Syslog management on Windows platforms.

Do you know WinSyslog from Adiscon? It is so cool a tool for us system operators/administrators.
Check it out at: http://www.adiscon.com/
(For Japanese: http://adiscon.port139.co.jp/)
This tool is so cool, as it allows you to consolidate all the standard error/log messages to one server. With MSSQL you can even display the messages via IIS 4/5. Merging Syslog, SNMP, and Windows Event logs are critical for system admins, to whom we can say this tool is the very solution for managing system health in general.
You can merge SNMP with syslog, using either the latest version of WinSyslog, or with Kiwi Syslog Daemon (http://www.kiwisyslog.com).
You can merge Windows event logs with the following tools:

1. Event Reporter from Adiscon

2. Event logs to syslog utility from Purdue University.

3. ntsyslog service tool from SourceForge

cf. I found a localised version of ntsyslog in Vector or Mado-no-mori, which uses EUC-JP for Japanese. If you have already deployed Linux- or *NIX-based solution for the consolidation of logs, this client is just-fit, it seems.

Note: there are other tools in the world to facilitate this function. According to Kawabata-san (http://www.kawabata.com/), you can even write up the tool that just-fits to your need. ;-)

***System Requirements:

A. System: See the URLs above
B. Human:

B-1. Knowledge of syslog (unix and network devices you use.)

B-2. Ability or Experience of manually parsing eventlogs on Windows

B-3. Ability to configure network devices to emit logs, if you think you'd like to add the target of monitoring.

B-4. Ability to configure SNMP on servers and clients to enable them to emit SNMP messages.

B-5. Ability/experience to configure server management tools like Allied Telesyn SwimView, HP OpenView or Dell Server Administrator /IT assistant for PowerEdge Systems.

(It is okay to use other administrative tools according to the needs at your managed networks. Tools above are just as examples.)
Outputs are just like this.(Special thanks to lg_de_sucre, a cool guy working together.)


Howto: Manage logs (delete unwanted/needless log messages)?

-> Create jobs (using T-SQL) from SQL Server Enterprise Manager.

Howto: merge the route and simplify the system?

-> Use SoftEther or other VPN products.

Howto: merge outputs of Snort?

-> Consult with docs around Snort.

http://www.winsnort.com/ or http://www.snort.org/ are both good-starts.

Ah, it seems I am gonna miss the last train, so see ya later!


YamaKen at the office in Tokyo.
Published 29 January 2004 11:18 PM by kenji