Unix Technical Forum

remember central syslog server and forwarding

This is a discussion on remember central syslog server and forwarding within the HP-UX Operating System forums, part of the Unix Operating Systems category; --> Hi I couldn't find any examples of this on HPUX syslogd and syslog.conf where we have a central syslog ...


Go Back   Unix Technical Forum > Unix Operating Systems > HP-UX Operating System

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 01-16-2008, 08:57 PM
mmccaws2
 
Posts: n/a
Default remember central syslog server and forwarding

Hi

I couldn't find any examples of this on HPUX syslogd and syslog.conf
where we have a central syslog server that recieves all syslog
messages, saves them into the central syslog files and forwards the
messages to the appropriate computer or network management station.
Two problems, one we don't think it is forwarding to the management
station, two it needs to forward to the next management station as the
original ID. We're trying to migrate this from a 7 year old sun system
to a new HP UX, and we're not that familiar with HPUX differences.

Or is there an open source package that does what we're looking for?

Anyway, as you can see I would appreciate any suggestions.

Thanks
Mike

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 01-16-2008, 08:58 PM
all mail refused
 
Posts: n/a
Default Re: remember central syslog server and forwarding

On 2006-04-13, mmccaws2 <mmccaws@comcast.net> wrote:

> I couldn't find any examples of this on HPUX syslogd and syslog.conf
> where we have a central syslog server that recieves all syslog
> messages, saves them into the central syslog files and forwards the
> messages to the appropriate computer or network management station.
> Two problems, one we don't think it is forwarding to the management
> station, two it needs to forward to the next management station as the
> original ID. We're trying to migrate this from a 7 year old sun system
> to a new HP UX, and we're not that familiar with HPUX differences.


I do large-scale multi-unix-flavour syslog collection - including some
forwarding by HP-UX. Assuming you stick with the native s/w (as I have)
you just arrange in syslog.conf on that host to do *both* the forwarding
(into the management station) *and* the write to a local file. All other
hosts should forward to that one HP box.

After doing this the network management station may think all the traffic
comes from one host. If that's a problem then stop forwading into the
station by native syslog and use something that forges source addresses
when sending traffic to the management station. The blurb with netcat
explains how. You'll probably need to run that as root. I don't know
a product that does this - there probably are some and it doesn't sound
hard to do anyway if you read the logfile and generate matching net traffic.

Last week one bloke did over 20 million failed su to root attempts and I
stupidly forgot to put that in my weekly report before leaving today.

And some syslog messages aren't worth having. User denied? Yes, but
which user?!

--
Elvis Notargiacomo master AT barefaced DOT cheek
http://www.notatla.org.uk/goen/
Powergen write "Why not stay with us" - let me count the ways!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 07:05 PM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com