Re: Issue with scripts/services/evt[application|security|system]
Orion Poplawski <[email protected]>
| Newsgroups | gmane.comp.log.logwatch.devel |
|---|---|
| Message-ID | <[email protected]> |
On 06/29/2011 03:26 PM, William Voyek wrote: > On Wed, Jun 29, 2011 at 1:49 PM, Orion Poplawski<[email protected]> wrote: >> >> There still is something interesting on the syslog server that ends up >> putting in the hostname twice. What is the name of your syslog server? Are >> you running syslog or rsyslog? Could to attach the relevant (r)syslog.conf >> file? >> >> Not a big deal at this point as I've basically changed the logwatch scripts >> to ignore everything before the MSWinEventLog string. But I am interested >> in exploring issues with logwatch and syslog servers. It appears that at >> the moment logwatch throws away the initial host name. And I suspect lots >> of things break when there are two hostnames. >> >> -- >> Orion Poplawski >> Technical Manager 303-415-9701 x222 >> NWRA/CoRA Division FAX: 303-415-9702 >> 3380 Mitchell Lane [email protected] >> Boulder, CO 80301 http://www.cora.nwra.com >> > > We are running syslog on CentOS 5.6. It looks like the double hostname > is only happening on the SNARE syslog entries. Here are my syslog > config files Turns out I ran into a similar issue a while ago: https://bugzilla.redhat.com/show_bug.cgi?id=250628 Looks like snare 4.0 went the same way. Anyways, we should be good now. Just need to start ignoring more messages. -- Orion Poplawski Technical Manager 303-415-9701 x222 NWRA/CoRA Division FAX: 303-415-9702 3380 Mitchell Lane [email protected] Boulder, CO 80301 http://www.cora.nwra.com ------------------------------------------------------------------------------ All of the data generated in your IT infrastructure is seriously valuable. Why? It contains a definitive record of application performance, security threats, fraudulent activity, and more. Splunk takes this data and makes sense of it. IT sense. And common sense. http://p.sf.net/sfu/splunk-d2d-c2