Syslog severity in Netsight
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎11-23-2016 06:53 AM
My idea was to create severity alarm based on syslog messages i ECM. But I noticed that all syslog messages are logged and displayed with one severity INFO. Severity is coded in first 3 bits of every syslog message. But ECM is ignoring original severity.
Is there any explanation for such behavior?
Can ECM log syslog messages with original severity?
Thanks for your advices.
Is there any explanation for such behavior?
Can ECM log syslog messages with original severity?
Thanks for your advices.
11 REPLIES 11
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎11-24-2016 11:50 AM
Could you explain where to add/change the line for 2. - I don't get it.
Thanks
Thanks
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎11-24-2016 09:57 AM
Hi Suresh,
I am currently testing on ECM 7.0.4.29
Thanks,
Marius
I am currently testing on ECM 7.0.4.29
Thanks,
Marius
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎11-24-2016 06:48 AM
Hi Marius,
can you let me know what is your netsight version ?
Thanks,
Suresh.B
can you let me know what is your netsight version ?
Thanks,
Suresh.B
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎11-24-2016 06:31 AM
Hello,
i tried to modify rsyslog.conf.
I got severity in 3 first characters of messages in syslog file. But unfortunately ECM doesn't show these messages in SYSLOG events.
ex. of syslog file:
<6>Nov 24 09:14:18 Fima-03 AAA: Login passed for user admin through xml (172.16.69.100)<6>Nov 24 09:14:20 Fima-03 AAA: User admin logout from xml (172.16.69.100)
<4>Nov 24 09:16:09 172.16.69.6 snmp: SNMP Security access violation from 172.16.100.69
i tried to modify rsyslog.conf.
I got severity in 3 first characters of messages in syslog file. But unfortunately ECM doesn't show these messages in SYSLOG events.
ex. of syslog file:
<6>Nov 24 09:14:18 Fima-03 AAA: Login passed for user admin through xml (172.16.69.100)<6>Nov 24 09:14:20 Fima-03 AAA: User admin logout from xml (172.16.69.100)
<4>Nov 24 09:16:09 172.16.69.6 snmp: SNMP Security access violation from 172.16.100.69
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎11-23-2016 08:07 PM
EMC is still showing all messages as severity info even I've some with <3> which should be Error.
<3>Nov 23 21:59:17 172.24.24.101 events: Radar Analysis Engine Security threat [Unauthorized Bridging] detected by AP [AP3935-2], SN [1628Y-1033100000]. Details: state [inactive], location [Home], channel [6], frequency [2437MHz], associated MAC [A4:B1:E9:43:C3:1F], RSS [-85], description [Potential unauthorized AP active - WPS-enabled AP operating in vicinity] 1
<3>Nov 23 21:59:47 172.24.24.101 events: Radar Analysis Engine Security threat [Unauthorized Bridging] detected by AP [AP3935-2], SN [1628Y-1033100000]. Details: state [active], location [Home], channel [6], frequency [2437MHz], associated MAC [A4:B1:E9:43:C3:1F], RSS [-85], description [Potential unauthorized AP active - WPS-enabled AP operating in vicinity] 1
I'm running EMC 7.0.6.27 and also tried it after a ./stopserver & ./startserver
<3>Nov 23 21:59:17 172.24.24.101 events: Radar Analysis Engine Security threat [Unauthorized Bridging] detected by AP [AP3935-2], SN [1628Y-1033100000]. Details: state [inactive], location [Home], channel [6], frequency [2437MHz], associated MAC [A4:B1:E9:43:C3:1F], RSS [-85], description [Potential unauthorized AP active - WPS-enabled AP operating in vicinity] 1
<3>Nov 23 21:59:47 172.24.24.101 events: Radar Analysis Engine Security threat [Unauthorized Bridging] detected by AP [AP3935-2], SN [1628Y-1033100000]. Details: state [active], location [Home], channel [6], frequency [2437MHz], associated MAC [A4:B1:E9:43:C3:1F], RSS [-85], description [Potential unauthorized AP active - WPS-enabled AP operating in vicinity] 1
I'm running EMC 7.0.6.27 and also tried it after a ./stopserver & ./startserver
