Will I maintain a copy of the event log?

Support, Questions and Discussions on EventReporter

Moderator: alorbach

Will I maintain a copy of the event log?

Postby sbg31 on Thu Jul 08, 2004 4:52 pm

I want to use EventReporter to forward Windows event logs to a syslog server.

Will I still maintain a copy of the event log on the originating system?

Thanx
sbg31
sbg31
New
 
Posts: 4
Joined: Thu Jul 08, 2004 4:44 pm

Postby rgerhards on Thu Jul 08, 2004 5:00 pm

Yes, the event log is never reset. EventReporter keeps track of what it already sent and only forwards new entries. But, again, it does not delete anything.

I hope this helps,
Rainer Gerhards
Adiscon
User avatar
rgerhards
Site Admin
 
Posts: 1688
Joined: Thu Feb 13, 2003 11:57 am

Postby sbg31 on Thu Jul 08, 2004 5:05 pm

Thanx that's what I needed

sbg31
sbg31
New
 
Posts: 4
Joined: Thu Jul 08, 2004 4:44 pm

what about when the clients become disconnected

Postby et on Mon Sep 19, 2005 10:00 pm

What happens when the Client is physically disconnected from the Syslog Sever (Kiwi Syslog Daemon)? Maybe a user is working offline. Are any windows security events lost? does the eventreporter service know it has lost the connection?
et
 

Postby rgerhards on Tue Sep 20, 2005 7:43 am

Actually, it depends on the transmission protocol you are using. If you use UDP syslog, there is no way for EventReporter to detect that the message could not be sent. This is by UDP design (and the design of the syslog protocol, which does not supply a message acknowledge). However, if you use TCP, EventReporter will see it can't send to the syslog server and queue processing. Plain TCP is non-standard, but our syslog server (http://www.winsyslog.com) supports it. We also support standard TCP syslog via RFC 3195, but to the best of my knowledge no other product besides SDSC syslog does currently support it.

HTH
Rainer
User avatar
rgerhards
Site Admin
 
Posts: 1688
Joined: Thu Feb 13, 2003 11:57 am

Google Ads



Return to EventReporter

Who is online

Users browsing this forum: No registered users and 0 guests

cron