Device Specific syslog Configurations

Last modified 07-May-2003 10:26 PM
Comments to tbird

On this page:

Introduction & organization
The Devices

Apache
BIND v8
Borderware Firewall
Checkpoint FireWall-1
Cisco Catalyst Switches
Cisco IOS
Cisco PIX
HP 3000 MPE
HP JetDirect Printers
IBM SNA
IPSentry
Microsoft Internet Information Services
Microsoft Windows
MiniVend
NcFTPd
Netgear RT314
Netgear FM114P
Novell Netware FTP Server
PostgreSQL
RedHat Linux
sendmail
Solaris
3Com Total Control Routers
WU-FTP
ZyXEL

Introduction & organization

My goal here is to collect client configurations for any device that natively logs to syslog, or can be coerced in that direction. It's a combination of personal tinkering, vendor documentation, postings to the Log Analysis mailing list, and mental telepathy. Please test everything thoroughly before deploying in production. Your mileage may vary. Send corrections and contributions to Tina Bird.

We'll be adding similar guidelines for configuring systems to act as loghosts soon.

We've tried to provide at least three types of information, if they're available: command line configuration, configuration through a GUI, and vendor documentation (configuration notes, if not listed above, and references for messages). Some links will go to outside sources; they'll open in a new browser window. Special idiosyncracies are noted.

The Devices

Apache Web Server

Configuring Apache for syslog
Vendor logging documentation
Message dictionary
HTTP/1.1 Protocol Specification
Vendor Home

BIND v8

Configuring BIND for syslog
Vendor logging documentation
Message dictionary
Vendor Home

Note: What does this "lame server" error mean in my logs?
The message dictionary is probably useful for other versions of BIND.

Borderware Firewall

GUI configuration (see also Borderware Firewall syslog Support)
Vendor logging documentation not available
Message dictionary not available
Vendor Home

Checkpoint FireWall-1

Command line configuration
Another way to get FW-1 logs to syslog
GUI configuration
Vendor logging documentation
Message dictionary
Vendor Home

Cisco Catalyst Switches

Command line configuration
Vendor logging documentation
Message dictionary (for Cat6000 devices; probably generally useful, but YMMV)
Vendor Home

Cisco IOS

Command line configuration
Vendor logging documentation
Logging Call Detail Records on Cisco VOIP
Message dictionary (general IOS)
Message dictionary (IPsec)
Message dictionary (ICMP message types)
Network Monitoring & Event Correlation
Vendor Home

Note: enable logging at the notification level to catch system reboots and configuration changes.

Cisco PIX

Command line configuration
GUI configuration
Vendor logging documentation
Message dictionary
Vendor Home

HP 3000 MPE

Command line configuration
GUI configuration
Vendor logging documentation
Message dictionary
Vendor Home

HP JetDirect Printers

Command line configuration (only available for older HP JetDirect cards)
GUI configuration
Vendor logging documentation (configuration through front panel)
Message dictionary
Vendor Home

IBM SNA

Command line configuration
GUI configuration
Vendor logging documentation
Message dictionary
Vendor Home

Note: who'd've thought that a network protocol would have its own logging configuration?

IPSentry

GUI configuration
Vendor logging documentation
Message dictionary
Vendor Home

Note: IPSentry is a Windows-based system and network monitoring tool. The configuration instructions explain how to configure it to generate syslog alerts when alarm conditions are detected. It presumably logs administrative events to the Windows Event Log, which can then be forwarded to syslog as described here.

Microsoft Internet Information Services (IIS)

Microsoft Windows Operating Systems

MiniVend/Akopia Interchange

Command line configuration
Vendor logging documentation
Message dictionary
Vendor Home

NcFTPd

Command line configuration (for logins, logoffs, and file transfers)
Vendor logging documentation (for errors and significant system events)
Message dictionary (xferlog formats)
Message dictionary (session log formats)
Vendor Home

NetGear RT314

Command line configuration
Vendor logging documentation not available
Message dictionary not available
Vendor Home

NetGear FM114P

Command line configuration
GUI configuration
Vendor logging documentation not available
Message dictionary not available
Vendor Home

Novell Netware FTP Server

Command line configuration
GUI configuration
Vendor logging documentation
Message dictionary
Vendor Home

PostgreSQL

Configuring postgres.conf for centralized logging
GUI configuration
Vendor logging documentation
Message dictionary
Vendor Home

RedHat Linux

sendmail

Command line configuration
Vendor logging documentation
Managing Mail Logging (specific to IBM AIX's sendmail but contains generally useful ideas)
Message dictionary
Vendor Home

Sun Solaris

Configuring /etc/syslog.conf for centralized logging
GUI configuration
Vendor logging documentation
Message dictionary (for Solaris 7; check here for other operating system versions)
Auditing in the Solaris 8 Environment
Solaris BSD Auditing
Vendor Home

3Com Total Control Routers

Command line configuration
GUI configuration
Vendor logging documentation
Message dictionary
Vendor Home

WU-FTP

Command line configuration
Vendor logging documentation
Message dictionary not available
Vendor Home

Note: I'm a bit confused. It used to be that the default build of WU-FTP did not support logging to syslog - that's what the command line documentation above explains. But the current man page says that logging to syslog is enabled by starting ftpd with the -l argument, so re-compiling may no longer be necessary.

ZyXEL

Command line configuration
GUI configuration
Vendor logging documentation
Message dictionary
Vendor Home

Device template

Command line configuration
GUI configuration
Vendor logging documentation
Message dictionary
Vendor Home