In the correct sourcecode directory
Something like patch -p1 < filename.patch
I'm not sure if this will match and actually started
thinking along the terms of moving the matcher
to the syslogd-configuration.xml that way multiple
regexpes could be inserted.
/je
----- Original Message ----
From: Lee Quince <***@iqunity.com>
To: General OpenNMS Discussion <opennms-***@lists.sourceforge.net>
Sent: Wednesday, November 15, 2006 4:01:03 PM
Subject: Re: [opennms-discuss] syslog-ng / Splunk / OpenNMS
Message
DIV {
MARGIN:0px;}
Johan,
Would love to try it.. but how do I install the
patch?
Regards
Lee
-----Original Message-----
From:
opennms-discuss-***@lists.sourceforge.net
[mailto:opennms-discuss-***@lists.sourceforge.net] On Behalf Of
johan edstrom
Sent: 15 November 2006 02:18
To: General
OpenNMS Discussion
Subject: Re: [opennms-discuss] syslog-ng / Splunk
/ OpenNMS
Lee,
I hope you don't think I'm imposing, but attached is
a patch to
Onms Syslogd I *think* is what you need.
Would you mind trying
it?
/je
-----
Original Message ----
From: Lee Quince
<***@iqunity.com>
To: General OpenNMS Discussion
<opennms-***@lists.sourceforge.net>
Sent: Tuesday, November 14,
2006 5:18:26 PM
Subject: Re: [opennms-discuss] syslog-ng / Splunk /
OpenNMS
DIV {
MARGIN:0px;}
The sent from host is the first IP address if you ready from left to
right... The last IP was the one dished out when the vpn connected.. Each time
syslog is relayed the address gets added 1/2/3/4/5 and so
on..
-----Original Message-----
From:
opennms-discuss-***@lists.sourceforge.net
[mailto:opennms-discuss-***@lists.sourceforge.net] On Behalf Of
johan edstrom
Sent: 14 November 2006 12:56
To:
General OpenNMS Discussion
Subject: Re: [opennms-discuss]
syslog-ng / Splunk / OpenNMS
Oh
I see, we would need a different greedy regexp.
That would capture the
*last* in a row of IP/IP/IP - right?
It's really only a 3 liner I
think.
-----
Original Message ----
From: Lee Quince
<***@iqunity.com>
To: General OpenNMS Discussion
<opennms-***@lists.sourceforge.net>
Sent: Tuesday, November 14,
2006 7:08:15 AM
Subject: Re: [opennms-discuss] syslog-ng / Splunk /
OpenNMS
UNKNOWN {
FONT-FAMILY:Tahoma;panose-1:2 11 6 4 3 5 4 4 2 4;}
UNKNOWN {
FONT-FAMILY:"Trebuchet MS";panose-1:2 11 6 3 2 2 2 2 2 4;}
P.MsoNormal {
FONT-SIZE:12pt;MARGIN:0in 0in 0pt;FONT-FAMILY:"Times New Roman";}
LI.MsoNormal {
FONT-SIZE:12pt;MARGIN:0in 0in 0pt;FONT-FAMILY:"Times New Roman";}
DIV.MsoNormal {
FONT-SIZE:12pt;MARGIN:0in 0in 0pt;FONT-FAMILY:"Times New Roman";}
A:link {
COLOR:blue;TEXT-DECORATION:underline;}
SPAN.MsoHyperlink {
COLOR:blue;TEXT-DECORATION:underline;}
A:visited {
COLOR:blue;TEXT-DECORATION:underline;}
SPAN.MsoHyperlinkFollowed {
COLOR:blue;TEXT-DECORATION:underline;}
P.msonormal1 {
FONT-SIZE:12pt;MARGIN-LEFT:0in;MARGIN-RIGHT:0in;FONT-FAMILY:"Times New Roman";}
LI.msonormal1 {
FONT-SIZE:12pt;MARGIN-LEFT:0in;MARGIN-RIGHT:0in;FONT-FAMILY:"Times New Roman";}
DIV.msonormal1 {
FONT-SIZE:12pt;MARGIN-LEFT:0in;MARGIN-RIGHT:0in;FONT-FAMILY:"Times New Roman";}
SPAN.EmailStyle20 {
COLOR:navy;FONT-FAMILY:Arial;}
UNKNOWN {
MARGIN:1in 1.25in;}
DIV.Section1 {
}
The problem with
this is as the message is relayed from syslog-NG the UDP source IP is then
the queried and matched host
Hence every syslog event is then seen as the
syslog-NG server.
Two ways forward I
can see
Allow the SyslogD
to match the host,ip from the column in the in the UDP string..
ie..
Nov 14 03:24:39
10.91.254.251/10.129.250.10
Kiwi_Syslog_Daemon l2tp,ppp,info,account ***@iqunity.net logged in,
10.65.251.239
Or is there away
that Splunk can read the OpenNMS event and alert log..??? And Point the
syslog on the node to OpenNMS (this is the least favored
way)
Regards
Lee
From:
opennms-discuss-***@lists.sourceforge.net
[mailto:opennms-discuss-***@lists.sourceforge.net] On Behalf Of johan edstrom
Sent: Monday, November 13, 2006 11:08
PM
To: General OpenNMS
Discussion
Subject: Re:
[opennms-discuss] syslog-ng / Splunk / OpenNMS
Lee
What's in trunk handles BSD
style cascading.
http://www.opennms.org/index.php/Syslogd
I think
tools (with source) for Win32 Eventlog -> Syslog
are readily
available, we use
https://engineering.purdue.edu/ECN/Resources/Documents/UNIX/evtsys/
----- Original Message ----
From:
Lee Quince < ***@iqunity.com >
To:
opennms-***@lists.sourceforge.net
Sent: Monday, November 13, 2006
5:33:57 PM
Subject: [opennms-discuss] syslog-ng / Splunk /
OpenNMS
Any ideals on the best
way to integrate all these???
Currently we have
Syslog-NG collecting
syslogs and piping them into Splunk.. And OpenNMS monitoring and providing
performance Stat's...
Now if only I could get
the events (syslog) into OpenNMS as well..? Is there a way for me to point
SysLog to OpenNMS and Integrate Splunk or Configure SysLog-NG to
relay/forward to OpenNMS, when I tried it before the SysLog's only ever log
as if they were coming from the SysLog-NG
machine....
Ohh before I forget we
are running ONMS 1.3.2 on Debian Etch..
Regards
Lee
Quince
Managing
Technical Director
iQunity Ltd
Undivided Attention
mobile: 07970 070 806
fax: 08703 835 661
Internet
Email Confidentiality Notice:
This
message contains confidential information. If you are not the addressee
indicated in this message, you may not copy or deliver it to anyone.
In
such case, you should destroy this message and kindly notify us by reply
email.
-------------------------------------------------------------------------
Using
Tomcat but need to do more? Need to support web services, security?
Get
stuff done quickly with pre-integrated technology to make your job
easier
Download IBM WebSphere Application Server v.1.0.1 based on Apache
Geronimo
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642
_______________________________________________
Please
read the OpenNMS Mailing List FAQ:
http://www.opennms.org/index.php/Mailing_List_FAQ
opennms-discuss
mailing list
To *unsubscribe* or change your subscription options,
see the bottom of this page:
https://lists.sourceforge.net/lists/listinfo/opennms-discuss
-------------------------------------------------------------------------
Using
Tomcat but need to do more? Need to support web services, security?
Get
stuff done quickly with pre-integrated technology to make your job
easier
Download IBM WebSphere Application Server v.1.0.1 based on Apache
Geronimo
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642
_______________________________________________
Please read the
OpenNMS Mailing List FAQ:
http://www.opennms.org/index.php/Mailing_List_FAQ
opennms-discuss
mailing list
To *unsubscribe* or change your subscription options,
see the bottom of this page:
https://lists.sourceforge.net/lists/listinfo/opennms-discuss
Everyone is raving about the all-new Yahoo! Mail beta.
-------------------------------------------------------------------------
Take
Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's
Techsay panel and you'll get the chance to share your
opinions on IT &
business topics through brief surveys - and earn cash
http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________
Please read the
OpenNMS Mailing List FAQ:
http://www.opennms.org/index.php/Mailing_List_FAQ
opennms-discuss
mailing list
To *unsubscribe* or change your subscription options, see
the bottom of this page:
https://lists.sourceforge.net/lists/listinfo/opennms-discuss
-------------------------------------------------------------------------
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to share your
opinions on IT & business topics through brief surveys - and earn cash
http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________
Please read the OpenNMS Mailing List FAQ:
http://www.opennms.org/index.php/Mailing_List_FAQ
opennms-discuss mailing list
To *unsubscribe* or change your subscription options, see the bottom of this page:
https://lists.sourceforge.net/lists/listinfo/opennms-discuss