Koozali.org: home of the SME Server

Exporting SYSLOG(s) to Remote Server?

Offline bloxguy

  • *
  • 6
  • +0/-0
Exporting SYSLOG(s) to Remote Server?
« on: May 15, 2014, 12:24:28 AM »
Is there anyway to export the syslogs from /var/logs/messages to an external SYSLOG server, ie: SPLUNK?
if so, how can I set this up?

Is there a chance this feature could also be added to the general configuration of the server?
it would be great to be able to monitor SME servers using SPLUNK.

Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
Re: Exporting SYSLOG(s) to Remote Server?
« Reply #1 on: May 15, 2014, 03:01:38 AM »
Is there anyway to export the syslogs from /var/logs/messages to an external SYSLOG server, ie: SPLUNK?
if so, how can I set this up?

You need to do some reading of the documentation here. Search for "custom templates".

Quote
Is there a chance this feature could also be added to the general configuration of the server?

Again, please read some of the documentation here. You can ask for New Feature Requests via the bug tracker. But you need to be aware that there are many more feature requests than there are developers to implement them. If you want something, do it yourself, and then contribute it.

Offline Stefano

  • *
  • 10,894
  • +3/-0
Re: Exporting SYSLOG(s) to Remote Server?
« Reply #2 on: May 15, 2014, 10:13:57 AM »
You need to do some reading of the documentation here. Search for "custom templates".

or just search the wiki:

http://wiki.contribs.org/Syslog

Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
Re: Exporting SYSLOG(s) to Remote Server?
« Reply #3 on: May 15, 2014, 03:04:41 PM »
or just search the wiki:

http://wiki.contribs.org/Syslog

Those deal with information flow in the other direction, i.e.. into SME server. OP wants syslog messages to flow out from SME server to another system.

OP needs "*.*   @a.b.c.d" entries in syslog.conf, via a custom template.
« Last Edit: May 15, 2014, 03:19:51 PM by CharlieBrady »

Offline Stefano

  • *
  • 10,894
  • +3/-0
Re: Exporting SYSLOG(s) to Remote Server?
« Reply #4 on: May 15, 2014, 03:10:50 PM »
doh, you're right.. :-)

I really need more coffee in the morning.. ;-)

Offline bloxguy

  • *
  • 6
  • +0/-0
Re: Exporting SYSLOG(s) to Remote Server?
« Reply #5 on: May 15, 2014, 04:45:14 PM »
Thanks for the heads up, I'd already read all the documentation/wiki, which lead me to this forum.
Everything posted for SME with regards to SYSLOG is for setting up SME as a recipient server not a forwarder.

Instead of custom scripts, etc, I found that SPLUNK has created a "universal forwarder" RPM package that can be adapted to run on SME.
If there is somewhere on the site to post a HOWTO; I would be glad to share the information.
I currently have SME 8.x reporting to SPLUNK 6.1.x with no issues.

but again, as a "nice to have" it would be great to see this built into the product; and made configurable through the GUI.

Offline ReetP

  • *
  • 3,954
  • +6/-0
Re: Exporting SYSLOG(s) to Remote Server?
« Reply #6 on: May 19, 2014, 04:51:27 PM »

If there is somewhere on the site to post a HOWTO; I would be glad to share the information.

The Wiki is the place. You can get an account easily here :

http://wiki.contribs.org/Help:Contents

Quote
but again, as a "nice to have" it would be great to see this built into the product; and made configurable through the GUI.

Lots of things we'd all like to have but it is time and resources :-) We have very little of either.

If you want to look at building this as a contrib then go to the bug tracker and you will get help.

Make sure you are on the mailing lists too :

http://lists.contribs.org/mailman/listinfo/

Please get involved - you have done half the work already !!

B. Rgds
John Crisp
...
1. Read the Manual
2. Read the Wiki
3. Don't ask for support on Unsupported versions of software
4. I have a job, wife, and kids and do this in my spare time. If you want something fixed, please help.

Bugs are easier than you think: http://wiki.contribs.org/Bugzilla_Help

If you love SME and don't want to lose it, join in: http://wiki.contribs.org/Koozali_Foundation