Re: SYSLOG and SNMP traps analysis and alerting
Tim Yocum <[email protected]>
| Newsgroups | gmane.org.operators.internet-access |
|---|---|
| Message-ID | <[email protected]> |
Hello Frank, On Sat, May 9, 2009 at 12:27 PM, Frank Bulk <[email protected]> wrote: [snip] > I have a syslog-ng in place (as well as NAGIOS and cacti) and I’ve through > about using snmp-tt, but I still need something to “ingest” my logs and let > me know when “strange” things occur. [snip] > - Send me an e-mail [...] > - Send me an e-mail [...] > - Send me an e-mail [...] > - Run a script and send an e-mail [...] > - Send me a page [...] You are running syslog-ng, so you already have the capability to define a perl script or similar as a destination that takes filtered alerts and pipes them into an email. Or an SMS. Or do basically anything you can write in Perl. Nate Campi has put a lot of thought into this and more: http://www.campin.net/newlogcheck.html (thanks, Nate!) > - Send me a daily report on how many “denies” have been logged in our > BIND logs > > - Search DHCP, CMTS, and eMTA logs for a certain IP or MAC address > > - Graph out over time how many “denies” have been logged for SSH > “attacks” against my routers Suddenly it seems your search narrows to some trending work vs. notifications that you can augment with syslog-ng out of the box. hth, - Tim -- Eat sushi frequently. - Avi [email protected] is the human contact address. [email protected] is the list posting address. See below URL for subscribe/unsubscribe and list options: http://inet-access.net/mailman/listinfo/list