ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    SysLog Forwarding for XenServer

    IT Discussion
    rsyslog xenserver logging kibana elk elasticsearch
    10
    110
    24.4k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • travisdh1T
      travisdh1 @DustinB3403
      last edited by

      @DustinB3403 said in SysLog Forwarding for XenServer:

      @travisdh1 said in SysLog Forwarding for XenServer:

      For my XenServer (still 6.5), I actually started up the XenCenter app. Right click on the server -> properties -> click log destination on left -> click remote on right and enter the rsyslog server ip.

      Which I've done that, but where on the syslog VM would I actually see the logs being created? What should I modify in the /var/lib/syslog.conf file on XenServer?

      By default, everything goes in /var/log/messages. If you want to find things for just one host name

      sudo cat /var/log/messages | grep 'hostname'
      

      I'm now understanding why @scottalanmiller likes binary logs instead of ascii. That messages file grows quickly.

      DustinB3403D 1 Reply Last reply Reply Quote 1
      • DustinB3403D
        DustinB3403 @travisdh1
        last edited by

        @travisdh1 That does show a lot of information, which is scrolling very quickly!

        I guess it works

        1 Reply Last reply Reply Quote 0
        • DustinB3403D
          DustinB3403
          last edited by

          So if that works, then I need to setup a easy way to view these messages..

          Is splunk the go to solution for this?

          BRRABillB 1 Reply Last reply Reply Quote 0
          • BRRABillB
            BRRABill @DustinB3403
            last edited by BRRABill

            @DustinB3403 said in SysLog Forwarding for XenServer:

            So if that works, then I need to setup a easy way to view these messages..

            Is splunk the go to solution for this?

            I used Splunk because it is free and easy. 🙂 (For me.)

            I tried setting up a few other things, and gave up. (Like loggly.) I want to get back to other logging stuff some day, but it works for me.

            1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller
              last edited by

              Splunk is free only for very small sizes. Once your logs grow or you have more than a few servers you normally overrun the free part.

              1 Reply Last reply Reply Quote 1
              • DustinB3403D
                DustinB3403
                last edited by

                So what would be a good aggregation tool to be able to view the logs?

                If Splunk stops at a tiny level..... I won't bother with it.

                BRRABillB 1 Reply Last reply Reply Quote 0
                • BRRABillB
                  BRRABill @DustinB3403
                  last edited by

                  @DustinB3403 said in SysLog Forwarding for XenServer:

                  So what would be a good aggregation tool to be able to view the logs?

                  If Splunk stops at a tiny level..... I won't bother with it.

                  500MB per day.

                  DustinB3403D 1 Reply Last reply Reply Quote 0
                  • DustinB3403D
                    DustinB3403 @BRRABill
                    last edited by

                    @BRRABill said in SysLog Forwarding for XenServer:

                    @DustinB3403 said in SysLog Forwarding for XenServer:

                    So what would be a good aggregation tool to be able to view the logs?

                    If Splunk stops at a tiny level..... I won't bother with it.

                    500MB per day.

                    yeah that's worthless......

                    BRRABillB 2 Replies Last reply Reply Quote 0
                    • BRRABillB
                      BRRABill @DustinB3403
                      last edited by

                      @DustinB3403 said

                      yeah that's worthless......

                      Not for me! 🙂

                      1 Reply Last reply Reply Quote 0
                      • BRRABillB
                        BRRABill @DustinB3403
                        last edited by

                        @DustinB3403 said

                        yeah that's worthless......

                        You'll want to avoid logg.ly before someone recommends it, then. That is 200MB per day.

                        1 Reply Last reply Reply Quote 0
                        • DustinB3403D
                          DustinB3403
                          last edited by

                          So elk/logstash then?

                          Wasn't there a post around here by scott on how to set this up?

                          DanpD 1 Reply Last reply Reply Quote 1
                          • DustinB3403D
                            DustinB3403
                            last edited by

                            Has anyone setup syslog with Elk (with Elasticsearch 2.3 or greater) and Kibana

                            scottalanmillerS 1 Reply Last reply Reply Quote 0
                            • DanpD
                              Danp @DustinB3403
                              last edited by

                              @DustinB3403 Maybe one of these?

                              DustinB3403D 1 Reply Last reply Reply Quote 0
                              • DustinB3403D
                                DustinB3403 @Danp
                                last edited by

                                @Danp said in SysLog Forwarding for XenServer:

                                @DustinB3403 Maybe one of these?

                                I was actually just looking at that and Kibana...

                                I'm trying to determine if I can run it locally or if I need a DO account to do it...

                                1 Reply Last reply Reply Quote 0
                                • scottalanmillerS
                                  scottalanmiller @DustinB3403
                                  last edited by

                                  @DustinB3403 said in SysLog Forwarding for XenServer:

                                  Has anyone setup syslog with Elk (with Elasticsearch 2.3 or greater) and Kibana

                                  I'm pretty sure my walkthrough covers that.

                                  DustinB3403D 1 Reply Last reply Reply Quote 0
                                  • DustinB3403D
                                    DustinB3403 @scottalanmiller
                                    last edited by

                                    @scottalanmiller This one, correct?

                                    scottalanmillerS 1 Reply Last reply Reply Quote 0
                                    • scottalanmillerS
                                      scottalanmiller @DustinB3403
                                      last edited by

                                      @DustinB3403 said in SysLog Forwarding for XenServer:

                                      @scottalanmiller This one, correct?

                                      Yes

                                      1 Reply Last reply Reply Quote 0
                                      • BRRABillB
                                        BRRABill
                                        last edited by

                                        Let me know how it goes. I'd love to install another free server around here.

                                        TAKE THAT MICROSOFT!

                                        1 Reply Last reply Reply Quote 1
                                        • DustinB3403D
                                          DustinB3403
                                          last edited by

                                          I'm getting stuck at

                                            ./load.sh
                                          

                                          with

                                          Loading dashboards to http://localhost:9200 in .kibana
                                          Loading search Cache-transactions:
                                          curl: (7) Failed connect to localhost:9200; Connection timed out
                                          
                                          1 Reply Last reply Reply Quote 0
                                          • DustinB3403D
                                            DustinB3403
                                            last edited by

                                            You know if I wasn't tired I would've noticed that @scottalanmiller made that a bash file.......

                                            1 Reply Last reply Reply Quote 1
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 5
                                            • 6
                                            • 1 / 6
                                            • First post
                                              Last post