Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Troube Adding 3Com Switches as Syslog Nodes

$
0
0

Are you using "Scan for New Nodes" to find them? It sounds like it found something, and you added the connectors, or configured them manually, but it's still not finding them?

 

Here's the thing about the auto-scan: it wants at least 100 lines in the log file before it'll consider it enough hits to match a connector. The big reason we did this was with too few events it's too easy for a connector to match multiple possible choices, which makes automatically picking the right one confusing. We might want to do a "deeper scan" sort of thing where we show you EVERYTHING we found and you can pick. There are also some connectors that are excluded from the scan process because they generate/match everything, and would always be presented as an option. You'll always have to configure those manually.

 

When configuring connectors manually, the default log file is sometimes hard to choose, and might not match where your log data actually is (the easy rule is /var/log/facility.log, e.g. local1.log, local2.log, ...).

 

The last possibility is that those messages really don't match a connector, or the format has changed from the connectors we've built.

 

So, from here, if you can tell me what you've tried and where you're seeing the data, I can tell you a few more things to try. And, if you can paste a few lines of the log (you can scrub IPs) I can confirm which manual connector to configure in case we have to do it by hand.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>