Quantcast
Channel: THWACK: Popular Discussions - Kiwi Syslog
Viewing all 15803 articles
Browse latest View live

Kiwi Syslog WebAccess Installation Error (error code is 2869)

$
0
0

*Kiwi Syslog Server V.9.1.0
*Windows 2008 SP1 and SP2 64bit

Our client encountered a Kiwi Syslog WebAccess installation error.

The error message is as follows:
=============================================
The installer has encountered an unexpected error
installing this package. This may indicate a problem
with this package.The error code is 2869.
=============================================
*Kiwi Syslog Server service runs correctly.

*The client stopped Anti-Virus service before the installation.

 

Are there some information to resolve the problem?


Syslog chrashes when scheduler archives log files

$
0
0

Every night our log files are copied to a dated folder.

But on one syslogserver this doesn't work. At midnight when the scheduler starts the archiving ths syslog servers stops. Restarting the syslog servers is not possible, a restart of the server is needed.

I tried different versions, with all the same result.

The scheduler is configured very basic, only to perform a copy from one directory to another on the same local server. No other options are selected.

These are the messages in the errorlog file :

2011-01-15 00:03:22    *** INTERNAL PROGRAM ERROR - Please contact http://www.kiwisyslog.com/support/ ***
2011-01-15 00:03:22    Service Version 9.2.1 | Error Number: 429 | Description: ActiveX component can't create object | Module Name: ProxyScheduleArchiver.cls | Procedure Name: Class_Initialize | Line Number: 10 | Date and time: 15/01/2011 0:03:22

 

Somebody any ideas ?

 

Thanks.

Event Log Forwarder - Where is the Audit Failure Type?

$
0
0

Hi There,

 

I'm trialing Kiwi Syslog and I'm having trouble with the Log Forwarder and Security Event Log.  When I click on the Security Log I don't see Audit Success or Audit Failure as an event type.  It just has Error, Warning and Information.  If I manually edit the CFG file and add <int>16</int> it works, but then it gets overwritten if I make a change.  Am I doing something wrong?  How can I see Audit Failure as an Event Type?

 

Thanks,

sys log server errors "FormatMessage failed with 1815" help please!!

$
0
0

Good day Community,

 

I am experiencing an urgent issue. The sys log server forwarder is forwarding the following message to the KIWI sys log server. The actual security logs are showing the correct information, however the message below is being showed. I thought it was the server, but wen I added another sever to forward security logs, I am getting the same message as shown below.

 

Can anyone who have encountered this message or know how to resolve this issue. The security logs are on the server and I can view them using event viewer properly and audit logs are reflecting fine.

 

I would really appreciate your humble assistance or comments.

 

 

 

Apr 08 14:36:34 CASSIOPEIA1.carimed.local MSWinEventLog 5 Security 495 Wed Apr 08 14:36:33 2015

4624 Microsoft-Windows-Security-Auditing N/A Audit Success CASSIOPEIA1.carimed.local 12544

The description for Event ID 4624 from source Microsoft-Windows-Security-Auditing cannot be

found. Either the component that raises this event is not installed on your local computer or

the installation is corrupted. You can install or repair the component on the local computer.If

the event originated on another computer, the display information had to be saved with the

event.The following information was included with the event: S-1-0-0. FormatMessage failed with

error 1815, The specified resource language ID cannot be found in the image file.

I'm HIRING Solarwinds Certified Professions for a project in DC! Interviewing TODAY!

$
0
0

My name is Juliana. I am a recruiter with Clarus Group and I am hiring a team of 2 Solarwinds Certified Professionals. I need one Senior and one Junior-mid level for a long term contract/contract-hire opportunity (1yr+) in Washington, DC. This project would not start for another month or so but, we need to identify our team now. This team would have to be on site for this role.

 

Great opportunity, competitive pay! I do have a deadline TODAY by Close of Business. Send resumes to jbuonanno@clarusgp.com if interested and call 443-478-4365 to discuss this opportunity further. Talk to you soon!

Setting Up a Syslog Server

$
0
0

Dear All,

 

We are planning to setup a syslog server. i.e, move from Orion inbuilt syslog to kiwi syslog.

We are not utilizing orion inbuilt at this point to fullest. Just few devices are configured to send logs to this inbuilt syslog

 

We have around 5 devices per centers across 60 location (13 Countries)

 

1) 2 Routers

2) 1 Bandwidth Shaper

3) 2 Switch Stacks

4) 1 WLC with 10 APs minimum

 

Total=250 Devices.

 

I would like to what is the best approach.

 

1) How many syslog license i should be looking at?

2) What kind of server configuration is required ?

3) We need a log retention policy of 15 days. Should I consider to setup a DB to for log storage?

4) Can the Orion inbuilt syslog write messages to external DB storage

How to Split Log Files by IP Address and Date in Kiwi Syslog Server

$
0
0

SolarWinds's own Justin Finley just recorded a video tutorial that shows how to split logs into multiple files by IP address and date in Kiwi Syslog Server.  Specifically, this syslog server tutorial shows how to store logs in separate folders for each source IP address, and then shows how to keep separate log files for each day within those folders.  (e.g., "D:\logs\192.168.000.001\Log2012-07-13.txt")

 

 

External link to Jing: autosplit - justinfinley's library

 

Video Guide:

  • 0:00 Opening Kiwi Syslog's configuration dialog
  • 0:15 Using an "AutoSplit" variable of "IP Address (4 octets)" (%IPAdd4) in the log path to split logs by IP address
  • 0:40 Using an "AutoSplit" variable of "ISO Date" (%DateISO) in the log path to split logs by date

 

Remember to "LIKE" this if you find it useful - that helps other find it too!

Procurve switches not sending syslog messages in KIWI syslog

$
0
0

Hi all,

 

New here, searched for discussions but found no entry on procurve switch(es).

The Procurve switches will not send any syslog messages (wiresharked the server)

Turned on logging on the switch: logging 'ip-address'

 

show debug

 

Debug Logging

  Source IP Selection: Outgoing Interface
  Destination:
   Logging --
     'ip-address' Kiwi Syslog server

       Protocol = UDP
       Port     = 514
     Facility = user
     Severity = info
     System Module = all-pass
     Priority Desc =

 

tried facility 'syslog' still nothing.

 

Only the Procurve switches will not send any syslog messages.

Other devices such as Cisco ASA's work fine.

 

Anyone ideas to solve this?

 

TIA Jaap


Kiwi Syslog Server free ed. not receiving SNMP Traps version 2c

$
0
0

Hello Everybody.

 

I'm having troubles receiving SNMP Traps v 2c on Kiwi Syslog Server Free edition.

Although it is described in the feature list that this is supported (also in the documentation), i can receive version 1 but not 2c.

 

Using Wireshark to listen to the traffic i can clearly see SNMP traps version 2 incoming, but nothing appears on syslog server.

 

Can anyone help?

I asked support@ and sent many mails, but didn't get any answer to the problem, they just said to post my question here because this is a free product.

 

Thank you very much.

Kiwi Syslog Service Keeps crashing

$
0
0

We have been experiencing an issue with our Kiwi Syslog Service crashing about every other day.  We are running version 9 and have a pretty standard setup where we are pushing syslogs from all of our devices in our network.  We have quite a bit of stuff logging to our Syslog server and are easily breaching the 200000 maximum message count throughout the day and getting email's.  We up'ed that and seem to be doing better however the syslog service continues to fail and will at times restart itself based off of the services recovery failure to restart the service but this is happening way to often. 

Has anyone else seen this problem and if so, what kinds of things did you try/do?  Is this box just getting pegged so hard that it's causing the service to malfunction and trip up?  I'm not a Windows guy but is this issue even Windows related?  The only other application we have running on this server is CatTools and it runs clean with no service issues.  The systems team has taken a look at the server and believe this to be related only to the Kiwi application itself. 

Next Steps: I'm thinking of removing and rebuilding the Kiwi 9 application from scratch to see if this corrects the issue but wanted some direction from the forum if anyone has any good ideas/suggestions.

 

Thankyou in advance!

Kiwi Syslog 9.5 Release Candidate is now Available!

$
0
0

The Release Candidate for Kiwi Syslog Server 9.5 is now ready! The new Kiwi Syslog version is packed with great new features and improvements. RC is the last step before general availability, and it is a chance for existing customers to get the newest functionality before it is available to everyone else. You can download it from the LATEST DOWNLOADS FOR YOUR PRODUCTS section of the customer portal. Change filter to "Release Candidate" and click on download button next to Kiwi Syslog RC version.

 

This release contains various improvements such as

 

  • SNMP v3 Trap support
  • SNMP Trap Forwarding
  • Trap fields to VarBinds Elements in Output
  • Logging to Papertrail cloud
  • IPv6 Support
  • Statistics email reports based on different interval
  • Ability to create more than five web console users

 

RC builds are made available to existing customers prior to the formal release. These are used to get customer feedback in production environments and are fully supported. If you have any questions I encourage you to leverage the KSS forum on thwack.

 

Now go and download new version now!

Question about filtering Windows Security Audit Successes.

$
0
0

Hi All!

 

I have a problem filtering succesfull security audits from Windows machines in Kiwi.

I have made a priority filter that excludes notices. Also made a message text filter (complex) with sub-string that excludes "Audit Success" and "Success"

However the server console keeps filling up with succesfull audits. Just installed this yesterday, so this is very new to me, sure im overlooking something.

Any suggestions would be very much appreciated! Thanks!

2015-10-27 14_01_52-filter1.jpg

2015-10-27 14_02_16-Filter2.jpg

Kiwi Memory Leak?

$
0
0

I am curious if there is a known memory leak in the Kiwi Syslog system?  I suspect it's due to the UltiDev Cassini Web Server based on my testing.

 

Windows doesn't show the UltiDev Cassini service using much memory; however, when I disable that service and restart the system I don't see the memory utilization problems making it the obvious culprit.  No matter how much memory I give the system, it will always end up using all of it's memory (I stopped giving it more memory at 4 GB) if the UltiDev Cassini service is running.

 

Thoughts?

Trial Version need to get rid of some devices so I can add others

$
0
0

Hi

Does anyone know where to delete the devices so I can add other to test while using the trial version?

 

thanks

log forwarder and dhcp auditing?

$
0
0

I am needing to forward all of our DHCP audits to the syslog, however I cannot figure out how to do that with the Log Forwarder.  Which source do I use in the Event Viewer?  The audit is logged to a file.  Is there any way to forward changes to files?


syslog server 9.5 log path incorrect

$
0
0

I've newly installed Kiwi syslog server 9.5 in Windows 7 and it is logging to an incorrect path.

 

The log file in setup is: "C:\Program Files (x86)\Syslogd\Logs\SyslogCatchAll-%DateISO.txt".

 

I found a log file here: "C:/Users/gsmith/AppData/Local/VirtualStore/Program Files (x86)/Syslogd/Logs/SyslogCatchAll-2015-10-27.txt".

 

I'm using the free version and I don't see an obvious place to submit a bug report, so I'm posting here.

Problem with filtering in Kiwi Syslog

$
0
0

I am setting up a kiwi syslog server.  Running into a problem with the filtering not working the way I would expect.  I have used Kiwi but that was several years ago.  I have setup a display for a specific switch and have tried several different filter possibilities but still getting syslog messages on the display that dont belong to the switch I am trying to watch. 

I have tried a ip address - simple filter with the ip address of the switch "10.1.1.2".  On the cisco switch, I have used the command logging source-interface vlan 254 which should send out the syslog messages using the ip address in the simple filter I setup.  I have also tried the hostname option with the hostname of the switch "Switch1" but same problem.

It has got to be something simple but so far I havent found the problem.  Since this is the free version, I know I cant call Solar Winds support.

Any suggestions are appreciated.


Ron

Kiwi syslog server service can't start

$
0
0

Hi everyone,

 

I'm using Kiwi syslog server 9 on Windows 2008 R2 server (VMware virtual machine). On 17.8.2012. physical server has stopped responding and customer had to restart it manually. Since then Kiwi syslog server doesn't work. When I try to access it, server's CPU raises to 100%, it is stuck like that for few minutes and then it displays error message in Kiwi grid pop up window saying 'Run-time error '0''.

 

Kiwi syslog service also can't be started, when I try to start it, it says it couldn't be started in timely fashion.

 

I've tried to delete/rename files in c:\program files\solarwinds\kiwi web access\html\app_data but with no success. I've renamed event.sdf to Old_event.sdf and made a copy of Event-blank.sdf and then renamed it to event.sdf.

 

I've raised a support ticket but with no results till now.

 

Do you have any idea what's the problem here?

 

Regards, O


Event Log Forwarder - Where is the Audit Failure Type?

$
0
0

Hi There,

 

I'm trialing Kiwi Syslog and I'm having trouble with the Log Forwarder and Security Event Log.  When I click on the Security Log I don't see Audit Success or Audit Failure as an event type.  It just has Error, Warning and Information.  If I manually edit the CFG file and add <int>16</int> it works, but then it gets overwritten if I make a change.  Am I doing something wrong?  How can I see Audit Failure as an Event Type?

 

Thanks,

SYSLOG to SQL

$
0
0

Brand new KIWI 9.1 eval user... succeeded in getting my SYSLOG fed to a SQL table, but need to parse the msgtext field.   I'm not a script writer, but hope there is a way to do this without scripting???    I've attached an exerpt from what ends up in the SQL table.  The delimiter for the MSGText field is Binary 09 which I believe is a tab?    Also, a screen shot of how my rules are currently set up (and feeding but not parsing...)

The actual log entry would look like this with the underlined bold part being the msgtext to be parsed.......

2010-11-05 13:22:11 Local4.Info 10.0.1.11 Nov  5 13:22:11 iprism: WEB<009>http<009>1288988531<009>P<009>10.31.40.248<009>CKHS_Students<009>cksduser\vollmer3861m<009>287<009>http://pixel.quantserve.com/pixel/p-e4m3Yko6bFYVc.gif?labels=NewsAndReference<009>internet services<009>0<009>HTTPGET<009>200<009>image/gif

 



Any thoughts would be greatly appreciated!

Thanks all...

Viewing all 15803 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>