ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    SysLog Forwarding for XenServer

    IT Discussion
    rsyslog xenserver logging kibana elk elasticsearch
    10
    110
    24.4k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DustinB3403D
      DustinB3403 @coliver
      last edited by

      @coliver I did.

      I'll run it again though.

      1 Reply Last reply Reply Quote 0
      • DustinB3403D
        DustinB3403
        last edited by

        So still digging into this...

        [root@syslog-cent bin]# ./kibana serve restart
          log   [10:14:12.914] [fatal] Error: listen EADDRINUSE 0.0.0.0:5601
        	at Object.exports._errnoException (util.js:870:11)
        	at exports._exceptionWithHostPort (util.js:893:20)
        	at Server._listen2 (net.js:1236:14)
        	at listen (net.js:1272:10)
        	at net.js:1381:9
        	at nextTickCallbackWith3Args (node.js:448:9)
        	at process._tickDomainCallback (node.js:395:17)
        FATAL { [Error: listen EADDRINUSE 0.0.0.0:5601]
          cause:
           { [Error: listen EADDRINUSE 0.0.0.0:5601]
        	 code: 'EADDRINUSE',
        	 errno: 'EADDRINUSE',
        	 syscall: 'listen',
        	 address: '0.0.0.0',
        	 port: 5601 },
          isOperational: true,
          code: 'EADDRINUSE',
          errno: 'EADDRINUSE',
          syscall: 'listen',
          address: '0.0.0.0',
          port: 5601 }
        
        1 Reply Last reply Reply Quote 0
        • DustinB3403D
          DustinB3403
          last edited by

          We must have to change the kibana.yml file to not listen on the localhost address...

          kibana.yml...

          [root@syslog-cent config]# cat kibana.yml
          server.host: "localhost"
          elasticsearch_url: "http://localhost:9200"
          server.port:5601
          
          1 Reply Last reply Reply Quote 0
          • DustinB3403D
            DustinB3403
            last edited by

            I'm rebooting see if its hung somewhere. As from what I can find online the kibana server is supposedly running twice...

            1 Reply Last reply Reply Quote 0
            • DustinB3403D
              DustinB3403
              last edited by

              Ok so after playing with the timestamp (top right) I do actually have logs, but only from the 12th of the month...

              So maybe it was working, but not showing the logs... now to figure out what the crap is broken....

              1 Reply Last reply Reply Quote 1
              • momurdaM
                momurda
                last edited by

                I donwloaded the Graylog OVA this morning to test it out and put it on my XS pool. Just set Xencenter to forward logs to the Graylog server, seems to work well. Xenserver still making local log entries, but i am ok with that.
                Xenserver sure does like logging messages. 2 hosts making a couple hundred messages/minute, xenstored and xapi are the top ones by far.

                DustinB3403D BRRABillB 2 Replies Last reply Reply Quote 2
                • DustinB3403D
                  DustinB3403 @momurda
                  last edited by

                  @momurda said in SysLog Forwarding for XenServer:

                  I donwloaded the Graylog OVA this morning to test it out and put it on my XS pool. Just set Xencenter to forward logs to the Graylog server, seems to work well. Xenserver still making local log entries, but i am ok with that.
                  Xenserver sure does like logging messages. 2 hosts making a couple hundred messages/minute, xenstored and xapi are the top ones by far.

                  What source are you using?

                  1 Reply Last reply Reply Quote 0
                  • momurdaM
                    momurda
                    last edited by

                    All i did was download and import the ova, then went into Xencenter and forwarded logs on each host to the ip of the graylog server. Here is my sources page
                    0_1471548705190_upload-f2c491d5-e547-43ae-bbe7-1cfaeb259539

                    Here is more sources, basically the whole list. I am still quite overwhelmed with the options and config of graylog, but as i get dashboards setup for things and add more log sources i will post them here as well if you would like.

                    0_1471548847262_upload-5fae783d-0560-4963-b4af-b4000cdc21b3

                    1 Reply Last reply Reply Quote 1
                    • momurdaM
                      momurda
                      last edited by

                      I think it is important to note that the graylog ova is preconfigured to 'just work' according to their site, and it seems to do just that. I will try adding some of my windows vm to this and see what happens later today or tomorrow.

                      BRRABillB 1 Reply Last reply Reply Quote 1
                      • DustinB3403D
                        DustinB3403
                        last edited by

                        For some reason I thought / think there are some pretty big limitations to GrayLog.

                        Maybe I'm wrong.... but I'll take a look at it.

                        1 Reply Last reply Reply Quote 0
                        • DustinB3403D
                          DustinB3403
                          last edited by

                          For anyone curious how to stop any local logging just modify

                          /var/lib/syslog.conf
                          

                          Comment out everything that hits a local path, leaving the @<ip_addr> as the only option.

                          BRRABillB 1 Reply Last reply Reply Quote 1
                          • BRRABillB
                            BRRABill @DustinB3403
                            last edited by

                            @DustinB3403 said in SysLog Forwarding for XenServer:

                            For anyone curious how to stop any local logging just modify

                            /var/lib/syslog.conf
                            

                            Comment out everything that hits a local path, leaving the @<ip_addr> as the only option.

                            Reboot and see if it sticks.

                            It did not for me.

                            DustinB3403D 1 Reply Last reply Reply Quote 0
                            • BRRABillB
                              BRRABill @momurda
                              last edited by

                              @momurda said in SysLog Forwarding for XenServer:

                              I donwloaded the Graylog OVA this morning to test it out and put it on my XS pool.

                              I cannot get it to import onto my XS.

                              Did you just import it in with no issues?

                              BRRABillB momurdaM 2 Replies Last reply Reply Quote 0
                              • DustinB3403D
                                DustinB3403 @BRRABill
                                last edited by

                                @BRRABill said in SysLog Forwarding for XenServer:

                                @DustinB3403 said in SysLog Forwarding for XenServer:

                                For anyone curious how to stop any local logging just modify

                                /var/lib/syslog.conf
                                

                                Comment out everything that hits a local path, leaving the @<ip_addr> as the only option.

                                Reboot and see if it sticks.

                                It did not for me.

                                Will test tomorrow.

                                BRRABillB 1 Reply Last reply Reply Quote 0
                                • BRRABillB
                                  BRRABill @DustinB3403
                                  last edited by

                                  @DustinB3403 said in SysLog Forwarding for XenServer:

                                  @BRRABill said in SysLog Forwarding for XenServer:

                                  @DustinB3403 said in SysLog Forwarding for XenServer:

                                  For anyone curious how to stop any local logging just modify

                                  /var/lib/syslog.conf
                                  

                                  Comment out everything that hits a local path, leaving the @<ip_addr> as the only option.

                                  Reboot and see if it sticks.

                                  It did not for me.

                                  Will test tomorrow.

                                  That was my issue. On reboot it would wipe out the changes I made.

                                  stacksofplatesS 1 Reply Last reply Reply Quote 0
                                  • stacksofplatesS
                                    stacksofplates @BRRABill
                                    last edited by

                                    @BRRABill said in SysLog Forwarding for XenServer:

                                    @DustinB3403 said in SysLog Forwarding for XenServer:

                                    @BRRABill said in SysLog Forwarding for XenServer:

                                    @DustinB3403 said in SysLog Forwarding for XenServer:

                                    For anyone curious how to stop any local logging just modify

                                    /var/lib/syslog.conf
                                    

                                    Comment out everything that hits a local path, leaving the @<ip_addr> as the only option.

                                    Reboot and see if it sticks.

                                    It did not for me.

                                    Will test tomorrow.

                                    That was my issue. On reboot it would wipe out the changes I made.

                                    In a pinch you can do chattr +i on the rsyslog.conf file to make it immutable.

                                    BRRABillB 1 Reply Last reply Reply Quote 0
                                    • BRRABillB
                                      BRRABill @stacksofplates
                                      last edited by

                                      @stacksofplates said in SysLog Forwarding for XenServer:

                                      @BRRABill said in SysLog Forwarding for XenServer:

                                      @DustinB3403 said in SysLog Forwarding for XenServer:

                                      @BRRABill said in SysLog Forwarding for XenServer:

                                      @DustinB3403 said in SysLog Forwarding for XenServer:

                                      For anyone curious how to stop any local logging just modify

                                      /var/lib/syslog.conf
                                      

                                      Comment out everything that hits a local path, leaving the @<ip_addr> as the only option.

                                      Reboot and see if it sticks.

                                      It did not for me.

                                      Will test tomorrow.

                                      That was my issue. On reboot it would wipe out the changes I made.

                                      In a pinch you can do chattr +i on the rsyslog.conf file to make it immutable.

                                      Yeah on the bottom of that article everyone talks about it basically says to change the permission to make it unwritable.

                                      But they call that a QUOTE dirty, dirty tirck UNQUOTE.

                                      1 Reply Last reply Reply Quote 0
                                      • BRRABillB
                                        BRRABill @BRRABill
                                        last edited by

                                        @BRRABill said in SysLog Forwarding for XenServer:

                                        @momurda said in SysLog Forwarding for XenServer:

                                        I donwloaded the Graylog OVA this morning to test it out and put it on my XS pool.

                                        I cannot get it to import onto my XS.

                                        Did you just import it in with no issues?

                                        I tried on my other XS and it worked fine.

                                        Must have been a memory issue on my test one.

                                        1 Reply Last reply Reply Quote 0
                                        • BRRABillB
                                          BRRABill @momurda
                                          last edited by

                                          @momurda said in SysLog Forwarding for XenServer:

                                          I think it is important to note that the graylog ova is preconfigured to 'just work' according to their site, and it seems to do just that. I will try adding some of my windows vm to this and see what happens later today or tomorrow.

                                          Once I had it imported onto my XS, I had it logging in seconds.

                                          Pretty sweet.

                                          If only I was using open source and virtualization years ago!!!!!!

                                          1 Reply Last reply Reply Quote 2
                                          • momurdaM
                                            momurda @BRRABill
                                            last edited by

                                            @BRRABill
                                            Yes, no issues. Didn't even use the fixup disc option. Took a few minutes to start up but it worked right away

                                            BRRABillB 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 5
                                            • 6
                                            • 5 / 6
                                            • First post
                                              Last post