so that I can monitor UP time for ISP's as the I Ethernet connectivity, so if there link down beyond the mux, i cannot find that when it went down and at what time it came back, Basically for how long it? So i want to set IP SLA between CE-PE and same i want to plot a graph in MTRG so that NOC team can motinor as well we can pull historical report for that link.
    Can you please suggest if this is achievable? if yes than how can i achieve this?
    Thanks
    Jagdev

    Hi ,
     You can configure IP SLA on your device using below link 
    http://www.cisco.com/c/en/us/td/docs/ios/12_4/ip_sla/configuration/guide/hsla_c/hsicmp.html
    you need to download MIB on to your MRTG server for montioring 
    CISCO-IPSLA-ECHO-MIB
    CISCO-IPSLA-ETHERNET-MIB
    Look into below url for loading MIB 
    http://oss.oetiker.ch/mrtg/doc/mrtg-reference.en.html
    HTH
    Sandy

Maybe you are looking for