<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Send cDOT auditlog to remote syslog server in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Send-cDOT-auditlog-to-remote-syslog-server/m-p/122054#M26156</link>
    <description>&lt;P&gt;Latest code release seems to support. ran this on 8.3.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;log-forwarding create -destination HOSTNAME -port 514 -facility local4&lt;/P&gt;</description>
    <pubDate>Fri, 05 Aug 2016 14:06:02 GMT</pubDate>
    <dc:creator>ANDREW_WINEINGER</dc:creator>
    <dc:date>2016-08-05T14:06:02Z</dc:date>
    <item>
      <title>Send cDOT auditlog to remote syslog server</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Send-cDOT-auditlog-to-remote-syslog-server/m-p/26642#M6262</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How do you send the command audit log on Clustered ONTAP to a remote syslog facility?&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;/P&gt;&lt;P&gt;On 7mode, we would perform this by adding the following to /etc/syslog.conf:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cmdsaudit.auditlog&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; @&amp;lt;syslog server IP&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On Cmode I've added our syslog server as an event destination.&amp;nbsp; I believe that I need to add an event route, but I can't seem to be able to find any event message names that pertain to the system auditlog.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 14:22:04 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Send-cDOT-auditlog-to-remote-syslog-server/m-p/26642#M6262</guid>
      <dc:creator>bjones_ea</dc:creator>
      <dc:date>2013-10-28T14:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: Send cDOT auditlog to remote syslog server</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Send-cDOT-auditlog-to-remote-syslog-server/m-p/26647#M6265</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This information is buried in the &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Clustered Data ONTAP®&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt; 8.2 &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;System Administration Guide for Cluster Administrators which is at &lt;/SPAN&gt;&lt;A href="https://library.netapp.com/ecm/ecm_download_file/ECMP1196798" style="color: #1155cc;" target="_blank"&gt;https://library.netapp.com/ecm/ecm_download_file/ECMP1196798&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; font-size: 12.727272033691406px; background-color: #ffffff;"&gt;Starting on page 199 there's a section called "Setting up the Event Management System" and it has information on the "event" branch of the commands and you can, assuming the documentation is right, make a syslog server a destination for the events. You can also use email or snmp traps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; font-size: 12.727272033691406px; background-color: #ffffff;"&gt;I only got ahold of the documentation recently and I don't have a test environment to play with, so I'm trying to be very cautious in implementing this. I have no idea if this is just a wrapper for a typical syslog daemon or if NetApp engineers came up with a completely different technology.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; font-size: 12.727272033691406px; background-color: #ffffff;"&gt;Our reps also told us about this knowledge article if you need information on g&lt;SPAN style="line-height: 1.5em;"&gt;etting access to the logs in the /etc directory in CDOT.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #222222; font-family: arial, sans-serif; font-size: 12.727272033691406px; background-color: #ffffff;"&gt;&lt;A href="https://kb.netapp.com/support/index?page=content&amp;amp;id=1013814" style="color: #1155cc;" target="_blank"&gt;https://kb.netapp.com/support/index?page=content&amp;amp;id=1013814&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are able to get syslog working I'd love to know about it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Phil Jessel, University of Michigan&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-email-small" href="mailto:pjessel@umich.edu" target="_blank"&gt;pjessel@umich.edu&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Jan 2014 13:52:06 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Send-cDOT-auditlog-to-remote-syslog-server/m-p/26647#M6265</guid>
      <dc:creator>UMICHGPCC</dc:creator>
      <dc:date>2014-01-17T13:52:06Z</dc:date>
    </item>
    <item>
      <title>Re: Send cDOT auditlog to remote syslog server</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Send-cDOT-auditlog-to-remote-syslog-server/m-p/26652#M6267</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm curious as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jan 2014 21:16:01 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Send-cDOT-auditlog-to-remote-syslog-server/m-p/26652#M6267</guid>
      <dc:creator>JIM_SURLOW</dc:creator>
      <dc:date>2014-01-20T21:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: Send cDOT auditlog to remote syslog server</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Send-cDOT-auditlog-to-remote-syslog-server/m-p/26656#M6269</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In your example you would run something like this... when using a specific -messagename you comma delimit the severity instead of &amp;lt;=.&amp;nbsp; I did not check if cmdsaudit.auditlog is a cDOT message but assuming it is...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cmode::&amp;gt; event destination create -name syslog -syslog &amp;lt;syslog server IP&amp;gt;&lt;/P&gt;&lt;P&gt;cmode::&amp;gt; event route add-destinations {-severity EMERGENCY,ALERT,CRITICAL,ERROR,WARNING,NOTICE,INFORMATIONAL -messagename cmdsaudit.auditlog} -destinations syslog&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# to get all critical events and lower...&lt;/P&gt;&lt;P&gt;cmode::&amp;gt; event route add-destinations {-severity &amp;lt;=CRITICAL} -destinations syslog&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jan 2014 23:50:53 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Send-cDOT-auditlog-to-remote-syslog-server/m-p/26656#M6269</guid>
      <dc:creator>scottgelb</dc:creator>
      <dc:date>2014-01-20T23:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: Send cDOT auditlog to remote syslog server</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Send-cDOT-auditlog-to-remote-syslog-server/m-p/26661#M6271</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Support is telling me that pulling out of /etc/log/auditlog, can't be done.&amp;nbsp; And of course, /etc/log/mlog/mgwd.log is probably better, but also unavailable via syslog.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jan 2014 00:34:11 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Send-cDOT-auditlog-to-remote-syslog-server/m-p/26661#M6271</guid>
      <dc:creator>JIM_SURLOW</dc:creator>
      <dc:date>2014-01-21T00:34:11Z</dc:date>
    </item>
    <item>
      <title>Re: Send cDOT auditlog to remote syslog server</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Send-cDOT-auditlog-to-remote-syslog-server/m-p/26666#M6273</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;and each node keeps audit logs... I did take some notes and some great advice from support and Justin Parisi a while ago.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One note is that the default is to not log show commands..to enable logging of show commands..changes log but not show.&lt;/P&gt;&lt;P&gt;cmode::&amp;gt; security audit modify -cliset on -httpset on -cliget on -httpget on&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From systemshell we viewed logs...doesn't help get it to syslog but maybe someone has a method to import sftp or scp the files to syslog.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;node% less /mroot/etc/mlog/command-history.log*&lt;/P&gt;&lt;P&gt;node% less /mroot/log/auth.log&lt;/P&gt;&lt;P&gt;node% egrep “console|ssh” /mroot/log/mgwd.log*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jan 2014 00:48:04 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Send-cDOT-auditlog-to-remote-syslog-server/m-p/26666#M6273</guid>
      <dc:creator>scottgelb</dc:creator>
      <dc:date>2014-01-21T00:48:04Z</dc:date>
    </item>
    <item>
      <title>Re: Send cDOT auditlog to remote syslog server</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Send-cDOT-auditlog-to-remote-syslog-server/m-p/90151#M19299</link>
      <description>&lt;P&gt;Here's a script (not mine) to grab the /mroot/etc/mlog/command-history.log* files and send the events to a syslog server:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;A href="http://www.cosonok.com/2014/08/command-history-to-syslog-for-cdot_17.html" target="_blank"&gt;http://www.cosonok.com/2014/08/command-history-to-syslog-for-cdot_17.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;A href="http://www.cosonok.com/2014/08/command-history-to-syslog-for-cdot.html" target="_blank"&gt;http://www.cosonok.com/2014/08/command-history-to-syslog-for-cdot.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's a PowerShell script, but I expect the same methodology could be reimplemented in bash.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It requires that HTTPS access to the log files be enabled per &lt;A href="https://kb.netapp.com/support/index?page=content&amp;amp;id=1013814" target="_blank"&gt;https://kb.netapp.com/support/index?page=content&amp;amp;id=1013814&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Sep 2014 20:02:57 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Send-cDOT-auditlog-to-remote-syslog-server/m-p/90151#M19299</guid>
      <dc:creator>WilliamHorka</dc:creator>
      <dc:date>2014-09-29T20:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: Send cDOT auditlog to remote syslog server</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Send-cDOT-auditlog-to-remote-syslog-server/m-p/99947#M20313</link>
      <description>&lt;P&gt;-messagename cmdsaudit.auditlog&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cmdsaudit.auditlog&amp;nbsp; messagename type doesn't exists on my cluster.....&amp;nbsp;&amp;nbsp; 8.2P6.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any advice?&amp;nbsp; Nothing even looks close.&amp;nbsp; would&amp;nbsp;&amp;nbsp; "-messagename cmds.*"&amp;nbsp; work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.config.checksum&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.config.file&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.config.file.backup&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.config.file.delete&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.config.line.read&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.config.reg.commit1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.config.reg.commit2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.config.reg.commit3&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.config.reg.create1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.config.reg.create2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.config.reg.create3&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.config.reg.file.open&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.config.reg.file.update&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.config.reg.memLimit&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.config.reg.set&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.config.version&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.config.version.minor&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.delete.x509.key&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.delete.x509key.fail&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.fail.regxCommit5&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.ifconfig.all1s.netmask&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.ifconfig.del.autocf&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.ifconfig.ip.rm&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.ifconfig.ip.rm.memAlloc&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.ifconfig.reg.trans.commit&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.ifconfig.reg.trans.create&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.ifconfig.socket.create&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.net.TOE.offload&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.pktt.trace.suspend&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.pktt.write.info&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.pktt.write.issue&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.pktt.write.stop&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.pktt.write.stuck&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.rdate.Time.changed&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.route.addDefault&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.route.addGateway&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.route.invalidHost&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.skbuilt.overflow.check.count&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.software.dirErr&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.software.installDone&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.software.installNotDone&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.sysconf.haltERR1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.sysconf.haltERR2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.sysconf.inconstRule&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.sysconf.logErr&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.sysconf.logInfo&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.sysconf.perCheckOff&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.sysconf.perIntSmall&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.sysconf.syslogger&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.sysconf.validDebug&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.sysconf.wakeDebug&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.unab.create.regTransc4&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.unab.create.regTransc5&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.unable.add.certReg&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.unable.delete.certReg&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.unable.delete.regKey&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.unable.delete.regKey2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.unable.get.valueKey&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.unable.read.regIpsec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.unable.write.regIpsec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.vf.migrate.complete&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.vf.migrate.info&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.vf.trans.migrated&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.vfiler.config.save&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.vfiler.console.switch&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.vfiler.dr.activate&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.vfiler.dr.activated&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.vfiler.dr.configure&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.vfiler.info&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.vfiler.ip.add&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.vfiler.ip.move&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.vfiler.ip.remove&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.vfiler.path.move&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.vfiler.proto.allow&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.vfiler.proto.deny&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.vfiler.replica&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.vfiler.resource.move&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.vfiler.storUnit.add&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.vfiler.storUnit.rm&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmds.ypsetWar&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jan 2015 18:31:01 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Send-cDOT-auditlog-to-remote-syslog-server/m-p/99947#M20313</guid>
      <dc:creator>JoeF</dc:creator>
      <dc:date>2015-01-29T18:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: Send cDOT auditlog to remote syslog server</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Send-cDOT-auditlog-to-remote-syslog-server/m-p/99948#M20314</link>
      <description>&lt;P&gt;Should have waited to hit post....&amp;nbsp; this is what I received back.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;event route add-destinations {-severity EMERGENCY,ALERT,CRITICAL,ERROR,WARNING,NOTICE,INFORMATIONAL -messagename cmds.* } -destinations syslog&lt;BR /&gt;77 entries were acted on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm open to anyone's feedback on how to improve this.&amp;nbsp; I'm trying to ramp up in this area.&amp;nbsp; I can share the perl script we have for grabbing the other logs and sending to our syslog server if someone is interested.&amp;nbsp; That process wasn't pretty on the logrythum side.&amp;nbsp; (thankfully someone else had to do that part)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once I hear back from the logrythum guy on what he's getting I'll update the thread.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jan 2015 18:35:06 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Send-cDOT-auditlog-to-remote-syslog-server/m-p/99948#M20314</guid>
      <dc:creator>JoeF</dc:creator>
      <dc:date>2015-01-29T18:35:06Z</dc:date>
    </item>
    <item>
      <title>Re: Send cDOT auditlog to remote syslog server</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Send-cDOT-auditlog-to-remote-syslog-server/m-p/103982#M21114</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/19915"&gt;@JoeF&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;Should have waited to hit post....&amp;nbsp; this is what I received back.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;event route add-destinations {-severity EMERGENCY,ALERT,CRITICAL,ERROR,WARNING,NOTICE,INFORMATIONAL -messagename cmds.* } -destinations syslog&lt;BR /&gt;77 entries were acted on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm open to anyone's feedback on how to improve this.&amp;nbsp; I'm trying to ramp up in this area.&amp;nbsp; I can share the perl script we have for grabbing the other logs and sending to our syslog server if someone is interested.&amp;nbsp; That process wasn't pretty on the logrythum side.&amp;nbsp; (thankfully someone else had to do that part)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once I hear back from the logrythum guy on what he's getting I'll update the thread.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Joe,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am interested interested in your process and scripts as I am using Logrhythm as well..&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2015 16:30:07 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Send-cDOT-auditlog-to-remote-syslog-server/m-p/103982#M21114</guid>
      <dc:creator>mredondo</dc:creator>
      <dc:date>2015-04-30T16:30:07Z</dc:date>
    </item>
    <item>
      <title>Re: Send cDOT auditlog to remote syslog server</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Send-cDOT-auditlog-to-remote-syslog-server/m-p/114360#M24333</link>
      <description>&lt;P&gt;We are running cdot 8.3 and the previous issue is fixed. you can run the 2 lines below to configure syslog to an external syslog host.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;event destination create -name syslogger -syslog &amp;lt;ip_of_syslog_host&amp;gt;
event route add-destinations -messagename * -destinations syslogger&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;Kris Boeckx&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2016 10:05:26 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Send-cDOT-auditlog-to-remote-syslog-server/m-p/114360#M24333</guid>
      <dc:creator>kris_boeckx</dc:creator>
      <dc:date>2016-01-07T10:05:26Z</dc:date>
    </item>
    <item>
      <title>Re: Send cDOT auditlog to remote syslog server</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Send-cDOT-auditlog-to-remote-syslog-server/m-p/122054#M26156</link>
      <description>&lt;P&gt;Latest code release seems to support. ran this on 8.3.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;log-forwarding create -destination HOSTNAME -port 514 -facility local4&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2016 14:06:02 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Send-cDOT-auditlog-to-remote-syslog-server/m-p/122054#M26156</guid>
      <dc:creator>ANDREW_WINEINGER</dc:creator>
      <dc:date>2016-08-05T14:06:02Z</dc:date>
    </item>
  </channel>
</rss>

