Quantcast
Channel: THWACK: Popular Discussions - Kiwi Syslog
Viewing all 15803 articles
Browse latest View live

How to Split Logs to Multiple Displays in Kiwi Syslog Server

$
0
0

SolarWinds's own Justin Finley just recorded a video tutorial that shows how to split logs into multiple displays in Kiwi Syslog Server.

 


External link to Jing: Multiple Displays - justinfinley's library

 

Video Guide:

  • 0:00 Unfiltered display (Display 00)
  • 0:10 Showing the rule that sends all messages to Display 00
  • 0:20 Changing the unfiltered display from Display 00 to Display 05
  • 0:25 Checking that the switch happened
  • 0:35 Adding a new filter rule looking for the word "logon" and sending it to Display 01
  • 1:20 Adding a new filter rule looking for the word "logoff" and sending it to Display 02
  • 2:05 Checking that the new filters work
  • 2:25 Renaming "Display 05" to "All Messages"
  • 2:45 Renaming "Display 01" to "Logon" and "Display 02" to "Logoff"
  • 3:10 Checking that the display renaming worked

 

Remember to "LIKE" this if you find it useful - that helps other find it too!


Syslog Server - Can Hostname Be Mapped to IP Address?

$
0
0

I have a new syslog server (freeware) and I work for a large (new) department of state government that broke off from a previous department.

 

Because all the infrastructure still resides in the old department (including DNS), and for other security reasons by which we don't put our firewalls into DNS anyway, I can't/don't want to use DNS to resolve the IP address from the two clustered Cisco ASA firewalls I manage. Furthermore, our firewalls are located in a different data center than where the old infrastructure resides. That means that if the connection goes down, I don't have any logs. As a result, I've added a evaluation syslog server locally in the other data center.

 

Everything works, but I didn't want to see the date/time etc. two times in the display so I turned off embedded date & time. But this also turned off the hostname that comes from Cisco.

 

So the only question left is: Is there any way to manually map a hostname to an IP address so that the hostname appears in that column (instead of just the IP address)?

 

If it only works via DNS, then this turns into an enhancement request.

 

Also, if it doesn't work like I'd like it to, can I map it in the (c:\windows\system32\drivers\) hosts file and have it work through that?

 

 

Thanks...

 

ArchiTech89

Uninstall Syslog service.

$
0
0

Hi,

 

I'm trying to uninstall the 14 day trial of syslog server (9.4.1) eval. installed on Windows Server 2003.

 

There is no uninstall service on the management menu drop down. as per the instructions.

 

"Using the Service Manager, uninstall the service

Use the Manage | Uninstall the Syslogd service menu."

 

Some help required please.

 

Simon.

Windows 2012 error for Kiwi Manager

$
0
0

Has anyone else ever run into this issue?

 

I'm receiving the following error whenever I try to open the Kiwi Syslog Manager (Console).

 

Faulting application name: Syslogd_Manager.exe, version: 9.4.0.2, time stamp: 0x54fda0df

Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000

Exception code: 0xc0000005

Fault offset: 0x043c05b8

Faulting process id: 0x780

Faulting application start time: 0x01d0b3331378b7a3

Faulting application path: C:\Program Files (x86)\Syslogd\Syslogd_Manager.exe

Faulting module path: unknown

Report Id: 51d9622d-1f26-11e5-80eb-0050569a06c7

Faulting package full name:

Faulting package-relative application ID:

 

This is on a fresh physical Windows 2012 server and is running as a local system service.  The service runs, collects logging, and we have web access working.  However, whenever I try to open the Kiwi Manager, it crashes.  I do have a support ticket in place but as of now, it has been sent up to the developers.  It's frustrating for the syslog catchall files because we can't filter what we want.

 

What's weird is that it run perfectly fine on Windows 2003 Storage Server. 

 

Before install i did the following:

Disabled UAC

Disabled any HIPS / HBSS so that doesn't block the install.

Set a different TMP / TEMP directory with read/write privileges.

Tried a dedicated local admin-account to run the service and tried just local system.

 

Any help or information in this regards would be a HUGE help.  I'm pretty stumped at the moment.

Event Log Forwarder - Where is the Audit Failure Type?

$
0
0

Hi There,

 

I'm trialing Kiwi Syslog and I'm having trouble with the Log Forwarder and Security Event Log.  When I click on the Security Log I don't see Audit Success or Audit Failure as an event type.  It just has Error, Warning and Information.  If I manually edit the CFG file and add <int>16</int> it works, but then it gets overwritten if I make a change.  Am I doing something wrong?  How can I see Audit Failure as an Event Type?

 

Thanks,

Unable to Get the Syslog Manager to Open After Install

$
0
0

Hello,

 

I used to have Syslog installed but removed it and now I am trying to reinstall it but I am running into an issue. The install goes smooth with no issues but after the install (using the service version and 9.5) I am unable to open the Manager. It says it is already running and to check the sys tray which it is not there. If I go to Task manager I can see it there running under my username but I cannot kill it (I am a Domain Admin) it just does nothing if I end task and if I "End Process Tree" I get a Access Denied.

 

Anyone else have an issue like this?

Procurve switches not sending syslog messages in KIWI syslog

$
0
0

Hi all,

 

New here, searched for discussions but found no entry on procurve switch(es).

The Procurve switches will not send any syslog messages (wiresharked the server)

Turned on logging on the switch: logging 'ip-address'

 

show debug

 

Debug Logging

  Source IP Selection: Outgoing Interface
  Destination:
   Logging --
     'ip-address' Kiwi Syslog server

       Protocol = UDP
       Port     = 514
     Facility = user
     Severity = info
     System Module = all-pass
     Priority Desc =

 

tried facility 'syslog' still nothing.

 

Only the Procurve switches will not send any syslog messages.

Other devices such as Cisco ASA's work fine.

 

Anyone ideas to solve this?

 

TIA Jaap

Kiwi Syslog not receiving SNMP Traps

$
0
0

Hi all.

 

I have just installed Kiwi Syslog Server 9.5 on a test machine to evaluate its suitability for a project I'm working on. It's currently still running in 14-day Evaluation mode.

 

We can't seem to get it to receive SNMP traps at all. No matter what we do, netstat shows nothing listening on UDP port 162. SNMPv1 traps are being sent to the server, and we can see them in Wireshark arriving at the server, but Kiwi isn't listening for them.

 

In desparation, we tried enabling the Windows SNMP Trap service (although we understand this isn't required?) and this 'absorbed' the traps, but nothing appeared in Kiwi.

 

The test machine is running Windows 7 (32-bit) with the Windows Firewall switched off.

 

Should the 14-day Evaluation be able to receive SNMP traps?

 

Thanks in advance for any advice!


How to Split Logs to Multiple Displays in Kiwi Syslog Server

$
0
0

SolarWinds's own Justin Finley just recorded a video tutorial that shows how to split logs into multiple displays in Kiwi Syslog Server.

 


External link to Jing: Multiple Displays - justinfinley's library

 

Video Guide:

  • 0:00 Unfiltered display (Display 00)
  • 0:10 Showing the rule that sends all messages to Display 00
  • 0:20 Changing the unfiltered display from Display 00 to Display 05
  • 0:25 Checking that the switch happened
  • 0:35 Adding a new filter rule looking for the word "logon" and sending it to Display 01
  • 1:20 Adding a new filter rule looking for the word "logoff" and sending it to Display 02
  • 2:05 Checking that the new filters work
  • 2:25 Renaming "Display 05" to "All Messages"
  • 2:45 Renaming "Display 01" to "Logon" and "Display 02" to "Logoff"
  • 3:10 Checking that the display renaming worked

 

Remember to "LIKE" this if you find it useful - that helps other find it too!

log forwarder and dhcp auditing?

$
0
0

I am needing to forward all of our DHCP audits to the syslog, however I cannot figure out how to do that with the Log Forwarder.  Which source do I use in the Event Viewer?  The audit is logged to a file.  Is there any way to forward changes to files?

Kiwi syslog 9.4 on windows server 2012 64bit Service crash - Possible bug!

$
0
0

Hello , kiwi friends!

 

I am trying to get Kiwi syslog 9.4 to work on windows server 2012 64bit but having problems with the service crashing then i try to start the kiwi syslog server console.

I have applied the kb fix for Microsoft .Net Framework 2 , before that i couldnt install kiwi syslog successfully becuse the service could not start.

http://knowledgebase.solarwinds.com/kb/questions/4386/

 

 

I have the following errors in the windows event viewer!

Error 7000: The Kiwi Syslog Server service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion

Error 7009 : A timeout was reached (30000 milliseconds) while waiting for the Kiwi Syslog Server service to connect.

 

Do you have a solution for this or could it be a new bug in windows server 2012 and the old dot net framework combined ?

 

Thanks in advance.

How to delete old records from Kiwi Syslog Web Access?

$
0
0

How to delete records from the Kiwi Syslog Web Access?

Thanks.

Event Log Forwarder - Where is the Audit Failure Type?

$
0
0

Hi There,

 

I'm trialing Kiwi Syslog and I'm having trouble with the Log Forwarder and Security Event Log.  When I click on the Security Log I don't see Audit Success or Audit Failure as an event type.  It just has Error, Warning and Information.  If I manually edit the CFG file and add <int>16</int> it works, but then it gets overwritten if I make a change.  Am I doing something wrong?  How can I see Audit Failure as an Event Type?

 

Thanks,

Syslog configure to pull Exchange server message tracaking log

$
0
0

looking for a guide to configure syslog server with Exchange server to pull exchange message tracking logs into syslog server.

Faulting application name: Syslogd_Service.exe

$
0
0

I have installed and configured Kiwi Syslog, i recently started noticing the service stops randomly. after looking through event logs im finding that the app keeps crashing and i get the below. any ideas?

 

 

 

 

Faulting application name: Syslogd_Service.exe, version: 9.4.0.2, time stamp: 0x54fda0c5

Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000

Exception code: 0xc0000005

Fault offset: 0x064edf14

Faulting process id: 0x%9

Faulting application start time: 0x%10

Faulting application path: %11

Faulting module path: %12

Report Id: %13

Faulting package full name: %14

Faulting package-relative application ID: %15

 

 

Fault bucket , type 0

Event Name: APPCRASH

Response: Not available

Cab Id: 0

 

 

Problem signature:

P1: Syslogd_Service.exe

P2: 9.4.0.2

P3: 54fda0c5

P4: unknown

P5: 0.0.0.0

P6: 00000000

P7: c0000005

P8: 064edf14

P9:

P10:

 

 

Attached files:

C:\Windows\Temp\WER751C.tmp.WERInternalMetadata.xml

C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_Syslogd_Service._db17ea651912375fcb9862559d784039662e_00000000_cab_1012775e\memory.hdmp

C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_Syslogd_Service._db17ea651912375fcb9862559d784039662e_00000000_cab_1012775e\minidump.mdmp

 

 

These files may be available here:

C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_Syslogd_Service._db17ea651912375fcb9862559d784039662e_00000000_cab_1012775e

 

 

Analysis symbol:

Rechecking for solution: 0

Report Id: e3d4b04b-1f3b-11e5-80de-005056aa628b

Report Status: 4

Hashed bucket:


Kiwi - Palo Alto User ID agent

$
0
0

I have written a perl script to take data from Kiwi, parse out some information and pass it into our Palo Alto UserID agent.  It runs fine when I pass the message in on the command line but when I have kiwi run it (so to pull the data from kiwi) it fails with an error:

 

Error Info: invalid charater on line 1

 

My script looks like this:

 

sub Main() {

  use PAN::API;

  $string = Fields.VarCleanMessageText;

  $SERVER = '127.0.0.1';

 

  #Extract user and IP from string

  if ($string =~ /(\w+)([.+]|(\s))(\w+)(\s|\+|.)(\d+\.\d+\.\d+\.\d+)/) {

       $delim = ($3 eq "+") ? " " : $3;

       $username = "$1\\$2$delim$5";

       $ip_address = $7;

  }

  print "$username : $ip_address \n";

 

  # Create User ID API connection

  $uid=PAN::API::UID->new($SERVER);

 

  #Post data to agent

  $uid->add('login',$name,$address);

  $uid->submit();

 

  return "OK"; #return value for Kiwi

}

 

Thanks for any guidance.

 

Kevin

Pushing in messages(RFC5424) into Kiwi via UDP

$
0
0

Hello

 

I have a number of remote servers which generate logs in the RFC5424 format that I am downloading and pushing into Kiwi via C# and the UDP port. All of the messages are appearing in Kiwi but the Host Name, Date, Time fields are being taken from the server which is performing the download and push into Kiwi rather than the details held in the message.

 

Is it possible to push logs into Kiwi from a server and Kiwi take the data for  Host Name, Date and Time etc from the message content rather than just the server which pushed it in?

 

Really hoping someone can help.

 

Thanks for looking

How to Migrate Kiwi Syslog Server

$
0
0

There are 3 things that you need to consider when migrating Kiwi Syslog Server:


  1. Configuration - to back them up, simply open the Kiwi Syslog Server Manager and click "File -> Export Settings to INI" .
  2. Logs - Manually copy Syslog messages log files. Under Setup, look for all Log to file - action and take note of the path and file name.
  3. License - Deactivate the license from the old server using License Manager Tool first so that you can transfer the license to the new server. Please take note that Activation Key will be different once the license is deactivated. You can refer to the following video for more detail information:

Need Help Troubleshooting - Not Receiving/Displaying Messages

$
0
0

Server 2008 R2 Std

Kiwi Syslog Server 9.4.1

 

I have an older version of Kiwi installed on an old server that is being retired.  I've installed it on the new server, but I cannot get it to display anything.  I exported settings from the other server and imported on this one, then went to Inputs-UDP and set the correct IP to bind it to.

 

  • I've gone through ALL the steps at SolarWinds Knowledge Base :: Kiwi Syslog Daemon is not receiving messages and Kiwi Syslog Server but had no luck getting it to work.
  • I know for a fact that messages are being received -- when I run WireShark with the filter, "udp port 514", I see PLENTY of traffic from my firewall.  Both my firewall and VPN device are sending syslog messages to the old server and the new one.  The old server is still working just fine.
  • Windows Firewall on the new server is completely disabled.
  • I loaded the default rules and settings but still had no luck.
  • I disabled all DNS resolution - no luck.
  • There is no Errorlog.txt in C:\Program Files (x86)\Syslogd.
  • Test messages from within Kiwi work just fine.
  • I finally uninstalled Kiwi, rebooted the server, then reinstalled, and have the same problem.

 

Kiwi is running as LocalService -- I wondered if that might be the problem, but that's how it's running on the old server as well.

 

I'm at a loss as to what to do now.  I tried contacting support, but since I'm using the free version I was directed here.

Administrator Password Missed; Other way to login

$
0
0

Hi,

 

I have recently been handed over Kiwi Syslog server to manage which has both Fat Client and Web Server. Fat Client is directly logged in however Web console could not be logged in. When I checked regarding the password of "Administrator", I have been informed that resource handling it has left long ago and there is no one to tell.

 

Is there a way we can reset the password of Administrator or create a new user from Syslog Fat Client. I cant raise the request with Support as we do not have active maintanence.

 

Thanks,

Syed

Viewing all 15803 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>