VMware
Previous Next
4


The use of a “syslog” server is important in today’s data center.
Most network and SAN switches, along with Unix and Linux servers are
capable of sending logging information to a syslog server. The obvious
reason for a syslog server is to centralize all of your logs. This
enables you to troubleshoot issues more efficiently. Most syslog
servers allow you to do a time-line based analysis of log data so that
you have an enterprise – wide view of all activity. This allows you to
see how different devices interact.

An less obvious reason for a syslog server is for security purposes.
The theory is that an attacker will attempt to elevate to root
privileges and then try to delete or alter logs to hide evidence of the
attack. If all log information is relayed to a syslog server, the hope
is that this data is secured for forensic study, if needed.

Read more…

Tags: syslog, splunk


Jun 1, 2009 9:19 AM MattG

The current VMware app in Splunkbase base requires Java on the Splunk server and is clunky. I am anxiously awaiting an updated version that uses VMware native APIs to pull the data.
-MattG

Jun 1, 2009 11:21 AM dconvery in response to: MattG

Matt -
Thanks for the info. Do you know of any logging server out there that can collect these logs with any efficiency? I know the Java app is clunky, but I didn't find anything that could collect logs via WMI AND plain text logs from Windows. Its a shame there is no sysloggin facility built into Windows.


Dave Convery
VMware vExpert 2009
http://www.dailyhypervisor.com

Careful. We don't want to learn from this.
Bill Watterson, "Calvin and Hobbes"

Jun 1, 2009 11:32 AM MattG in response to: dconvery

Unfortunately, no. I am waiting for the Splunkbase VMware version that uses native VMw APIs. I was led to believe that it was coming some soon, but it is still not here.

-MattG


If you find this information useful, please award points for "correct" or "helpful".

Jul 2, 2009 8:06 AM dconvery in response to: MattG

Matt -
Check out SNARE -> http://www.dailyhypervisor.com/2009/07/02/setting-up-a-splunk-server-to-monitor-a-vmware-environment


Dave Convery
VMware vExpert 2009
http://www.dailyhypervisor.com
http://twitter.com/dconvery

Careful. We don't want to learn from this.
Bill Watterson, "Calvin and Hobbes"

Click to view dconvery's profile Member since: May 10, 2006

vExpert

View dconvery's profile

Communities