Quantcast
Channel: THWACK: Popular Discussions - Kiwi Syslog
Viewing all 15803 articles
Browse latest View live

How to Split Log Files by IP Address and Date in Kiwi Syslog Server

$
0
0

SolarWinds's own Justin Finley just recorded a video tutorial that shows how to split logs into multiple files by IP address and date in Kiwi Syslog Server.  Specifically, this syslog server tutorial shows how to store logs in separate folders for each source IP address, and then shows how to keep separate log files for each day within those folders.  (e.g., "D:\logs\192.168.000.001\Log2012-07-13.txt")

 

 

External link to Jing: autosplit - justinfinley's library

 

Video Guide:

  • 0:00 Opening Kiwi Syslog's configuration dialog
  • 0:15 Using an "AutoSplit" variable of "IP Address (4 octets)" (%IPAdd4) in the log path to split logs by IP address
  • 0:40 Using an "AutoSplit" variable of "ISO Date" (%DateISO) in the log path to split logs by date

 

Remember to "LIKE" this if you find it useful - that helps other find it too!


Can't setup syslog with a Cisco ASA 5505

$
0
0

I have never used Syslogs before but was asked to setup one.

I am having trouble setting it up with my Cisco ASA 5505 security Device.

I can ping FROM the server to the Cisco ASA

I can ping FROM the ASA to the Server.

 

 

 

Things I have done.

 

  1. I have downloaded the Solarwind Kiwi Sylog server.
  2. I installed it as a service.
  3. I tested the Kiwi Syslog server using it's built in testing tool and I received messages. They came in on 127.0.0.1.
  4. In Kiwi Sys Log server I added the IP address of the Cisco ASA.
    1. File - Setup - Input - 192.168.200.1 (Server address)
  5. Inputs - UDP
    1. Made sure Port was set to 514
  6. Logged into the Cisco ADSM management.
  7. Went to:
    1. Configuration - Device Management - Logging
  8. Under Logging setup I selected "Enable"
  9. Logging filters
    1. I enabled Sys Log and selected "Severity:Warnings" for all event classes.
  10. Clicked on "Sys Log Server" from the menu. I added:
    1. Interface: Data (inside which the Sys Log is connected to)
    2. IP Address ( IP address of the Syslog server)
    3. UDP Port 514
    4. EMBLEM and Secure is set to "NO"
  11. Click on "Syslog Setup" on the ASA in the menu structure
    1. Include Timestamp in syslogs
  12. I applied the settings to the ASA and then committed the changes to flash.

 

Any ideas on why the syslog server isn't displaying the info?

 

Thanks so much in advance!

Not receiving Secure (TLS) Syslog messages

$
0
0

Hi community,

 

I'm having a problem with the Kiwi Syslog Server. I want to establish a connection over Secure (TLS) Sylog over TCP between a Cisco ASA 5550 and the Syslog Server 9.3.2 running on a Windows Server 2008 R2. But I can't recieve any messages. It works only with UDP.

The Server is configured as in this tutorial described: http://www.kiwisyslog.com/help/syslog/index.html?inputs___secure_tls_syslog.htm

I've created my certificate with makecert.bat from Xampp and it's selected in the Kiwi certificate browser. This certificate is also imported in the Cisco ASA.

 

I hope somebody can help me.

Thanks

Martin

Kiwi Syslog Server Log Location won't change.

$
0
0

Hey all,

 

I have recently taken over a sys admin position, and am required to move the location of the Kiwi Syslog Server logs to another file location. I have never used it prior.  However, I can't seem to move the file.

 

Kiwi Syslog Server 9.2.1 (Free version.)

Windows Server 2003 SP2 (WORKGROUP)(VM)

 

Current configuration:

Log to Log File

Path and file name:  C:\Program Files\Syslogd\Logs\SyslogCatchAll.txt

 

If I test the configuration, I can see the test messages in the location noted about.  However, after I apply the settings, the older location (a CIFS share) continues to receive the actual syslogs of the devices we monitor.

 

There are three local users, all of which show the same configuration.

 

I have tried deleting and recreating the Log to Log File rule.  No change.

I have tried starting and stopping the service.  No change.

I have tried exporting the system settings, and then reimporting them.  No change.

I have tried searching the registery for the old location.  Nothing found.

 

I have two theories.

1.  The settings are locked for some reason.

2.  The settings are stored somewhere else.

 

Any help would be great.

 

Thanks,

 

Aaron

Solarwinds Padawan

Syslog configure to pull Exchange server message tracaking log

$
0
0

looking for a guide to configure syslog server with Exchange server to pull exchange message tracking logs into syslog server.

android app -> syslog

$
0
0

I downloaded the community version of kiwi.

I've got an app that I'm developing that will submit an event to a syslog server.  So, I need to find out how to quickly configure it to look for a udp message at a specific ip address.

 

Any suggestions?

no log shows on Kiwi Syslog Web Access

$
0
0

I am having kiwi syslog 9.5 installed.

I choose to install as service and also installed the web access.

The syslog console opened fine and I see logs on displayed and also to file.

However, with the web access, it shows nothing (what so ever).  I checked the Setup on Console Manager and see that under Rules i have 2 exact same option for "Log to Syslog Web Access".  Everything under that options checked.

But I still see no log on web access.

 

1) I tried to uncheck all the "Log to Syslog Web Access".

2) Closed the Console Manager and reopened it

3) Checked mark one of the 2 optioins "Log to Syslog Web Access" and everything below it.

4) Opened and log in to web access -> Still see nothing.

 

any idea?

Kiwi Syslog rules with time interval

$
0
0

Hello All,

 

I have created a rule where Kiwi will search for a message within the logs, and email me when this message is found.  We have over 100 devices logging to our Kiwi, so this rule does get fired often.  I would like to set a time interval filter, so that we will be emailed when the rule is true, but only once every 30 minutes. This part seems easy enough, but I only want the time interval filter applied per host.

 

i.e.:  The rule is fired by a log from Host1.  The time interval will stop sending emails for 30 minutes for this host.  The rule will continue sending emails though, if other hosts send the same message.

 

It this possible??

 

Thanks!

Paul


Kiwi syslog forward to QRadar

$
0
0

hello,

 

i am seeing a lot of post where kiwi syslog forwarding to QRadar is not working .

in kiwi site it seems straight forward but I need your help to document all the steps properly.

please post here snapshot of your configuration and steps if you are successful sending kiwi log to QRadar.

thank you

Kiwi Grid Run-Time Error '0'

$
0
0

Installed Kiwi Syslog 9.2.1 on Windows 7 pro SP1 VM ESXI server.  After the installation was complete and rebooted the computer.  This error comes up when i log in.

 

I have searched, but have not found any solutions for this error.

LOG FORWARDER 2012 server DOES NOT FORWARD EVENTS

$
0
0

We are using windows Server 2012 Standard version for Windows log forwarder but logs are not coming on Kiwi Syslog Server 9.6

Integration to WhatsUp Gold in iFrame?

$
0
0
Hi all together.



I am running WhatsUp Gold, but WuG's syslog and eventlog management is very weak.

And ipswitch has no good product for this with a webinterface.



As I only have to monitor approx. 20 servers, I don't want to buy a $$$$-solution. Kiwi syslog server would do it fine.



But for a quick overview on a device, I would like to integrate the informations from Kiwi syslog server into WuG.

WuG does allow; it's possible to insert iframes and insert custom html or a link.

(For further informations: look at http://www.plixer.com/products/netflow-sflow/scrutinizer-whatsupgold.php , there is also a pdf which explains this in detail.
It's for scrutinizer, but should work with every webpage).



I now would like to insert (in the device-report of WuG) a link to the webinterface of Kiwi.

To achieve a smooth operation, I will have to include some informations in the link.

I think this will be:



i) the login + password for the Kiwi Web Access

(Kiwi would be installed on the same machine or a machine in the same subnet; Wug and Kiwi won't be accessible from the web, only from the LAN).


ii) the IP or NetBiosName for the device of interest (on the reports-per-device, I only want to see the device-specific messages)



iii) if possible: Also some sort of filter string; for example to show only Messages from Service ABCD (running on the particular machine).





Question A)

Can I access a Kiwi Syslog Server - Webpage directly by a link including this informations?

If yes - how would such a link look like (I have found nothing on the web).

Are there any guides, how-to's, tips, experiences for this integration?



Question B)

Opening severals reports in WuG would fire several accesses to the Kiwi-Pages using the same login+password combo.

Does this cause any problems on Kiwi?



Kind regards to all,

How to Split Log Files by IP Address and Date in Kiwi Syslog Server

$
0
0

SolarWinds's own Justin Finley just recorded a video tutorial that shows how to split logs into multiple files by IP address and date in Kiwi Syslog Server.  Specifically, this syslog server tutorial shows how to store logs in separate folders for each source IP address, and then shows how to keep separate log files for each day within those folders.  (e.g., "D:\logs\192.168.000.001\Log2012-07-13.txt")

 

 

External link to Jing: autosplit - justinfinley's library

 

Video Guide:

  • 0:00 Opening Kiwi Syslog's configuration dialog
  • 0:15 Using an "AutoSplit" variable of "IP Address (4 octets)" (%IPAdd4) in the log path to split logs by IP address
  • 0:40 Using an "AutoSplit" variable of "ISO Date" (%DateISO) in the log path to split logs by date

 

Remember to "LIKE" this if you find it useful - that helps other find it too!

Forward syslog events to QRadar

$
0
0

I'm trying to forward events from Kiwi Syslog to QRadar SIEM. 

 

In Kiwi Syslog setup, I created an Action: Forward to another host; gave it the QRadar appliance's IP as the Destination IP; selected "Retain the original source address of the message"; clicked the Test button to verify the configuration and got a gree checkmark.

 

The test event was the only event received by the QRadar.  None of the events I'm forwarding have been received as incoming logs on QRadar.

 

I've tried this with and without adding the Kiwi Syslog servers as log sources in QRadar.

 

Do I need to install a universal DSM on the Kiwi Syslog servers?

Kiwi Syslog Server 9.4.1 - Active Directory Settings

$
0
0

Has anyone configured Active Directory Settings in Kiwi Syslog Server 9.4.1?  Below are the available Active Directory Settings available in the Web Access interface under the Admin Tab.

 

  • Domain URL: <Free Form Box>  My domain prepopulated correctly.
  • Authentication Type: <Free Form Box>.  Is this supposed to be NTLM, Kerberos, etc?
  • User Groups: <Free Form Box>  Does the format need to be LDAP based?

Kiwi Syslog Web Access Problem

$
0
0

Hello,

I've got a registered version of Kiwi Syslog Server.

I've got the "Log To Syslog Web Access" Filters set up.

But I don't have any log in the web access.

The only little clue I have is when I do a Syslog_Diagnostics I've got this :

 

SolarWinds.KiwiSyslog.WebAccess.Data

====================================
Component not started.

And this error :

2010-06-01 20:26:46    SolarWinds.KiwiSyslog.WebAccess.Data error: Unable to start component, SQL exception. System.Data.SqlServerCe.SqlCeError: The database file is larger than the configured maximum database size. This setting takes effect on the first concurrent database connection only. [ Required Max Database Size (in MB; 0 if unknown) = 0 ]

Any Ideas ?

Syslog stops logging with no notification

$
0
0

I discovered this morning (only because I didn't receive the nightly report) that two of our Syslog servers stopped logging yesterday afternoon. The nightly archiving and cleanup jobs did not run. The service did not crash. The drive has 63 GB of free space. There are no entries under the Application or System logs in Windows. Under the Errorlog I see this for all of the reporting nodes ("ip.address.#" is placeholder for the actual values in the logs):

 

2015-05-28 15:38:59    Log to file action - Error: Win32File Object [45600] Unknown error.

2015-05-28 15:38:59    Log to file action - Error: Win32File Object [45600] Unknown error.

2015-05-28 15:38:59    Log to file action - Error: FlushCacheLines <Encoding_Failed> - File: E:\Syslogs\Firewalls\ip.address1.txt

2015-05-28 15:39:00    Log to file action - Error: Win32File Object [45600] Unknown error.

2015-05-28 15:39:00    Log to file action - Error: Win32File Object [45600] Unknown error.

2015-05-28 15:39:00    Log to file action - Error: FlushCacheLines <Encoding_Failed> - File: E:\Syslogs\Firewalls\ip.address.1..txt

2015-05-28 15:39:02    Log to file action - Error: Win32File Object [45600] Unknown error.

2015-05-28 15:39:02    Log to file action - Error: Win32File Object [45600] Unknown error.

2015-05-28 15:39:02    Log to file action - Error: FlushCacheLines <Encoding_Failed> - File: E:\Syslogs\Firewalls\ip.address.2.txt

2015-05-28 15:39:03    Log to file action - Error: Win32File Object [45600] Unknown error.

2015-05-28 15:39:03    Log to file action - Error: Win32File Object [45600] Unknown error.

2015-05-28 15:39:03    Log to file action - Error: FlushCacheLines <Encoding_Failed> - File: E:\Syslogs\ESX\ip.address.3.txt

2015-05-28 15:39:03    Log to file action - Error: Win32File Object [45600] Unknown error.

2015-05-28 15:39:03    Log to file action - Error: Win32File Object [45600] Unknown error.

2015-05-28 15:39:03    Log to file action - Error: FlushCacheLines <Encoding_Failed> - File: E:\Syslogs\Firewalls\ip.address.1.txt

2015-05-28 15:39:06    Log to file action - Error: Win32File Object [45600] Unknown error.

2015-05-28 15:39:06    Log to file action - Error: Win32File Object [45600] Unknown error.

2015-05-28 15:39:06    Log to file action - Error: FlushCacheLines <Encoding_Failed> - File: E:\Syslogs\Firewalls\ip.address.1.txt

2015-05-28 15:39:07    Log to file action - Error: Win32File Object [45600] Unknown error.

2015-05-28 15:39:07    Log to file action - Error: Win32File Object [45600] Unknown error.

2015-05-28 15:39:07    Log to file action - Error: FlushCacheLines <Encoding_Failed> - File: E:\Syslogs\ESX\ip.address.4.txt

2015-05-28 15:39:08    Log to file action - Error: Win32File Object [45600] Unknown error.

2015-05-28 15:39:08    Log to file action - Error: Win32File Object [45600] Unknown error.

2015-05-28 15:39:08    Log to file action - Error: FlushCacheLines <Encoding_Failed> - File: E:\Syslogs\Firewalls\ip.address.1.txt

2015-05-28 15:39:11    Log to file action - Error: Win32File Object [45600] Unknown error.

2015-05-28 15:39:11    Log to file action - Error: Win32File Object [45600] Unknown error.

2015-05-28 15:39:11    Log to file action - Error: FlushCacheLines <Encoding_Failed> - File: E:\Syslogs\Firewalls\ip.address.1.txt

2015-05-28 15:39:16    Log to file action - Error: Win32File Object [45600] Unknown error.

2015-05-28 15:39:16    Log to file action - Error: FlushCacheLines <Encoding_Failed> - File: E:\Syslogs\Firewalls\ip.address.1.txt

2015-05-28 15:39:16    Log to file action - Error: Win32File Object [45600] Unknown error.

2015-05-28 15:39:16    Log to file action - Error: FlushCacheLines <Encoding_Failed> - File: E:\Syslogs\ESX\ip.address.5.txt

 

     The log stops there. When I restart the service I see these additional entries in the Error log:

 

2015-05-29 07:17:16    Unable to open InterApp listening socket on TCP port 3300

2015-05-29 07:17:16    Unable to open UDP socket on port 514

2015-05-29 07:19:08    Service running, but Service/Manager comm link is not connecting.

2015-05-29 07:19:28    Unable to connect to Service socket on TCP port 3300

2015-05-29 07:19:38    Service running, but Service/Manager comm link is not connecting.

 

Any ideas?

The list of Windows Update that conflicts with Kiwi Syslog Server

$
0
0

Hi,

I use Kiwi Syslog Server on Windows Server 2016.

 

I got an error on Kiwi Syslog Server due to conflict with Windows Update several times.

 

1) Performed on April 26, 2017

*Environment

- Windows Server 2016

- Kiwi Syslog Server version 9.5.2

 

The following patchs were installed by Windows Update successfully.

KB4015217

KB890830

 

Then KSS is unable to load and presents the following error:

---------------------------

Syslogd

---------------------------

Component 'KiwiSocket.ocx' or one of its dependencies not correctly registered: a file is missing or invalid

---------------------------

 

 

2) Performed on May 19, 2017

*Environment

- Windows Server 2016

- Kiwi Syslog Server version 9.6.1

 

The following patchs were installed by Windows Update successfully.

KB3150513

KB4019472

KB890830

KB4013418

 

 

Then KSS is unable to load and presents the following error:

---------------------------

Syslogd

---------------------------

Component 'XceedZip.dll' or one of its dependencies not correctly registered: a file is missing or invalid.

---------------------------

 

 

[Resolution]

Both cases, I uninstalled and re-installed Kiwi Syslog Server.

 

Please refer:

https://support.solarwinds.com/Success_Center/Kiwi_Syslog_Server/KSS_error_Component_XceedZip_dll_or_one_of_its_dependencies_not_correctly_registered_a_file_is_missing_or_invalid

 

 

 

3) Performed on June 21, 2017

*Environment

- Windows Server 2016

- Kiwi Syslog Server version 9.6.1 

 

The following patchs were installed by Windows Update successfully.

(KB3186568)

(KB4023834)

(KB4022715)

(KB890830)

(KB3150513)

 

Then KSS is unable to load and presents the following error:

---------------------------

Syslogd

---------------------------

Component 'XceedZip.dll' or one of its dependencies not correctly registered: a file is missing or invalid.

---------------------------

 

[Resolution]

I uninstalled and re-installed Kiwi Syslog Server.

 

 

メッセージ編集者:

Date: June 28, 2017

JTC Osaka 

After Windows Update(2017-June-21), KSS can not start again.

Kiwi Syslog Service Keeps crashing

$
0
0

We have been experiencing an issue with our Kiwi Syslog Service crashing about every other day.  We are running version 9 and have a pretty standard setup where we are pushing syslogs from all of our devices in our network.  We have quite a bit of stuff logging to our Syslog server and are easily breaching the 200000 maximum message count throughout the day and getting email's.  We up'ed that and seem to be doing better however the syslog service continues to fail and will at times restart itself based off of the services recovery failure to restart the service but this is happening way to often. 

Has anyone else seen this problem and if so, what kinds of things did you try/do?  Is this box just getting pegged so hard that it's causing the service to malfunction and trip up?  I'm not a Windows guy but is this issue even Windows related?  The only other application we have running on this server is CatTools and it runs clean with no service issues.  The systems team has taken a look at the server and believe this to be related only to the Kiwi application itself. 

Next Steps: I'm thinking of removing and rebuilding the Kiwi 9 application from scratch to see if this corrects the issue but wanted some direction from the forum if anyone has any good ideas/suggestions.

 

Thankyou in advance!

Integration to WhatsUp Gold in iFrame?

$
0
0
Hi all together.



I am running WhatsUp Gold, but WuG's syslog and eventlog management is very weak.

And ipswitch has no good product for this with a webinterface.



As I only have to monitor approx. 20 servers, I don't want to buy a $$$$-solution. Kiwi syslog server would do it fine.



But for a quick overview on a device, I would like to integrate the informations from Kiwi syslog server into WuG.

WuG does allow; it's possible to insert iframes and insert custom html or a link.

(For further informations: look at http://www.plixer.com/products/netflow-sflow/scrutinizer-whatsupgold.php , there is also a pdf which explains this in detail.
It's for scrutinizer, but should work with every webpage).



I now would like to insert (in the device-report of WuG) a link to the webinterface of Kiwi.

To achieve a smooth operation, I will have to include some informations in the link.

I think this will be:



i) the login + password for the Kiwi Web Access

(Kiwi would be installed on the same machine or a machine in the same subnet; Wug and Kiwi won't be accessible from the web, only from the LAN).


ii) the IP or NetBiosName for the device of interest (on the reports-per-device, I only want to see the device-specific messages)



iii) if possible: Also some sort of filter string; for example to show only Messages from Service ABCD (running on the particular machine).





Question A)

Can I access a Kiwi Syslog Server - Webpage directly by a link including this informations?

If yes - how would such a link look like (I have found nothing on the web).

Are there any guides, how-to's, tips, experiences for this integration?



Question B)

Opening severals reports in WuG would fire several accesses to the Kiwi-Pages using the same login+password combo.

Does this cause any problems on Kiwi?



Kind regards to all,
Viewing all 15803 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>