Networking Forums

Networking Forums > Computer Networking > Linux Networking > Windoze > Linux Syslog server

Reply
Thread Tools Display Modes

Windoze > Linux Syslog server

 
 
KM
Guest
Posts: n/a

 
      06-29-2005, 10:11 PM
Sorry about mentioning other miscreant OS's in this post, but I am currently
using a Linux Server as central Syslog server.

The question is, how do I filter (from /var/log/messages) out the multitude
of information and authentication messages that I am receiving from the
Windoze boxes?

for example
Jun 29 22:06:31 sirius Security: NT AUTHORITY\SYSTEM: Successful Network
Logon: User Name: SIRIUS$ Domain: CZD Logon ID: (0x0,0x25B039) Logon Type:
3 Logon Process: Kerberos Authentication Package: Kerberos Workstation
Name:
Jun 29 22:06:31 sirius Security: NT AUTHORITY\SYSTEM: Special privileges
assigned to new logon: User Name: Domain: Logon ID: (0x0,0x25B08C)
Assigned: SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege
SeChangeNotifyPrivilege
Jun 29 22:06:31 sirius Security: NT AUTHORITY\SYSTEM: Successful Network
Logon: User Name: SIRIUS$ Domain: CZD Logon ID: (0x0,0x25B08C) Logon Type:
3 Logon Process: Kerberos Authentication Package: Kerberos Workstation
Name:
Jun 29 22:06:31 sirius Security: NT AUTHORITY\SYSTEM: User Logoff: User
Name: SIRIUS$ Domain: CZD Logon ID: (0x0,0x25B08C) Logon Type: 3
Jun 29 22:06:31 sirius Security: NT AUTHORITY\SYSTEM: User Logoff: User
Name: SIRIUS$ Domain: CZD Logon ID: (0x0,0x25AFBA) Logon Type: 3

I would like to ignore these, but they don't (seem) to fall into the usual
Linux logging categories.

OS=FC3

Thanks

Martyn


--
--
KM
 
Reply With Quote
 
 
 
 
Michael Heiming
Guest
Posts: n/a

 
      06-30-2005, 06:39 AM
In comp.os.linux.networking KM <martyn@n0spam<.>czd<.>org <.>uk>:
> Sorry about mentioning other miscreant OS's in this post, but I am currently
> using a Linux Server as central Syslog server.


> The question is, how do I filter (from /var/log/messages) out the multitude
> of information and authentication messages that I am receiving from the
> Windoze boxes?


> for example
> Jun 29 22:06:31 sirius Security: NT AUTHORITY\SYSTEM: Successful Network


Try a search (freshmeat.net) for "syslog-ng", this should allow
you to redirect each system log to a separate file.

[..]

Good luck

--
Michael Heiming (X-PGP-Sig > GPG-Key ID: EDD27B94)
mail: echo (E-Mail Removed) | perl -pe 'y/a-z/n-za-m/'
#bofh excuse 10: hardware stress fractures
 
Reply With Quote
 
KM
Guest
Posts: n/a

 
      06-30-2005, 08:25 AM
Michael Heiming wrote:

> In comp.os.linux.networking KM <martyn@n0spam<.>czd<.>org <.>uk>:
>> Sorry about mentioning other miscreant OS's in this post, but I am
>> currently using a Linux Server as central Syslog server.

>
>> The question is, how do I filter (from /var/log/messages) out the
>> multitude of information and authentication messages that I am receiving
>> from the Windoze boxes?

>
>> for example
>> Jun 29 22:06:31 sirius Security: NT AUTHORITY\SYSTEM: Successful Network

>
> Try a search (freshmeat.net) for "syslog-ng", this should allow
> you to redirect each system log to a separate file.
>
> [..]
>
> Good luck
>

Thanks

I'll try it out

Martyn
--
--
KM
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Linux dialup on a modern Windoze laptop Victor Schneider, Ph. D. Linux Networking 0 05-09-2007 01:18 PM
Linux behaving like Windoze ;( W.P. Linux Networking 7 04-22-2007 10:28 PM
Syslog parser wanted to replace Kiwi Syslog (win32) Jurgen.Turrekens@gmail.com Linux Networking 0 01-19-2006 01:08 PM
Best way to integrate Mac into Linux/Windoze network? Roger Blake Linux Networking 5 09-03-2004 11:03 PM
Linux-windoze home networking ad Linux Networking 3 05-23-2004 02:10 AM



1 2 3 4 5 6 7 8 9 10 11