Monitoring windows logs


 
Thread Tools Search this Thread
Top Forums UNIX for Dummies Questions & Answers Monitoring windows logs
# 1  
Old 07-20-2013
Monitoring windows logs

is it possible to monitor log files that are on a windows server, from a linux/unix host?

i'm thinking that the directory that the files are located in on windows can be be mounted on the linux host, and then a script or tool can just monitor the log as though it were local?

any thing wrong with this thinking? please suggest to me other methods i can try.
# 2  
Old 07-21-2013
Quote:
Originally Posted by SkySmart
is it possible to monitor log files that are on a windows server, from a linux/unix host?

i'm thinking that the directory that the files are located in on windows can be be mounted on the linux host, and then a script or tool can just monitor the log as though it were local?
That will work perfectly. Windows and Unix use different protocol stacks, so you need some software. In the TCP/IP-world there is NFS, which is used to mount remote (parts of) filesystems locally. The respective protocol in NetBIOS (the protocol stack Windows uses) is called SMB.

Either use a NFS server daemon for Windows to export the part with the log files and then NFS-mount it on the Unix system or install a SMB-client on the Unix system to mount the (SMB-)shared Windows drive. Example products for the former would be FreeNFS, an example for the latter would be SAMBA. I am sure there are other similar products for both options too.

I hope this helps.

bakunin
This User Gave Thanks to bakunin For This Post:
# 3  
Old 07-21-2013
Quote:
Originally Posted by bakunin
That will work perfectly. Windows and Unix use different protocol stacks, so you need some software. In the TCP/IP-world there is NFS, which is used to mount remote (parts of) filesystems locally. The respective protocol in NetBIOS (the protocol stack Windows uses) is called SMB.

Either use a NFS server daemon for Windows to export the part with the log files and then NFS-mount it on the Unix system or install a SMB-client on the Unix system to mount the (SMB-)shared Windows drive. Example products for the former would be FreeNFS, an example for the latter would be SAMBA. I am sure there are other similar products for both options too.

I hope this helps.

bakunin
thank you so much. the one problem i foresee with this is, isn't it a bad idea to be reading files off NFS? considering it can cause network issues? I/O?

i remember a while ago reading a data file off NFS. i wondered why it was taking soo long to read the file. but when i moved the data file over from the nfs drive to the local server, the file was read very quickly.

if i'm going mount the windows log files on NFS or anything similar to it, what can i do to make sure i can read the log files just as fast as i would be able to do locally? are there other problems you experts can anticipate?

i presume reading files off NFS wouldn't/shouldn't be an issue on the right hardware. but then the question becomes, what is the right hardware?
# 4  
Old 07-21-2013
Quote:
Originally Posted by SkySmart
thank you so much. the one problem i foresee with this is, isn't it a bad idea to be reading files off NFS? considering it can cause network issues? I/O?

i remember a while ago reading a data file off NFS. i wondered why it was taking soo long to read the file. but when i moved the data file over from the nfs drive to the local server, the file was read very quickly.
Generally said, this is the problem with any complex thing: the more parts it consists of, the more opportunities are there for something to go wrong. Sledge hammers tend to have less operational errors than computers, so to say. ;-))

Of course, when you set up NFS (or any other file sharing system with a similar functionality) you have to make sure the network between the two systems works reliably. Furthermore, you have to make sure the DNS system is responding reliably and quickly, because name resolution is used heavily inside the NFS parts and the longer a single name resolution takes the (preceptibly) slower the observable speed of the file transfer is.

Of course, neither do i know your network nor your systems, so i cannot tell you what went wrong in your case. But my general experience is that misconfiguration and/or sloppy setup is the culprit much more often than failing hardware. To expand on what i said above: suddenly failing NFS mounts can often be traced back to network cards set to the wrong speed (like "100/Full Duplex" instead of "100/Half Duplex" or vice versa), unreliable DNS services, etc., etc.. You can't evade such problems with more hardware set up equally sloppy, only with a better work ethic.

Many problems stem from a tendence to confuse a problem without apparent symptoms with a problem solved: if a problem in some operation takes place and suddenly this problem is gone, you haven't solved it, you have just stopped to see the symptom. The problem is solved only once you understand fully why you do not experience any symptoms any more - not any sooner.

But i am digressing. Generally NFS is a quite reliable method. You should not use it for the distribution of high-security data, because it is prone to network sniffing and it won't support ACLs without some very complicated extra configuration. If you have such data i suggest using sftp, scp, NFS over a securified VPN or something such. Just to distribute logs it is good enough and the provisioning system on the Unix flavour i work most - AIX's NIM - is even bassed on it. IBM wouldn't have done that if it can't be brought to work reliably.

I hope this helps.

bakunin
This User Gave Thanks to bakunin For This Post:
 
Login or Register to Ask a Question

Previous Thread | Next Thread

10 More Discussions You Might Find Interesting

1. Infrastructure Monitoring

How to monitoring windows process using nagios CheckProcState?

Hello, I am trying to get correct syntax to monitoring process running on windows server using CheckProcState. when i am trying below command whether notepad.exe running or not. its showing process running. Could you please provide me correct syantx. /usr/local/nagios/libexec/check_nrpe -H... (0 Replies)
Discussion started by: ghpradeep
0 Replies

2. Shell Programming and Scripting

Script for monitoring logs

hi, i'm using unix solaris 5.8. I have to write a shell script for monitoring logs. whenever the logs are not updated more than one hour an alert will be send to my mail. I'm new to Unix, so could anyone help me to find this. (3 Replies)
Discussion started by: Arasu
3 Replies

3. Shell Programming and Scripting

Perl script to parse multiple windows event logs.

Hi all, I am developing a log parsing agent in perl to send windows Event logs to Zenoss Monitoring tool. Using Win32::EventLog i can able to get the Event messages but only one Eventype eg Application or System could able to parse at a time. Can you please help to how to open mutiple eventlogs... (3 Replies)
Discussion started by: kar_333
3 Replies

4. AIX

How to send AIX logs to windows

good day all how to send aix syslogs to a shared folder in windows regards , (2 Replies)
Discussion started by: thecobra151
2 Replies

5. Windows & DOS: Issues & Discussions

windows server hardware monitoring

:wall:hi all, as hp support pack has hpasm, hpacu command using in linux server to show and monitor hareware status. hpacu command was avaialbe in windows server also, but where can find hpasm command in windows, it looks hp support pack not support hpasm in windows. any one can help? an... (1 Reply)
Discussion started by: maxlee24
1 Replies

6. Shell Programming and Scripting

Logs access in windows fetching the data from a unix server

How I can get the logs that are getting stored in specific location in unix server through an Apache web server installed in unix server? Requirement is to access the logs through the URL in windows browser without any access. (1 Reply)
Discussion started by: alvida
1 Replies

7. UNIX for Advanced & Expert Users

How to view the unix logs in windows ??

Hi ! I have a FTP site, where I softlinked my server log file. Now I want to view the logs in IE as I do in unix Some kind of free tool should be there, Can somebody provide me a pointer. Thanks. (0 Replies)
Discussion started by: dashok.83
0 Replies

8. Windows & DOS: Issues & Discussions

Log monitoring in windows

Hi, I'd like to know if there is a way to monitor a log file conitnuously for one or more strings and if found, send an alarm. It should also take care not to inlcude the old log file entries. Thanks. (2 Replies)
Discussion started by: er_ashu
2 Replies

9. UNIX for Dummies Questions & Answers

Perl Scripting for monitoring logs

Hi, I am new to perl. I want to write a perl script to monitor logs. Where i want to monitor exceptions logged or any kind of error strings. I have a dir(On Solaris) with multiple log file which keeps rolling to .gz file after some time in that same dir. These logs files size keeps on... (1 Reply)
Discussion started by: solitare123
1 Replies

10. UNIX for Dummies Questions & Answers

Unix performance monitoring via Windows/NT

We are trying to Monitor Unix via Window95/98 on an NT network. Is there anyone that could point us in the direction on software that runs in Windows on a Telnet connection that we could use to accomplish this? We have tried a program called Unix Watcher by Etasoft and can' get it to connect. ... (6 Replies)
Discussion started by: btrout
6 Replies
Login or Register to Ask a Question