<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Question about a syslog aggregator in Network and Storage Protocols</title>
    <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Question-about-a-syslog-aggregator/m-p/60081#M5478</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Something I ended up finding out that may be useful to the community in the future.&amp;nbsp; As it turns out, Splunk is free if you log less than 500mb of data per day.&amp;nbsp; In this particular environment that's the case.&amp;nbsp; You do lose multiple logins in the free version, but again that's okay in this particular environment.&amp;nbsp; I'll definitely keep LogZilla in mind though.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 03 Oct 2011 12:44:09 GMT</pubDate>
    <dc:creator>adamgross</dc:creator>
    <dc:date>2011-10-03T12:44:09Z</dc:date>
    <item>
      <title>Question about a syslog aggregator</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Question-about-a-syslog-aggregator/m-p/60046#M5463</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm looking for a solution that would allow me to take syslog output from all of my controllers to an external system.&amp;nbsp; I think I understand what my syslog.conf file needs to look like.&amp;nbsp; Where I'm stumped is picking add-ons or a replacement syslogd that would help with this.&amp;nbsp; In the end I'd like all messages to be logged to /etc/messages, also to the remote system, and then be searchable.&amp;nbsp; Any advice or nudges in the right direction would be greatly appreciated.&amp;nbsp; Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2025 06:52:31 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Question-about-a-syslog-aggregator/m-p/60046#M5463</guid>
      <dc:creator>adamgross</dc:creator>
      <dc:date>2025-06-05T06:52:31Z</dc:date>
    </item>
    <item>
      <title>Question about a syslog aggregator</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Question-about-a-syslog-aggregator/m-p/60052#M5464</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; LogLogic will do this out of the box.&amp;nbsp; Very simple.&amp;nbsp; We are evaluating a LogLogic appliance now.&amp;nbsp; But, we are tring to setup CIFS auditing...not so easy!&amp;nbsp; If anyone can help, or know of a better solution, please, please advise.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 19:21:17 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Question-about-a-syslog-aggregator/m-p/60052#M5464</guid>
      <dc:creator>txskibum2000</dc:creator>
      <dc:date>2011-06-21T19:21:17Z</dc:date>
    </item>
    <item>
      <title>Question about a syslog aggregator</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Question-about-a-syslog-aggregator/m-p/60061#M5467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you set syslog.conf to log locally and remotely?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*.info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /dev/console&lt;/P&gt;&lt;P&gt;*.info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /etc/messages&lt;/P&gt;&lt;P&gt;*.info&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; @hostname&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 19:58:07 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Question-about-a-syslog-aggregator/m-p/60061#M5467</guid>
      <dc:creator>adamgross</dc:creator>
      <dc:date>2011-06-21T19:58:07Z</dc:date>
    </item>
    <item>
      <title>Question about a syslog aggregator</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Question-about-a-syslog-aggregator/m-p/60065#M5469</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; yes...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*.*&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; @ipaddress of our syslog appliance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 20:13:00 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Question-about-a-syslog-aggregator/m-p/60065#M5469</guid>
      <dc:creator>txskibum2000</dc:creator>
      <dc:date>2011-06-21T20:13:00Z</dc:date>
    </item>
    <item>
      <title>Question about a syslog aggregator</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Question-about-a-syslog-aggregator/m-p/60072#M5473</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I took a look at Splunk yesterday and pointed all of my controllers at it...&amp;nbsp; was very easy to setup and appears to do exactly what I'm after.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll check out LogLogic as well after I've played with Splunk for a few days.&amp;nbsp; Thanks for the recommendation txskibum2000.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Jun 2011 12:57:05 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Question-about-a-syslog-aggregator/m-p/60072#M5473</guid>
      <dc:creator>adamgross</dc:creator>
      <dc:date>2011-06-22T12:57:05Z</dc:date>
    </item>
    <item>
      <title>Question about a syslog aggregator</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Question-about-a-syslog-aggregator/m-p/60076#M5475</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We looked at LogLogic and Splunk (as well as several others) but ended up going with LogZilla which was easily 1/10 of the cost of Splunk and *way* less than LogLogic. In the end, we really like the very easy to use interface that logzilla offered versus the othe vendors - heck, even my manager uses it.lol.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There's a really good guide on Cisco's website that talks about syslog management techniques as well as some of the various tools. We found this link a while back and it has really helped us.&lt;/P&gt;&lt;P&gt;Building Scalable Syslog Management Solutions&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/technologies/collateral/tk869/tk769/white_paper_c11-557812.html#wp9000410" target="_blank"&gt;http://www.cisco.com/en/US/technologies/collateral/tk869/tk769/white_paper_c11-557812.html#wp9000410&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Oct 2011 03:03:01 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Question-about-a-syslog-aggregator/m-p/60076#M5475</guid>
      <dc:creator>BOBSIMPSON</dc:creator>
      <dc:date>2011-10-01T03:03:01Z</dc:date>
    </item>
    <item>
      <title>Question about a syslog aggregator</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Question-about-a-syslog-aggregator/m-p/60081#M5478</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Something I ended up finding out that may be useful to the community in the future.&amp;nbsp; As it turns out, Splunk is free if you log less than 500mb of data per day.&amp;nbsp; In this particular environment that's the case.&amp;nbsp; You do lose multiple logins in the free version, but again that's okay in this particular environment.&amp;nbsp; I'll definitely keep LogZilla in mind though.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Oct 2011 12:44:09 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Question-about-a-syslog-aggregator/m-p/60081#M5478</guid>
      <dc:creator>adamgross</dc:creator>
      <dc:date>2011-10-03T12:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: Question about a syslog aggregator</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Question-about-a-syslog-aggregator/m-p/60085#M5480</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;rsyslog (default in Ubuntu) will accept syslog messages and has an addon package what will let you dump the logs to a database for easier searching.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, depending on the size of your infrastructure you may want log servers per location &amp;amp; then have them forward to a central box only if the criticality warrants it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Finally be aware that most of the time this stuff is over UDP so you can't rely on the messages making it off the filer &amp;amp; the data is unencrypted so be aware others can read your logging messages.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jan 2012 14:13:10 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Question-about-a-syslog-aggregator/m-p/60085#M5480</guid>
      <dc:creator>jeremypage</dc:creator>
      <dc:date>2012-01-05T14:13:10Z</dc:date>
    </item>
    <item>
      <title>Re: Question about a syslog aggregator</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Question-about-a-syslog-aggregator/m-p/60089#M5481</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are using&amp;nbsp; EventLog Analyzer from Manage Engine in a Enterprise account&amp;nbsp; ... it's very robust and reliable .... Performs the job very well.......&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jan 2012 19:22:03 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Question-about-a-syslog-aggregator/m-p/60089#M5481</guid>
      <dc:creator>nitish</dc:creator>
      <dc:date>2012-01-05T19:22:03Z</dc:date>
    </item>
  </channel>
</rss>

