RE: SYSLOG and SNMP traps analysis and alerting
"Frank Bulk" <[email protected]>
| Newsgroups | gmane.org.operators.internet-access |
|---|---|
| Message-ID | <!&!AAAAAAAAAAAuAAAAAAAAAKTyXRN5/+lGvU59a+P7CFMBAN6gY+ZG84BMpVQcAbDh1IQAAAATbSgAABAAAACQdAOeYZVgTqgGT7upfQfHAQAAAAA=@iname.com> |
Thanks for pointing me to that article. You address the generation of notices based on certain syslog events, but I'm missing syslog analysis (strange events, graphing of quantity of certain types of events over time) and snmp trap translation. I looked again snmp-tt, but boy, they're not making it easy. I want to be able to have a MIB directory and have the utility generate plain-text output, but looks like I need to run a translator against each MIB. Perhaps I need to continue incrementally -- syslog-ng to notify me on certain types of events, and keep adding tools for each case. I reviewed OpenNMS and most of the other opensource graphical tools, they're left wanting in terms of SNMP trap handling. Frank -----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of Tim Yocum Sent: Saturday, May 09, 2009 9:07 PM To: [email protected] Subject: Re: SYSLOG and SNMP traps analysis and alerting Hello Frank, On Sat, May 9, 2009 at 12:27 PM, Frank Bulk <[email protected]> wrote: [snip] > I have a syslog-ng in place (as well as NAGIOS and cacti) and Ive through > about using snmp-tt, but I still need something to ingest my logs and let > me know when strange things occur. [snip] > - Send me an e-mail [...] > - Send me an e-mail [...] > - Send me an e-mail [...] > - Run a script and send an e-mail [...] > - Send me a page [...] You are running syslog-ng, so you already have the capability to define a perl script or similar as a destination that takes filtered alerts and pipes them into an email. Or an SMS. Or do basically anything you can write in Perl. Nate Campi has put a lot of thought into this and more: http://www.campin.net/newlogcheck.html (thanks, Nate!) > - Send me a daily report on how many denies have been logged in our > BIND logs > > - Search DHCP, CMTS, and eMTA logs for a certain IP or MAC address > > - Graph out over time how many denies have been logged for SSH > attacks against my routers Suddenly it seems your search narrows to some trending work vs. notifications that you can augment with syslog-ng out of the box. hth, - Tim -- Eat sushi frequently. - Avi [email protected] is the human contact address. [email protected] is the list posting address. See below URL for subscribe/unsubscribe and list options: http://inet-access.net/mailman/listinfo/list -- Eat sushi frequently. - Avi [email protected] is the human contact address. [email protected] is the list posting address. See below URL for subscribe/unsubscribe and list options: http://inet-access.net/mailman/listinfo/list