Quantcast
Channel: THWACK: Popular Discussions - Kiwi Syslog
Viewing all 15803 articles
Browse latest View live

Kiwi Syslog 9.4 Release Candidate is Now Available!

$
0
0

The engineering effort on Kiwi Syslog Server (KSS) v9.4 Release Candidate has been completed. RC is the last step before general availability and is a chance for existing customers to get the newest functionality before it is available to everyone else.

You will find the latest version on your customer portal in the Release Candidate section.


Here is the content of this RC version:

  • Moving to a new web server
    This change brings a lot of new functionality "for free". Examples:
  • Active Directory authentication for web access
  • Alerting for Message Queue Monitor
    Be notified when the number of messages in the message queue crosses certain threshold. This indicates there might be performance problems and gives you chance to take an action before messages get dropped.
  • Bug Fixes / resolved cases:

 

408596

AD support for Kiwi web access

416692

3 questions regarding Kiwi Syslog Web Access

396596

AD support for Kiwi web access

327093

Kiwi Syslog accounts - AD tie in?

312151

active directory authentication

299645

AD/LDAP Support for Web Console

491536

Kiwi Syslog Web User authentication via AD/LDAP

439899

Broken Support link

450187

Utra Dev Cassini Web Server Service

376801

After web access installation, Cassini Web service stops

380290

Feature Request - Support Newer UltiDev Cassini Server

317512

WebAdmin: HTTPS for Web Front End

159947

SSL for Web Access

491537

https for Kiwi web interface

435117

Alerting for Message Que Monitor

451568

Availability of Buffer statistics for alerting and reporting

447733

Milliseconds in Syslog in Descending Order!

459792

Feature Request - Email Summarization

465803

Database maintenance settings in Kiwi Syslog Webaccess doesn´t work

412290

Reducing number of syslogs on web access

412867

Question

416258

Radio button missing text on Archive Schedule Destination tab

416169

Wrong version displayed when cancelling licensing

334330

sounds not playing on alert

272984

"play a sound once" does not work

342995

Service crash after ORACLE ODBC configuration

427158

Status on 9.3.4

373025

Problem Creating Table for Oracle 11g Release 11.2.0.3.0

493671

Ability to see full list of devices

 

RC builds are made available to existing customers prior to the formal release. These are used to get customer feedback in production environments and are fully supported.


Kiwi Syslog fails to work properly unless service runs as Domain Admin

$
0
0

    Hi All,

 

I hope somebody can help, as I have been pulling my hair out trying to understand what is going on.

I am completely new to Syslog, and was asked to replace or log server recently.

Eagerly I setup a new Server 2008R2 VM, and installed our version of Syslog: (Version 8.3.48 - Registered but out of support)

 

I exported our config from the old box, imported it into the new machine and switched IPs. Straight away, logs started appearing, and I thought all would be well.

 

Now, the logging works, but here is where the problems occur:

 

We use log file rotation set to 1 day max age.

We run verious schedules which move log files to a file server. One schedule copies the locally aged logs to our file server. The other copies performance logs from another server to the file server.

We then also run a prune and clean up task on the file servers log store.

 

When I use a service account with domain admin membership (As well as domain user and backup operator) this all works fine. The log files are rotated, the prune tasks take place and the log files are moved. The email alerts also work for each task.

 

We are trying to do away with service accounts which are domain admins, so I created a service account with just Domain user and backup operator membership. I then made this account local admin on all servers it needs to carry out tasks on, and set it to have access to all the shares.

 

However, when using this account nothing appears to work.

 

Log file rotation:

The log files do not rotate. Sometimes there is a load of entries in the log saying something to the effect of "Log file rotation ignored. Registered version feature"

 

Schedules:

Only 1 of the schedules runs, and even this is temperamental. Some mornings it has run others it has not.

The prune tasks do not run.

It appears to just ignore the tasks.

 

 

So, I guess the question really is, what access does Kiwi Syslog require? Why does nothing appear to work when using a local admin account as opposed to a domain account.

 

Thanks for reading

Cisco ASA Stats

$
0
0

Hello,

 

I am looking to get statistics from our Cisco ASA's.  I am not sure how to get this information out of Kiwi Syslog.

Basically I am looking for the number of users that connected to our Cisco ASA's via IPSec Remote Access and SSL VPN.

Is this even possible?

 

Any help is appreciated.

 

Thanks,

Daniele

Kiwi Syslog + PFsense (parsing firewall log from 2 lines to 1 help)

$
0
0

PROBLEM - pfSense syslogs for firewall event is split into two lines when it is sent to Kiwi syslog app.

 

Is there a way to edit configuration or parsing script to parse the pfSense event as one similar to what the Splunk app can do see link http://www.basementpctech.com/content/pfsense-log-analysis-splunk

 

I understand that this is a PFsense tcpdump/issue, but I have already tried changing link http://redmine.pfsense.org/issues/1938 without any luck, it just don't work, tried all combinations of changes without any luck.

 

Pfsense version = 2.0.1-RELEASE, (amd64) , built on Mon Dec 12 18:16:13 EST 2011 ,FreeBSD 8.1-RELEASE-p6

 

I would really appreciate any help with this, as I have already exhasted searching for a working soloution using Kiwi Syslog, and the only thing holding me back from purchasing this application.

 

Appreciate any help on this..........

 

 

Example from Kiwi Syslog

 

02-06-2013 13:01:35 Local0.Info 10.x.x.x Feb  6 13:01:37 pf: <009>  Client-Ethernet-Address 00:50:56:9d:53:fc [|bootp]

02-06-2013 13:01:35 Local0.Info 10.x.x.x Feb  6 13:01:37 pf:     10.x.x.xx.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 00:xx:56:9d:53:fc, length 313, xid 0xf7d8ecbb, secs 3328, Flags[bcast]

02-06-2013 13:01:35 Local0.Info 10.x.x.x Feb  6 13:01:37 pf: 00:00:08.003040 rule 1/0(match): block in on em0: (tos 0x0, ttl 128, id 12646, offset 0, flags [none], proto UDP (17), length 341)

02-06-2013 13:01:35 Local0.Info 10.x.x.x Feb  6 13:01:37 pf: <009>  Client-Ethernet-Address 00:xx:56:9d:53:fc [|bootp]

Kiwi Syslog Server - Status Code 500

$
0
0

Hi community. I ve searched about my problem but only found topics related about Orin software. I am getting an exception in Kiwi Syslog Web Access. Status Code 500. Any one have experienced this issue ? Thanks a lot.

Exception of type  'System.Web.HttpUnhandledException' was thrown.

Status Code: 500


System.Web.HttpUnhandledException:  Exception of type 'System.Web.HttpUnhandledException' was thrown. --->  System.ArgumentOutOfRangeException: 'capacity' must be  non-negative.
Parameter name: capacity
at  System.Collections.ArrayList..ctor(Int32 capacity)
at  RadGridUserSettings.GetSerializedSettings()
at _Event.Render(HtmlTextWriter  writer)
at System.Web.UI.Control.RenderControlInternal(HtmlTextWriter writer,  ControlAdapter adapter)
at System.Web.UI.Control.RenderControl(HtmlTextWriter  writer, ControlAdapter adapter)
at  System.Web.UI.Control.RenderControl(HtmlTextWriter writer)
at  Telerik.Web.UI.RadAjaxControl.RenderPageInAjaxMode(HtmlTextWriter writer,  Control page)
at System.Web.UI.Control.RenderChildrenInternal(HtmlTextWriter  writer, ICollection children)
at  System.Web.UI.Control.RenderChildren(HtmlTextWriter writer)
at  System.Web.UI.Page.Render(HtmlTextWriter writer)
at  _Event.Render(HtmlTextWriter writer)
at  System.Web.UI.Control.RenderControlInternal(HtmlTextWriter writer,  ControlAdapter adapter)
at System.Web.UI.Control.RenderControl(HtmlTextWriter  writer, ControlAdapter adapter)
at  System.Web.UI.Control.RenderControl(HtmlTextWriter writer)
at  Telerik.Web.UI.RadAjaxControl.RenderPageInAjaxMode(HtmlTextWriter writer,  Control page)
at System.Web.UI.Control.RenderChildrenInternal(HtmlTextWriter  writer, ICollection children)
at  System.Web.UI.Control.RenderChildren(HtmlTextWriter writer)
at  System.Web.UI.Page.Render(HtmlTextWriter writer)
at  _Event.Render(HtmlTextWriter writer)
at  System.Web.UI.Control.RenderControlInternal(HtmlTextWriter writer,  ControlAdapter adapter)
at System.Web.UI.Control.RenderControl(HtmlTextWriter  writer, ControlAdapter adapter)
at  System.Web.UI.Control.RenderControl(HtmlTextWriter writer)
at  System.Web.UI.Page.ProcessRequestMain(Boolean includeStagesBeforeAsyncPoint,  Boolean includeStagesAfterAsyncPoint)
--- End of inner exception stack trace  ---
at System.Web.UI.Page.HandleError(Exception e)
at  System.Web.UI.Page.ProcessRequestMain(Boolean includeStagesBeforeAsyncPoint,  Boolean includeStagesAfterAsyncPoint)
at  System.Web.UI.Page.ProcessRequest(Boolean includeStagesBeforeAsyncPoint, Boolean  includeStagesAfterAsyncPoint)
at System.Web.UI.Page.ProcessRequest()
at  System.Web.UI.Page.ProcessRequestWithNoAssert(HttpContext context)
at  System.Web.UI.Page.ProcessRequest(HttpContext context)
at  ASP.events_aspx.ProcessRequest(HttpContext context)
at  System.Web.HttpApplication.CallHandlerExecutionStep.System.Web.HttpApplication.IExecutionStep.Execute()
at  System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean&  completedSynchronously)

Resource: http://localhost:8088/Events.aspx
Referrer: http://localhost:8088/Gateway.aspx


Click here to return to the previous  page    Click here to return to the login  page

Aruba ClearPass and syslog messages truncated

$
0
0

Hello,

 

I have a problem with my Kiwi Syslog server and syslog messages received from my Aruba ClearPass Server. So I get the messages, no problem with that, but they are truncated. I mean, I don't get the full syslog message.

 

Here is an example : 10-09-2013 11:52:18 Local1.Debug 1.1.1.1 2013-10-09 10:48:42,270 1.1.0.1 Guest Access 66 1 0 RADIUS.Auth-Method=PAP,RADIUS.Auth-Source=Local:localhost,

 

Normally, here are all the information sent by Aruba ClearPass (and that should be present into the message) :

 

RADIUS.Acct-Authentic

RADIUS.Acct-Called-Station-Id

RADIUS.Acct-Calling-Station-Id

RADIUS.Acct-Delay-Time

RADIUS.Acct-Framed-IP-Address

RADIUS.Acct-Input-Octets

RADIUS.Acct-Input-Pkts

RADIUS.Acct-NAS-IP-Address

RADIUS.Acct-NAS-Port

RADIUS.Acct-NAS-Port-Type

RADIUS.Acct-Output-Octets

RADIUS.Acct-Output-Pkts

RADIUS.Acct-Service-Name

RADIUS.Acct-Session-Id

RADIUS.Acct-Session-Time

RADIUS.Acct-Status-Type

RADIUS.Acct-Termination-Cause

RADIUS.Acct-Timestamp

RADIUS.Acct-Username

RADIUS.Auth-Method

RADIUS.Auth-Source

 

As you can see, there are only the last 2 parameters which I can see on Kiwi Syslog. Is there something to setup in Kiwi ?

 

Thanks for you help.

 

Dimitri

Kiwi Syslog and Sonicwall Viewpoint log format are compatible?

$
0
0

There is some function on kiwi that I lost if I use sonicwall standard log format?

Log Forwarder for Windows (available to all Kiwi customers on maint)

$
0
0

What it does:

Log Forwarder for Windows allows you to forward Windows events as Syslog to your Kiwi Syslog Server

  • Works on Windows XP, 2003, Vista, and 2008 (32-bit or 64-bit)
  • Provides .MSI version for silent installs, allowing use with remote software distribution systems (e.g., Microsoft SMS)
  • Enables definition of filters that describe which events are forwarded

How to get it:

If you download the Kiwi Syslog Server 9.0 from your customer portal, you will see there is an additional Log Forwarder executable included with your download.   The Log Forwarder for Windows was developed by the Kiwi Syslog team.  It is available at no cost to Kiwi Syslog customers current on maintenance.

Try it out and let us know what you think!


Syslog Manager fails to start on win 8.1

$
0
0

syslog_manager.exe 9.4.0.1 will not open correctly on windows 8.1. The process starts and can be seen in task manager, but closes a few second later. No GUI is seen at all not even the splash screen or the notification area icon.

 

there are no logs inside:

C:\Program Files (x86)\Syslogd\Dated logs

C:\Program Files (x86)\Syslogd\Logs

 

i tried calling (Service – Debug start-up: www.kiwisyslog.com/help/syslogd7/index.html?adv_reg_servicedebugstart_up.htm):

syslog_manager.exe DEBUGSTART

syslog_manager.exe /DEBUGSTART

syslog_manager.exe -DEBUGSTART

syslog_manager.exe --DEBUGSTART


but still no log or debug log files are created in the C:\Program Files (x86)\Syslogd directory or any of its sub directories.


i checked the window event log and found the same four error reoccurring every time the syslog_manager.exe is started up

 

==============================

Error 1

==============================

 

Fault bucket -339880763, type 1

Event Name: APPCRASH

Response: Not available

Cab Id: 0

 

Problem signature:

P1: Syslogd_Manager.exe

P2: 9.4.0.1

P3: 5256d7ac

P4: StackHash_4527

P5: 0.0.0.0

P6: 00000000

P7: c000041d

P8: PCH_1C_FROM_actskn43+0x00014197

P9:

P10:

 

Attached files:

C:\Users\user\AppData\Local\Temp\WER7A1F.tmp.WERInternalMetadata.xml

 

These files may be available here:

C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Syslogd_Manager._1c26be14be8bc7e884ee84c763454f0becaea_d6be21d2_0a3f7cfe

 

Analysis symbol:

Rechecking for solution: 0

Report ID: 89cea6aa-4b23-11e3-befa-001b63a57b6a

Report Status: 0

Hashed bucket: ee82e4cf87c028d8fde4d29d457939f8

 

==============================

Error 2

==============================

 

Faulting application name: Syslogd_Manager.exe, version: 9.4.0.1, time stamp: 0x5256d7ac

Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000

Exception code: 0xc000041d

Fault offset: 0x040705b8

Faulting process ID: 0xbe0

Faulting application start time: 0x01cedf304b48bb7b

Faulting application path: C:\Program Files (x86)\Syslogd\Syslogd_Manager.exe

Faulting module path: unknown

Report ID: 89cea6aa-4b23-11e3-befa-001b63a57b6a

Faulting package full name:

Faulting package-relative application ID:

 

==============================

Error 3

==============================

 

Fault bucket 50, type 5

Event Name: BEX

Response: Not available

Cab Id: 0

 

Problem signature:

P1: Syslogd_Manager.exe

P2: 9.4.0.1

P3: 5256d7ac

P4: StackHash_f2c9

P5: 0.0.0.0

P6: 00000000

P7: PCH_3D_FROM_ntdll+0x0003C1AC

P8: c0000005

P9: 00000008

P10:

 

Attached files:

C:\Users\user\AppData\Local\Temp\WER7676.tmp.WERInternalMetadata.xml

 

These files may be available here:

C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Syslogd_Manager._4bac366436d77f4150a9f635e3ff4264d568c57d_d6be21d2_070f7973

 

Analysis symbol:

Rechecking for solution: 0

Report ID: 893e635c-4b23-11e3-befa-001b63a57b6a

Report Status: 0

Hashed bucket: 18c71da6583848b95798fbf0fc6b19c1

 

==============================

Error 4

==============================

 

Faulting application name: Syslogd_Manager.exe, version: 9.4.0.1, time stamp: 0x5256d7ac

Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000

Exception code: 0xc0000005

Fault offset: 0x040705b8

Faulting process ID: 0xbe0

Faulting application start time: 0x01cedf304b48bb7b

Faulting application path: C:\Program Files (x86)\Syslogd\Syslogd_Manager.exe

Faulting module path: unknown

Report ID: 893e635c-4b23-11e3-befa-001b63a57b6a

Faulting package full name:

Faulting package-relative application ID:

Going insane with Kiwi Syslog

$
0
0

Trying to find any reason to continue with Kiwi Syslog.

 

So here's where I'm at:

 

Barracuda Firewall configured as 192.168.1.1 sending UDP 514 messages to my machine 192.168.4.107 (yes they can ping each other). Configured Kiwi to listen on UDP 514.

I've confirmed that the messages are being received:

kiwi.png

I've confirmed that UDP port 514 is open:

kiwi2.png

If I don't bind the address, I can send and receive text messages but it doesn't log actual traffic.

kiwi3.png

If I do bind the address, I still don't receive messages. (I get no errors in the error log either way)

I tried Kiwi SyslogGen and it says "Message Sent OK" but it also says "0 messages sent" so I don't know what it's trying to say.

It seems like it's sending messages but Kiwi doesn't receive them. I've adjusted target/source addresses and still nothing.

kiwi4.png

I tried adding a firewall rule to enable the traffic but it still didn't work so I turned off my firewall completely and still nothing.

 

I rebooted, tried again, reinstalled Kiwi, tried again and it's still not receiving messages.

 

I'm going crazy here. Any advice?

Recommend Kiwi Syslog on LinkedIn for 300 points!

Alert Message - Add Host

$
0
0

Kiwi Syslog Version 9.4.

 

I am pretty new here. Just setting up one Syslog Server for one of our branch router. I keep receiving the following message. Once per five minutes in average.

 

klogd: @ = Add Host : [MAC Address] VID 9 LinkID 1 PortNumber 6

 

Obviously, I haven't added any new host and I don't have any Port Number 6 in the device that I log. The device only contains 1 WAN port and 4 LAN port. That's it!

 

Would you please let me know what this alert message means? Thanks!

How to delete old records from Kiwi Syslog Web Access?

$
0
0

How to delete records from the Kiwi Syslog Web Access?

Thanks.

Kiwi Syslog and Sonicwall Viewpoint log format are compatible?

$
0
0

There is some function on kiwi that I lost if I use sonicwall standard log format?

Log Forwarder for Windows (available to all Kiwi customers on maint)

$
0
0

What it does:

Log Forwarder for Windows allows you to forward Windows events as Syslog to your Kiwi Syslog Server

  • Works on Windows XP, 2003, Vista, and 2008 (32-bit or 64-bit)
  • Provides .MSI version for silent installs, allowing use with remote software distribution systems (e.g., Microsoft SMS)
  • Enables definition of filters that describe which events are forwarded

How to get it:

If you download the Kiwi Syslog Server 9.0 from your customer portal, you will see there is an additional Log Forwarder executable included with your download.   The Log Forwarder for Windows was developed by the Kiwi Syslog team.  It is available at no cost to Kiwi Syslog customers current on maintenance.

Try it out and let us know what you think!


Kiwi Syslog Server High CPU Utilization - Messages Seem to be behind

$
0
0

The CPU on my Kiwi Syslog Server is Pegged.  Here is the Diagnostic info file from the server.

 

Kiwi Syslog Server [Registered] Version 9.0.3


///       Kiwi Syslog Server Statistics         ///
---------------------------------------------------
24 hour period ending on: Wed, 08 Sep 2010 14:44:34
Syslog Server started on: Wed, 08 Sep 2010 13:37:39
Syslog Server uptime:     1 hour, 7 minutes
---------------------------------------------------

+ Messages received - Total:          1098753
+ Messages received - Last 24 hours:  1098753
+ Messages received - Since Midnight: 1098753
+ Messages received - Last hour:      996804
+ Message queue overflow - Last hour: 416654
+ Messages received - This hour:      101949
+ Message queue overflow - This hour: 12336
+ Messages per hour - Average:        996804

+ Messages forwarded:                 769810
+ Messages logged to disk:            1194581

+ Errors - Logging to disk:           0
+ Errors - Invalid priority tag:      0
+ Errors - No priority tag:           2
+ Errors - Oversize message:          309

+ Disk space remaining on drive E:    41554 MB

    Breakdown of Syslog messages by severity  
+--------------------+------------+------------+
| Message Level      |  Messages  | Percentage |
+--------------------+------------+------------+
| 0 - Emerg          |         0  |      0.00% |
| 1 - Alert          |      2753  |      0.25% |
| 2 - Critical       |       496  |      0.05% |
| 3 - Error          |      5745  |      0.52% |
| 4 - Warning        |    103603  |      9.43% |
| 5 - Notice         |     42938  |      3.91% |
| 6 - Info           |    775902  |     70.62% |
| 7 - Debug          |    167316  |     15.23% |
+--------------------+------------+------------+

Custom statistics
-----------------
CustomStats01: 0
CustomStats02: 0
CustomStats03: 0
CustomStats04: 0
CustomStats05: 0
CustomStats06: 0
CustomStats07: 0
CustomStats08: 0
CustomStats09: 0
CustomStats10: 0
CustomStats11: 0
CustomStats12: 0
CustomStats13: 0
CustomStats14: 0
CustomStats15: 0
CustomStats16: 0

End of Report.


DNS Cache size  20000
DNS Cache entries 2
Entries in queue 0
DNS Cache hits  0
DNS Cache misses 0
DNS Cache TTL  1440 minutes
Total DNS Lookups 0
Successful cache hits 0%


IP Address Hostname TTL (minutes)
127.0.0.1       localhost Static
::1             localhost Static


Message Buffer Information
==========================
Message Queue Max Size: 20000
Message Queue overflow: 428990
Message Count:          19932
Message Count Max:      20000
Percentage free:        1

 

E-mail Buffer Information
==========================
Message Queue Max Size: 1000
Message Queue overflow: 0
Message Count:          0
Message Count Max:      13
Percentage free:        100

Kiwi Syslog not capturing syslogs

$
0
0

Installed Kiwi Syslog Free version 9.3.4 on Windows Server 2008 R2.  Trying to capture syslog from a Cisco ASA 5510.  I have confirmed that the syslog events are hitting the server with Wireshark.  Nothing is coming through to Kiwi Syslog.  Current settings are all default.  No filters in place.  Not sure what is wrong as I can see the syslog messages coming through Wireshark. Any ideas as to why the syslog messages are not being seen by Kiwi?

Kiwi Syslog Web Access

$
0
0

Hi, I am new to Kiwi Syslog and I keep coming up with the attached error when installing the web access component.

I have upgraded Syslog Server to 9.4.1 and can't seem to get this going.  I don't know if it was ever working to begin with.

When I try and go to http://localhost:8088 I get an error that "The resource cannot be found".

 

Is there any pre requisites that need to be pre installed on the server for web access to run?  We have it running on Windows Server 2008 R2 Ent. SP1

Sending events from Cisco 3750 switch

$
0
0

Hello,

I am trying to send events from a Cisco 3750 switch to our Kiwi syslog server but am unsure of the config for the switch.

Should the following work:

Switch (config) # logging on
Switch (config) # logging Syslog Server IP
Switch (config) # logging trap error

This command will send (Error 3) events (0-3) to the Kiwi server via UDP514. Is this the supported method of transfer?

Should this work or is there a "Supported" switch configuration that I should be using.

Thank you,

Chris

Kiwi Syslog - Filtering "Message" Using RegEx Not Responding

$
0
0

I'm trying to set a MESSAGE filter looking for the string "src=10.1.1." - then I want to append a regex to limit the IP Addresses in this Rule.

For example, the field input I use is:

"src=10.1.1."[1-9]|[1-4][0-9] (src=10.1.1.1 thru src=10.1.1.149)

but all IP's are visible.

For testing, I use "src=10.1.1."[2], and make sure the test string IP Address is 10.1.1.2 - test passes.

So I change the string to "src=10.1.1."[4], and force an event on that server. It appears in the messages - but so still do all the other IP's.

Can someone identify why this regex is not working?

Thx

Viewing all 15803 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>