Hello,
We got a old Kiwi syslog web access server with allot of different filters that need to be exported.
The problem is that we can only export one at the time... is there a way to export all at ones.
Hello,
We got a old Kiwi syslog web access server with allot of different filters that need to be exported.
The problem is that we can only export one at the time... is there a way to export all at ones.
*Kiwi Syslog Server V.9.1.0
*Windows 2008 SP1 and SP2 64bit
Our client encountered a Kiwi Syslog WebAccess installation error.
The error message is as follows:
=============================================
The installer has encountered an unexpected error
installing this package. This may indicate a problem
with this package.The error code is 2869.
=============================================
*Kiwi Syslog Server service runs correctly.
*The client stopped Anti-Virus service before the installation.
Are there some information to resolve the problem?
Installed 9.2 on Windows Server 2008 R2 from and Windows 2003 R2 (8.2.8). Redirect Cisco ASA 5510 logs to new server, but the only time Kiwi logs anything is at about 10:00pm Sunday nights. If I point the ASA back to Windows 2003 server, it logs normally. I have exported and imported the configuration from the 8.2.8 version, as well. Nothing seems to get the new Windows 2008 R2 9.2 version to actually log. This is still in the evaluation mode. The 2008 R2 does not have a firewall running (and we even allowed it through before hand), nor any A/V software with a firewall. It is odd that it works at 10:00pm on two consecutive Sundays, but not at any other time.
Hi,
I have recently been handed over Kiwi Syslog server to manage which has both Fat Client and Web Server. Fat Client is directly logged in however Web console could not be logged in. When I checked regarding the password of "Administrator", I have been informed that resource handling it has left long ago and there is no one to tell.
Is there a way we can reset the password of Administrator or create a new user from Syslog Fat Client. I cant raise the request with Support as we do not have active maintanence.
Thanks,
Syed
Happy Holidays all!
I'm a longtime user of Kiwi Syslog. In the past, I would set my Max Alert to email me using a garbage AOL account I had setup back in the day. Now, AOL is requiring TLS sign and I can no longer get email notifications from my syslogger. Is there another way around this? How do you get your notifications?
Hi all,
New here, searched for discussions but found no entry on procurve switch(es).
The Procurve switches will not send any syslog messages (wiresharked the server)
Turned on logging on the switch: logging 'ip-address'
show debug
Debug Logging
Source IP Selection: Outgoing Interface
Destination:
Logging --
'ip-address' Kiwi Syslog server
Protocol = UDP
Port = 514
Facility = user
Severity = info
System Module = all-pass
Priority Desc =
tried facility 'syslog' still nothing.
Only the Procurve switches will not send any syslog messages.
Other devices such as Cisco ASA's work fine.
Anyone ideas to solve this?
TIA Jaap
Hi,
When trying to start the Kiwi Syslog Server we are receiving the following error: Error 1053: The service did not respond to the start or control reqest in a timely fashion.
We also get the following messages in Event Viewer:
A timeout was reached (30000 milliseconds) while waiting for the Kiwi Syslog Server service to connect.
We are using the free version and had it running quite happily for 2 months before this issue occured. I can't find what may have changed on the day it started to fail. The tool is running on a Win7 Enterprise machine. I have tried the changes suggested here: http://knowledgebase.solarwinds.com/kb/questions/4386/Kiwi+Syslog+Server+Service+Startup+Failure+in+Versions+9.3.3+and+9.3.4 but they didn't work. I have also read the following but the service for me doesn't start no matter what account is used: http://thwack.solarwinds.com/thread/45470
Any suggestions would be greatly appreciated!
I'm trying to forward events from Kiwi Syslog to QRadar SIEM.
In Kiwi Syslog setup, I created an Action: Forward to another host; gave it the QRadar appliance's IP as the Destination IP; selected "Retain the original source address of the message"; clicked the Test button to verify the configuration and got a gree checkmark.
The test event was the only event received by the QRadar. None of the events I'm forwarding have been received as incoming logs on QRadar.
I've tried this with and without adding the Kiwi Syslog servers as log sources in QRadar.
Do I need to install a universal DSM on the Kiwi Syslog servers?
Hello,
Could you please tell me how to transfer all DHCP events (from a standard Windows 2012 DHCP server) to syslog ?
Thanks in advance for your help
I'm having trouble configuring email alerts. I'm trying to send alerts to my Office 365 email address. Can someone see if I've input one of these settings incorrectly? I'm using my full Office 365 email for each of the blacked out sections in the screen shot below. For "SMTP Password," I'm using my Office 365 password.
1st time starting a discussion.
1st time working with Kiwi Syslog.
Let me know if I'm in the wrong place.
I am very new to Syslog Servers.
I'm a Route/Switch type guy.
We are using Kiwi Syslog to get Call Manager Call Traces for troubleshooting.
This Instance of Kiwi Syslog was working fine as a Guest VMware Server on a Host Server.
We used the app Veeam to move the Kiwi Syslog VMware Guest Server to another Host.
This issue started after the copy/move of the Kiwi Syslog
No IP addresses were changed, it's on the same network as before.
It starts up, logs are being received, and then they stop.
If you try to start the service, it tells you it's already running.
At the bottom of the Kiwi Syslog Service Manager, you can see the MPH indicator has stopped.
Looking at the correct folder I can see the logs are no longer being received.
If I stop the service and start the service it starts.
There is a script that tells it to restart every morning at 4am, and it will do this.
Below is the error event seen when it stopped last time.
Windows Server 2012 R2
64 -bit OS
Has anyone seen this type of issue before?
Any help would be greatly appreciated,
Mhaley
Hello,
I'm currently trying to get the logs of where (what IP) and when (date and time) the Domain Administrator account information is used to log into one of three specific machines (2 DC's, and a Finance server). I'm having some trouble defining the subscription in the Kiwi Log Forwarder - Specifically, what boxes do I need to tick off and what event ID number do I need to include? I have the IP's for the three servers that I want AD to send the Admin login logs from. Thanks!
Happy Holidays all!
I'm a longtime user of Kiwi Syslog. In the past, I would set my Max Alert to email me using a garbage AOL account I had setup back in the day. Now, AOL is requiring TLS sign and I can no longer get email notifications from my syslogger. Is there another way around this? How do you get your notifications?
Hi,
When trying to start the Kiwi Syslog Server we are receiving the following error: Error 1053: The service did not respond to the start or control reqest in a timely fashion.
We also get the following messages in Event Viewer:
A timeout was reached (30000 milliseconds) while waiting for the Kiwi Syslog Server service to connect.
We are using the free version and had it running quite happily for 2 months before this issue occured. I can't find what may have changed on the day it started to fail. The tool is running on a Win7 Enterprise machine. I have tried the changes suggested here: http://knowledgebase.solarwinds.com/kb/questions/4386/Kiwi+Syslog+Server+Service+Startup+Failure+in+Versions+9.3.3+and+9.3.4 but they didn't work. I have also read the following but the service for me doesn't start no matter what account is used: http://thwack.solarwinds.com/thread/45470
Any suggestions would be greatly appreciated!
I have an issue wherein syslog messages from one host are being duplicated. We have a Secure Tunnel client running at one site, with network devices set up to send syslog messages to this client. No syslog messages from any other network device at this site are duplicated. I have verified that this appears to be a Secure Tunnel issue by configuring the offending network device to send syslog messages directly to the Kiwi Syslog Server. When this is done, only one syslog message is logged. When I reconfigure the network device to log to the Secure Tunnel client, two identical syslog messages are logged. I have also verified that there is only one syslog configuration line in the network device (i.e. that it is not configured to send syslogs both directly to the Syslog Server and to the SecureTunnel client.) This is eating up twice as much filespace, obviously... any help would be appreciated.
Hi Guys,
I'm monitoring my Kiwi Syslog Server (on windows) and I am seeing the below alarm but I cant work out what it is. I have tried looking up the OID but it seems to be unknown. Does anyone have any idea what the cause of this error might be please?
I'm running Kiwi Syslog version 8.3.52
Here's the error which is occuring several times per minute:
Created On : 13/01/2010 8:53:42
Name : OUR_NMS
Event : Unknown alert received from device OUR_NMS of type Host_Compaq. Device Time 13+01:32:56. (Trap type 1.3.6.1.4.1.311.1.1.3.1.2.4.0)
Trap var bind data:
Thanks!
Timed_Out
Installed Kiwi Syslog Free version 9.3.4 on Windows Server 2008 R2. Trying to capture syslog from a Cisco ASA 5510. I have confirmed that the syslog events are hitting the server with Wireshark. Nothing is coming through to Kiwi Syslog. Current settings are all default. No filters in place. Not sure what is wrong as I can see the syslog messages coming through Wireshark. Any ideas as to why the syslog messages are not being seen by Kiwi?
Hello,
I have an issue with the migration of my kiwi syslog product.
I have got a new server and I want to migrate my kiwi syslog version on this new server (after deactivating it on the old one).
When I read the documentation it is said to install the licence manager tool.
But when I use it, the tool says "No licensed solarwinds products on your machine".
But my two products are well registered and I can see the licenses on my online account.
Is it possible to deactivate them manually ?
Thanks for your helpsyslog
Hello!
I install Kiwi Syslog Server & Web Access.
Kiwi Syslog Server start and i see events from my devices, but when i start Kiwi Syslog Server Web Access its could not start:
"Kiwi Syslog WebAccess requires Kiwi Syslog Server to be online, but it is offline"
What's problem?
Version 9.2
Hi,
I have recently been handed over Kiwi Syslog server to manage which has both Fat Client and Web Server. Fat Client is directly logged in however Web console could not be logged in. When I checked regarding the password of "Administrator", I have been informed that resource handling it has left long ago and there is no one to tell.
Is there a way we can reset the password of Administrator or create a new user from Syslog Fat Client. I cant raise the request with Support as we do not have active maintanence.
Thanks,
Syed