New Install - No Event Log Created

Support, Questions and Discussions on WinSyslog

Moderator: alorbach

New Install - No Event Log Created

Postby JeffreyHunt on Thu Mar 06, 2003 11:06 pm

I've just downloaded and installed WinSysLog and EventReporter on my Primary Domain Controller NT40sr6. I'm following the 'How to setup Windows NT centralize Monitoring' step by step. At the very end of Major Step 2 it reads 'After Ste 2 is completed, the WinSyslog machine should have a log file in its C:\temp directory. This log will contain events forwarded from the EventReporter agents. Please verify if there is such a file. If it isn't check the setup you made.'

Afer setup I do not have any files in my C:\temp directory.

Thanks

Jeffrey Hunt
JeffreyHunt
 

Postby alorbach on Fri Mar 07, 2003 9:29 am

In this case, please take a look into the Application Eventlog, and look for error's from WinSyslog or EventReporter Service.

I assume that the folder C:\temp exists.

Another thing you can try to trigger the whole thing is, to lower the LastRecord value on the Application tab in EventReporter Client. The EventReporter will send old events again to teh WinSyslog Server.
User avatar
alorbach
Site Admin
 
Posts: 871
Joined: Thu Feb 13, 2003 11:55 am

New Install - No Event Log Created

Postby Jeffrey Hunt on Fri Mar 07, 2003 3:18 pm

Yes, in the Application eventlog there were errors 'Could not connect to Syslog Server over TCP'. There were not any errors at first, but they are there now. I lowered the LastRecord value as well.

On both programs I've change the default protocol to TCP and have specified the TCP/IP address of the machine. For right now I have both EventReporter and WinSyslog installed on the same server.

Thanks for your help.
Jeffrey Hunt
 

Postby rgerhards on Fri Mar 07, 2003 3:28 pm

Jeffrey,

can you please verify that the WinSyslog syslog service configuration does specify TCP as the protocol to use AND that it listens to the same port that EventReporter is sending data to (514).

Rainer Gerhards
Adiscon
User avatar
rgerhards
Site Admin
 
Posts: 1491
Joined: Thu Feb 13, 2003 11:57 am

WinSyslog

Postby Jeffrey Hunt on Fri Mar 07, 2003 5:58 pm

Yes, the WinSyslog service configuration does specify TCP as the protocol and I set the port to 1468.
Jeffrey Hunt
 

Postby alorbach on Fri Mar 07, 2003 6:05 pm

Hi,

change the port to 514 and restart the service, then it should work.

FYI, the port is changed to 1468 because this is normally used for Syslog over TCP.
User avatar
alorbach
Site Admin
 
Posts: 871
Joined: Thu Feb 13, 2003 11:55 am

Postby rgerhards on Fri Mar 07, 2003 6:09 pm

...let me add that "normally" means Cisco PIX ;) - just to avoid confusion. EventReporter sends to port 514, unless another value is explicitely specified in the services database (typically at \winnt\system32\drivers\etc\services.).

Rainer Gerhards
Adiscon
User avatar
rgerhards
Site Admin
 
Posts: 1491
Joined: Thu Feb 13, 2003 11:57 am

Google Ads



Return to WinSyslog

Who is online

Users browsing this forum: No registered users and 0 guests

cron