Re: Issue with scripts/services/evt[application|security|system]

Orion Poplawski <[email protected]>
Newsgroups gmane.comp.log.logwatch.devel
Message-ID <[email protected]>
On 06/29/2011 03:26 PM, William Voyek wrote:
> On Wed, Jun 29, 2011 at 1:49 PM, Orion Poplawski<[email protected]>  wrote:
>>
>> There still is something interesting on the syslog server that ends up
>> putting in the hostname twice.  What is the name of your syslog server?  Are
>> you running syslog or rsyslog?  Could to attach the relevant (r)syslog.conf
>> file?
>>
>> Not a big deal at this point as I've basically changed the logwatch scripts
>> to ignore everything before the MSWinEventLog string.  But I am interested
>> in exploring issues with logwatch and syslog servers.  It appears that at
>> the moment logwatch throws away the initial host name.  And I suspect lots
>> of things break when there are two hostnames.
>>
>> --
>> Orion Poplawski
>> Technical Manager                     303-415-9701 x222
>> NWRA/CoRA Division                    FAX: 303-415-9702
>> 3380 Mitchell Lane                  [email protected]
>> Boulder, CO 80301              http://www.cora.nwra.com
>>
>
> We are running syslog on CentOS 5.6. It looks like the double hostname
> is only happening on the SNARE syslog entries. Here are my syslog
> config files

Turns out I ran into a similar issue a while ago:

https://bugzilla.redhat.com/show_bug.cgi?id=250628

Looks like snare 4.0 went the same way.  Anyways, we should be good now.  Just 
need to start ignoring more messages.

-- 
Orion Poplawski
Technical Manager                     303-415-9701 x222
NWRA/CoRA Division                    FAX: 303-415-9702
3380 Mitchell Lane                  [email protected]
Boulder, CO 80301              http://www.cora.nwra.com

------------------------------------------------------------------------------
All of the data generated in your IT infrastructure is seriously valuable.
Why? It contains a definitive record of application performance, security 
threats, fraudulent activity, and more. Splunk takes this data and makes 
sense of it. IT sense. And common sense.
http://p.sf.net/sfu/splunk-d2d-c2
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.