Step-By-Step Guides  
 

How To Forward Various Logs To Different Syslog Servers?

Article created 2009-12-03 by Tom Bergfeld.

Are you interested in forwarding various logs to different syslog servers?
This guide will show you step by step how to configure the product.


Please note that this guide is valid for EventReporter and MonitorWare Agent.

In our example we want to forward Windows event logs, separated by the eventlog types 'application' and 'security', to 2 different syslog servers. Of course you can also use other separators.

General information about MonitorWare Agent
General information about EventReporter

 

Table of Contents

Services

1. Set up an Event Log Monitor Service

 

Actions

2. Set up the forward via syslog actions
3. Set up the filter conditions

 

1. Set up an EventLog Monitor Service

At first we set up the Event Log Monitor Service. Right click on 'Configured Services' - 'Add Service' and choose 'Event Log Monitor'. Now just follow the instructions of your configuration client. We do not have to change anything in that configuration of our Event Log Monitor service.

Adding an Event Log Monitor Service

Event Log Monitor Service

Back to Top

 

2. Set up the forward via syslog actions

The second step is to setup the forward via syslog actions. In our case we need 2 actions because we want to forward the logs to 2 different syslog servers. Just right click on 'Action' - 'Add action' - 'Forward via Syslog' and 'Finish'. Now we have to add a second rule for our second forward via syslog action.
Please note to add just a new rule - no further Rule Set. Every service can just be assigned to 1 Rule Set!
You create a new rule by right click on your Rule Set and 'Add Rule'. Here you can add a second action like we did before. Your configuration should look like in the screenshot below.

Current configuration

In the added forward via syslog action we have to adjust the IPs of our syslog servers, the ports and the protocol type. The default UDP settings would be adequate for the example, but please check the firewalls of your servers if the ports are opened. The configuration of the sample configuration would look like this.


Current configuration 'Forward via Syslog'

Back to Top

 

3. Set up the filter conditions

In this step we have to setup the filter conditions. With the filter we arrange which eventlog type will be forwarded to which syslog server. Click on your 'filter conditions' of your first rule. You will see that by default there is just an 'and' operator. Click on it and then on 'Add Filter'and follow the screenshot to choose the 'Event Type' filter.

Adding the EventType filter

Default Event Type filter

Now we have got the first action with its filter. Repeat this step for the filter conditions of our second forward via syslog action. After adding the 'Event Type' filter we have to adjust the type. If we click on that filter we will see that there are some configurations for that filter. We just need the 'set property value' field. Here we find all types that we need.
Choose the security type and save your changes.

Configure Set Status Action

Everything we need for this configuration is done and we can run our configuration. Just click start/restart to verify that all changes in you configuration are accepted.

Start your service

Back to Top

 

MonitorWare
 Home
 The Products
MonitorWare Products
Product Comparison
Which one to Purchase?
Order and Pricing
Upgrade Insurance Info
News Releases
Version History
MonitorWare Tools
 Event Repository
 Download
 Reference library
General Information
Step-by-step guides
 - All
 - Installation and Configuration
 - Services related
 - Actions related
 - Central Monitoring
Common Uses
Syslog configuration
Syslog Log Samples
Security Reference
 Help
Support
Manual
FAQ
 - All
 - General questions
 - Configurations related
 - Monitorware Agent
 - Monitorware Console
Articles
Seminars Online
 - All
 - General
 - MonitorWare Console
 - MonitorWare Agent
 - WinSyslog related
 - EventReporter
 Order & pricing
Order now
Product Comparison
Pricing Information
Upgrade Insurance Info
Local Reseller
 Contact Us
 Search
 
 



Printer Version Send this page to a friend

Copyright © 1988-2005 Adiscon GmbH All rights reserved.
Contact us via Secure Web Response | Privacy Policy
Topic Links: syslog | Free Weblinks Directory