Different Syslog formats in RSyslogd

This is the place for you, if you got rsyslog up and running but wonder how to make it do what you want.

Moderator: rgerhards

Different Syslog formats in RSyslogd

Postby speedfox on Wed Oct 01, 2008 2:12 pm

Hi Guys


I need to implement quite a few different types of syslog. ie Juniper,Cisco, Fortinet,Checkpoint, IIS,McAfee, etc etc.
What i need to know is how i configure rsyslog to read all the various messages from the different syslog formats? does it automatically do this?
if not how can i configure it to do so? is there a way in which i can add a configurable plugin(.cfg) file?

Also once it pulls the info into mysql. i need to be able to distuinguish which plugin it came from

Is this possible?

Thanks
Stuart
speedfox
Frequent Poster
 
Posts: 70
Joined: Wed Oct 01, 2008 2:07 pm

Professional Services Information

  • Custom written rsyslog.conf?
  • Maintenance Contract?
  • Installation support?

Re: Different Syslog formats in RSyslogd

Postby rgerhards on Wed Oct 01, 2008 2:50 pm

Given what came in recently in vendor horrors, this sound more complicated than one would expect it to be. Do you intend to use UDP or TCP? If it is just for the message format, I think the property replacer could do the job. But there are also protocol issues. Search the forum for recent posts on how to extract data, there has been at least one excellent howto-like post recently.

Rainer
User avatar
rgerhards
Site Admin
 
Posts: 1780
Joined: Thu Feb 13, 2003 11:57 am

Re: Different Syslog formats in RSyslogd

Postby speedfox on Wed Oct 01, 2008 2:55 pm

Hi Rainer

Im using TCP primarily.
to use the property replacer method. do i have to include it all on rsyslog.conf? or can i create a config file for each firewall type and tell rsyslog.conf to include it?
speedfox
Frequent Poster
 
Posts: 70
Joined: Wed Oct 01, 2008 2:07 pm

Re: Different Syslog formats in RSyslogd

Postby rgerhards on Wed Oct 01, 2008 2:57 pm

search the past 2 days for tcp framing problems. Netscreen and Cisco seem to have screwed up. I am working on a solution, but no technically sound fix is possible.

On the config: we do not yet have configurable input parsers. It would be nice to have them, but I did not yet have time to do that soon, as it looks...

Rainer
User avatar
rgerhards
Site Admin
 
Posts: 1780
Joined: Thu Feb 13, 2003 11:57 am

Re: Different Syslog formats in RSyslogd

Postby speedfox on Wed Oct 01, 2008 3:08 pm

great thanks! ill check out the tcp framing issues.
speedfox
Frequent Poster
 
Posts: 70
Joined: Wed Oct 01, 2008 2:07 pm

Google Ads



Return to Configuration

Who is online

Users browsing this forum: No registered users and 0 guests

cron