04-10-2015
You need to consult your McAfee manual and see if the "facility" is configurable. Usually, you'd choose one of the "user" facility types (local0 - local7) and configure it to use that facility... then you can adjust your syslog conf to take messages for that facility and output to a separate log area.
Alternatively, McAfee may have support for outputting to a local log file outside of using syslog messages, in which case you can configure that.
Syslog really doesn't support the idea of fine grained log selection (which is why SolarWinds and Splunk and such exist).
With that said, as systemd (the borg) takes over everything, logging is going to change in some pretty radical ways... so whatever you do with syslog today, don't get used to it. I promise you it will change if your distribution switches to systemd.
10 More Discussions You Might Find Interesting
1. Solaris
Dear All,
We are going for Disaster Recovery project, the vendor asked for more details about how much is the daily data changes only. using sar / iostat can any one help me to collect this ?!
Note: only I need the changed data size not the daily increasing data. this is to know how much... (1 Reply)
Discussion started by: adel8483
1 Replies
2. Shell Programming and Scripting
I want to connect to one database and collect data from any table using shell script. (0 Replies)
Discussion started by: rinku
0 Replies
3. Shell Programming and Scripting
Hi Friends ,
I am urgently needed your help.
could you pleas help me in creating the shell script.
Requirement :
collect the data from no_file.txt
no_file.txt
============
1
11
265
290
300
313
326
351
Then create another shele script like
my_shell.csh (3 Replies)
Discussion started by: bikas_jena
3 Replies
4. Shell Programming and Scripting
Hi All ,
In my environment we have 12 SAN switches .Culd u pls help me for below queries .
would like to telnet to all switches and collect information in daily basis with "switchstatus" command and store the output under /tmp/ folder on systemA .
To keep passwords of 12switches in a... (1 Reply)
Discussion started by: chinni-script
1 Replies
5. Shell Programming and Scripting
hi all
I am looking for shell script ,by which i need to gather all the DB information in Sybase server .
Thanks in advance :) (3 Replies)
Discussion started by: mvsramarao
3 Replies
6. Shell Programming and Scripting
I have a file current.csv file
2011/05/06 11:12:20 | 16:guest pid=014782 opened Boards 0, 1, 2, 3
2011/05/06 12:23:13 | 16:guest pid=014782 closed
2011/05/06 12:26:05 | 17:guest pid=022383 opened Boards 0, 1, 2, 3
2011/05/06 20:09:04 | 17:guest pid=022383 closed
2011/05/06... (5 Replies)
Discussion started by: sabercats
5 Replies
7. UNIX Desktop Questions & Answers
there are 200 files named file1_0.pdb,file1_60.pdb etc....it looks like:
ATOM 1 N VAL 1 8.897 -21.545 -7.276 1.00 0.00
ATOM 2 H1 VAL 1 9.692 -22.015 -6.868 1.00 0.00
ATOM 3 H2 VAL 1 9.228 -20.766 -7.827 1.00 0.00
ATOM 4 H3 ... (5 Replies)
Discussion started by: kanikasharma
5 Replies
8. Shell Programming and Scripting
I am using AIX 5.3.0.0 ; I need a script to find out each remote AIX boxes
Hostname, Model name and Serial number in following format
Hostname Modelname SerialID
AIXMC01 IBM,7026-B80 IBM,0110BBA1F
AIXMC02 IBM,7026-H50 IBM,0110BBA56
AIXMC03 IBM,7026-H50 IBM,0110BBARR... (12 Replies)
Discussion started by: amir07
12 Replies
9. Shell Programming and Scripting
Hi all,
i have a task to do with Python and because i'm a beginner on it i would like your help on this.
Create a python script that:
Every hour collect the Temperature (e.g. 29C) and Current Condition (e.g. Clear) from this website wunderground.com/global/stations/54511.html
Create a CSV... (0 Replies)
Discussion started by: ragaga123
0 Replies
10. Shell Programming and Scripting
I need to collect last 2 days data from /var/log/messages into a separate file (file format: flmessagetimedaymonth). I have collect today's month, date, time information in separate variable. Please help me in this issue (Probably need awk and grep function).
month=$(date|awk '{print $2}')... (4 Replies)
Discussion started by: makauser
4 Replies
LEARN ABOUT REDHAT
logwatch
LOGWATCH(8) User Manuals LOGWATCH(8)
NAME
logwatch - system log analyzer and reporter
SYNOPSIS
logwatch [--detail level ] [--logfile log-file-group ] [--service service-name ] [--print] [--mailto address ] [--archives] [--range range
] [--debug level ] [--save file-name ] [--logdir directory ] [--hostname hostname ] [--help|--usage]
DESCRIPTION
LogWatch is a customizable, pluggable log-monitoring system. It will go through your logs for a given period of time and make a report in
the areas that you wish with the detail that you wish. Easy to use - works right out of the package on almost all systems.
OPTIONS
--detail level
This is the detail level of the report. level can be high, med, low.
--logfile log-file-group
This will force LogWatch to process only the set of logfiles defined by log-file-group (i.e. messages, xferlog, ...). LogWatch will
therefore process all services that use those logfiles. This option can be specified more than once to specify multiple logfile-
groups.
--service service-name
This will force LogWatch to process only the service specified in service-name (i.e. login, pam, identd, ...). LogWatch will there-
fore also process any log-file-groups necessary to process these services. This option can be specified more than once to specify
multiple services to process. A useful service-name is All which will process all services (and logfile-groups) for which you have
filters installed.
--print
Print the results to stdout (i.e. the screen).
--mailto address
Mail the results to the email address or user specified in address.
--archives
Each log-file-group has basic logfiles (i.e. /var/log/messages) as well as archives (i.e. /var/log/messages.? or /var/log/mes-
sages.?.gz). This option will make LogWatch search through the archives in addition to the regular logfiles. The entries must
still be in the proper date range (see below) to be processed, however.
--range range
You can specify a date-range to process. This option is currently limited to only Yesterday, Today and All.
--debug level
For debugging purposes. level can range from 0 to 100. This will really clutter up your output. You probably don't want to use
this.
--save file-name
Save the output to file-name instead of displaying or mailing it.
--logdir directory
Look in directory for log files instead of the default directory.
--hostname hostname
Use hostname for the reports instead of this system's hostname. In addition, if HostLimit is set in /etc/log.d/logwatch.conf, then
only logs from this hostname will be processed (where appropriate).
--usage
Displays usage information
--help same as --usage.
FILES
/etc/log.d/logwatch.conf
Really a symlink to /etc/log.d/conf/logwatch.conf. This file sets the default values of all the above options. These defaults are
used when LogWatch is called without any parameters (i.e. from cron.daily). The file is well-documented, but the explanations above
also apply to this config file.
/etc/log.d/conf/services/*
Configuration files for the various services whose log entries LogWatch can process.
/etc/log.d/conf/logfiles/*
Configuration files for the various logfiles that the above service's log entries are stored in.
/etc/log.d/scripts/shared/*
Filters common to many services and/or logfiles.
/etc/log.d/scripts/logfiles/*
Filters specific to just particular logfiles.
/etc/log.d/scripts/services/*
Actual filter programs for the various services.
EXAMPLES
logwatch --service ftpd-xferlog --range all --detail high --print --archives
This will print out all FTP transfers that are stored in all current and archived xferlogs.
logwatch --service pam_pwdb --range yesterday --detail high --print
This will print out login information for the previous day...
MORE INFORMATION
For information on adding your own filter, please see the file HOWTO-Make-Filter which should have been included with Logwatch. If you
installed from an RPM, it is probably under /usr/share/doc/logwatch-XXX.
BUGS
The --range option is very weak... this will be fixed in the future.
AUTHOR
Kirk Bauer <kirk@kaybee.org>
http://www.kaybee.org/~kirk
ftp://ftp.kaybee.org/pub/redhat/RPMS
Linux MARCH 1998 LOGWATCH(8)