Logscape Support

Members Login
Username 
 
Password 
    Remember Me  
Post Info TOPIC: Syslog on a Forwarder
Anonymous Coward

Date:
Syslog on a Forwarder
Permalink  
 


Is there any ways to set a forwarder to listen on a port and forward logs from my Cisco ASA?  I dont want to have syslogs being streamed from a remote location to my logscape server.  I'd rather have them sent to a local host and then have them sent onto my indexer.

 

Thanks



__________________
ZG


Veteran Member

Status: Offline
Posts: 60
Date:
Permalink  
 


Hi

I hope I have understood what you are asking. It sounds like you don't want your Cisco ASA shipping directly to the Logscape Syslog Server. To get what you want,

1.) you should set up a syslog server on the localhost to collect your Cisco ASA data. They will be stored somewhere in /var/log depending on your configuration.

2.) Install the forwarder on that host and create a data source pointing to the location where your Cisco ASA syslogs are being collected

3.) As data comes through, it will be searchable from within Logscape.

Once you get this far you can then start exploring your Cisco ASA logs by typing in Cisco error codes or extract fields from the data.

Regards

ZG.



__________________
Anonymous

Date:
Permalink  
 

Your assumption was correct. 

I am now receiving syslogs messages on my forwarder, but i don't see them in my index even after creating the Data Source

I receive the messages in /var/log/syslog/devicename.log

 

My Data Source is set as follows.

Directory: /var/log/syslog

File Mask: DEVICENAME.log

Expires:30

Host Filter: FQDN of server-11003-0

 

 

 



__________________


Member

Status: Offline
Posts: 6
Date:
Permalink  
 

Can you change the file mask to *.log and remove the host filter?

Regards,
NA.

__________________
ZG


Veteran Member

Status: Offline
Posts: 60
Date:
Permalink  
 


I think it may be a good idea to start a new thread called something like, Cisco Search Recipes' or FAQ so that other users can get started quickly with searching Cisco logs.


__________________
Page 1 of 1  sorted by
 
Quick Reply

Please log in to post quick replies.



Create your own FREE Forum
Report Abuse
Powered by ActiveBoard