Hardwired Event Type Syslog Priority

Support, Questions and Discussions on EventReporter

Moderator: alorbach

Hardwired Event Type Syslog Priority

Postby systeu on Tue Jun 28, 2005 7:42 am

Hello all,

is it true that we have a fix mapping of event types to syslog priorities ?

AUDIT_SUCCESS = NOTICE Priority
AUDIT_FAILURE = WARNING Priority
INFORMATION = NOTICE Priority
WARNING = WARNING Priority
ERROR = ERR Priority

Or is there any possibility to change this like in the NTsyslog tool ?

Thanks in advance


Rgds

Uli
systeu
New
 
Posts: 3
Joined: Tue Jun 28, 2005 7:31 am

Postby rgerhards on Tue Jun 28, 2005 8:56 am

Hello Uli,

this mapping is fixed:

EVENTLOG_AUDIT_SUCCESS: NOTICE;
EVENTLOG_INFORMATION_TYPE: LOG_NOTICE;
EVENTLOG_AUDIT_FAILURE: LOG_WARNING;
EVENTLOG_WARNING_TYPE: LOG_WARNING;
EVENTLOG_ERROR_TYPE: LOG_ERR;

Do you have a need to configure it differently? If so, we could probably add some option to do this.

Rainer
User avatar
rgerhards
Site Admin
 
Posts: 1694
Joined: Thu Feb 13, 2003 11:57 am

Postby systeu on Tue Jun 28, 2005 9:04 am

Hello Rainer,


this would be a great feature. Because without this adjustment and a centralized logging on a UNIX syslog Server you have the problem that windows events can't reach the highest priorities in syslog (emerg, alert, crit).


Thanks in advance

Uli
systeu
New
 
Posts: 3
Joined: Tue Jun 28, 2005 7:31 am

Postby rgerhards on Tue Jun 28, 2005 9:31 am

Hello Uli,

I see - let me talk to our folks, I guess this is a quick change. I'll keep you posted.

Rainer
User avatar
rgerhards
Site Admin
 
Posts: 1694
Joined: Thu Feb 13, 2003 11:57 am

Postby rgerhards on Tue Jun 28, 2005 9:32 am

Oh, by the way. The current EventReporter can actually do this, but only via the rule engine and with a lot of configuration. Its far from being straightforward. But if you need somethin immediately, I can probably provide it to you. If you can wait a little bit, the enhanced version is a much better way to go...

Rainer
User avatar
rgerhards
Site Admin
 
Posts: 1694
Joined: Thu Feb 13, 2003 11:57 am

Postby systeu on Tue Jun 28, 2005 9:35 am

Hello Rainer,


thanks for your fast support. I will wait for the adjusted release.

Thanks


Uli
systeu
New
 
Posts: 3
Joined: Tue Jun 28, 2005 7:31 am

Postby rgerhards on Mon Sep 19, 2005 7:59 am

For the records: this feature is now implemented in the most recent build.

Rainer
User avatar
rgerhards
Site Admin
 
Posts: 1694
Joined: Thu Feb 13, 2003 11:57 am

Google Ads



Return to EventReporter

Who is online

Users browsing this forum: No registered users and 0 guests

cron