02-18-2008 02:29 PM - edited 03-11-2019 05:04 AM
We have a server on an inside interface and need to log anything related to its TCP connections (build, teardown, etc.) to a syslog server.
I see how to do it by class, by message id, even by customer message list. However, I don't see where we can do this given a specific local ip address.
Ideas?
Thanks!
Solved! Go to Solution.
02-18-2008 04:28 PM
You can set up a rule in the syslog server to log anything with the IP adderss and TCP as keywords in the message ID and log it to a file (or whatever rule you want to assign it). Not sure which syslog server you're using, but I know you could do it with Kiwi.
02-18-2008 04:28 PM
You can set up a rule in the syslog server to log anything with the IP adderss and TCP as keywords in the message ID and log it to a file (or whatever rule you want to assign it). Not sure which syslog server you're using, but I know you could do it with Kiwi.
02-20-2008 07:19 AM
That's a great idea. Although I wasn't able to find out how to filter the data in Kiwi, I was able to highlight certain messages.
Although I was receiving more data than I could view in real-time, I was able to search the log files for what I was looking for.
Can you think of a syslog server that will allow me to filter and store only data I want? I wasn't able to do this with Kiwi.
Thanks!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide