SUSE Linux is a major operating system. The developer rights are owned by Novell, Inc.

How to filter SYSLOG data to collect meaningful information only?

👤 Login to reply

Old 04-03-2015
JDBA JDBA is offline
Registered User
Join Date: Apr 2014
Last Activity: 10 June 2015, 8:44 AM EDT
Location: College Park, MD
Posts: 20
Thanks: 2
Thanked 0 Times in 0 Posts
How to filter SYSLOG data to collect meaningful information only?

Dear users,

SUSE 10 sp3 and SUSE 11.

I made configuration changes in '/etc/syslog-ng/syslog-ng.conf'
to move SYSLOG content to LogRhythm.

This is what I changed in the file.
Un-comment out the following lines
#Enable this and admop IP to send log messages to a log server
Destination logserver – Enter in syslog server ip address
log {source(src)
destination allmessages

Now, logs are being generated and transferred to LogRhythm. But the problem is too much log information is being generated and it's filling up our Logrhythm quickly, 30% in a week. We'd like to reduce log generated in SYSLOG by collecting only useful information which describe below.

The log information we'd like to capture is below.

what file should I edit and what changes should I make in that file? Is there any document or procedure posted on the web?

Always appreciate your support.

- Successful login and logoff attempts
- Unsuccessful login and authorization attempts
- All identification and authentication attempts
- All actions, connections and requests performed by privileged users
- All changes to logical access control authorities (e.g., rights, permissions
- System changes with the potential to compromise the integrity of audit -policy configurations, security policy configurations and audit record generation services.
- Creation, modification and deletion of objects including files, directories and user accounts
- Creation, modification and deletion of user accounts and group accounts
- Creation, modification and deletion of user account and group account privileges
- The date of the system event; ii)the time of the system event; iii) the type of system event initiated; and iv) the user account, system account, service or process responsible for initiating the system event.

- System start-up and shutdown functions.
- Modifications to administrator account(s) and administrator group
account(s)including: i) escalation of user account privileges
commensurate with administrator-equivalent account(s); and ii) adding or
deleting users from the administrator group account(s).

enabling or disabling of audit report generation services

-command line changes, batch file changes and queries made to the system (e.g., operating system, application, and database).
Sponsored Links
Old 04-03-2015
fpmurphy's Unix or Linux Image
fpmurphy fpmurphy is offline
Registered User
Join Date: Dec 2003
Last Activity: 12 June 2016, 11:03 PM EDT
Location: /dev/ph
Posts: 4,996
Thanks: 73
Thanked 476 Times in 438 Posts
I would continue to send all logging data to your logging server and use a tool like Solarwinds LEM (Log and Event Manager) to produce the reports and eventing output you looking for.
Sponsored Links
Old 04-06-2015
JDBA JDBA is offline
Registered User
Join Date: Apr 2014
Last Activity: 10 June 2015, 8:44 AM EDT
Location: College Park, MD
Posts: 20
Thanks: 2
Thanked 0 Times in 0 Posts
Flitering SYSLOG

is there a way to control producing or generating SYSLOG data?

I'd like SYSLOG to generate only certain data such as update, delete, logon etc.

We have LogRhythm and it doesn't want to store all SYSLOG data generated.

Old 04-10-2015
JDBA JDBA is offline
Registered User
Join Date: Apr 2014
Last Activity: 10 June 2015, 8:44 AM EDT
Location: College Park, MD
Posts: 20
Thanks: 2
Thanked 0 Times in 0 Posts
Filter unnessary log through syslog-ng.conf file

The SYSLOG file '/var/log/messages/' generates so many lines of Mcafee scan results.

I'd like to get rid of these lines.

The log lines start with 'nails-ddds' and end with 'cmd=update'.

What command do I add in '/etc/syslog-ng/syslog-ng.conf' file to get rid of these log information?

Thank you,
Sponsored Links
Old 04-10-2015
cjcox cjcox is offline
Registered User
Join Date: May 2005
Last Activity: 27 June 2016, 2:12 PM EDT
Posts: 614
Thanks: 4
Thanked 110 Times in 107 Posts
You need to consult your McAfee manual and see if the "facility" is configurable. Usually, you'd choose one of the "user" facility types (local0 - local7) and configure it to use that facility... then you can adjust your syslog conf to take messages for that facility and output to a separate log area.

Alternatively, McAfee may have support for outputting to a local log file outside of using syslog messages, in which case you can configure that.

Syslog really doesn't support the idea of fine grained log selection (which is why SolarWinds and Splunk and such exist).

With that said, as systemd (the borg) takes over everything, logging is going to change in some pretty radical ways... so whatever you do with syslog today, don't get used to it. I promise you it will change if your distribution switches to systemd.
Sponsored Links
Old 04-10-2015
Corona688 Corona688 is offline Forum Staff  
Mead Rotor
Join Date: Aug 2005
Last Activity: 20 July 2018, 3:26 PM EDT
Location: Saskatchewan
Posts: 22,727
Thanks: 1,194
Thanked 4,351 Times in 4,006 Posts
You never know what you'll want from your logfiles until you do, so I wouldn't try being too incredibly specific except for separating mcaffee results from everything else interesting.
Sponsored Links
Old 04-13-2015
rbatte1 rbatte1 is offline Forum Staff  
Root armed
Join Date: Jun 2007
Last Activity: 20 July 2018, 11:57 AM EDT
Location: Lancashire, UK
Posts: 3,588
Thanks: 1,594
Thanked 706 Times in 633 Posts
I would go for collecting everything and then extracting what you actually need when you need it. It leaves masses of records never read, but there is no way to say to the server, "Hey, just go back in time, replay a process that I don't know quite when it happened and show me the logging now."

We have load and load & LOADS of output that is never looked at unless there is a problem and we rotate the logs out and away at sensible intervals to keep on top of it. if we don't need most of it in a week (production batch messages) then they are sent to tape and never seen again.

Sponsored Links
👤 Login to reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
shell script to collect information from current and remote unix boxes amir07 Shell Programming and Scripting 12 02-07-2012 10:54 AM
collect data from files kanikasharma UNIX Desktop Questions & Answers 5 11-11-2011 03:13 AM
script to collect all db information mvsramarao Shell Programming and Scripting 3 10-30-2009 12:46 AM
Collect information from switches chinni-script Shell Programming and Scripting 1 04-03-2009 08:20 PM
Planning for DR, I have to collect information adel8483 Solaris 1 03-26-2007 07:45 AM

All times are GMT -4. The time now is 01:23 PM.

Unix & Linux Forums Content Copyright©1993-2018. All Rights Reserved.
Show Password

Not a Forum Member?
Forgot Password?