Windoze > Linux Syslog server
From: KM (martyn_at_n0spam<.)
Date: 06/30/05
- Next message: Dusty Harper {MS}: "Re: Can't talk between VPN'd client and Linux server."
- Previous message: eelco: "bad tcp cksum"
- Next in thread: Michael Heiming: "Re: Windoze > Linux Syslog server"
- Reply: Michael Heiming: "Re: Windoze > Linux Syslog server"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Date: Wed, 29 Jun 2005 23:11:14 +0100
Sorry about mentioning other miscreant OS's in this post, but I am currently
using a Linux Server as central Syslog server.
The question is, how do I filter (from /var/log/messages) out the multitude
of information and authentication messages that I am receiving from the
Windoze boxes?
for example
Jun 29 22:06:31 sirius Security: NT AUTHORITY\SYSTEM: Successful Network
Logon: User Name: SIRIUS$ Domain: CZD Logon ID: (0x0,0x25B039) Logon Type:
3 Logon Process: Kerberos Authentication Package: Kerberos Workstation
Name:
Jun 29 22:06:31 sirius Security: NT AUTHORITY\SYSTEM: Special privileges
assigned to new logon: User Name: Domain: Logon ID: (0x0,0x25B08C)
Assigned: SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege
SeChangeNotifyPrivilege
Jun 29 22:06:31 sirius Security: NT AUTHORITY\SYSTEM: Successful Network
Logon: User Name: SIRIUS$ Domain: CZD Logon ID: (0x0,0x25B08C) Logon Type:
3 Logon Process: Kerberos Authentication Package: Kerberos Workstation
Name:
Jun 29 22:06:31 sirius Security: NT AUTHORITY\SYSTEM: User Logoff: User
Name: SIRIUS$ Domain: CZD Logon ID: (0x0,0x25B08C) Logon Type: 3
Jun 29 22:06:31 sirius Security: NT AUTHORITY\SYSTEM: User Logoff: User
Name: SIRIUS$ Domain: CZD Logon ID: (0x0,0x25AFBA) Logon Type: 3
I would like to ignore these, but they don't (seem) to fall into the usual
Linux logging categories.
OS=FC3
Thanks
Martyn
-- -- KM
- Next message: Dusty Harper {MS}: "Re: Can't talk between VPN'd client and Linux server."
- Previous message: eelco: "bad tcp cksum"
- Next in thread: Michael Heiming: "Re: Windoze > Linux Syslog server"
- Reply: Michael Heiming: "Re: Windoze > Linux Syslog server"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Relevant Pages
|