VMware Cloud Community
wb2
Contributor
Contributor

remote syslogging

i recently setup a remote syslog server and it has captured about 30k events in about an hour.  Would this be normal?  It seems high to me.  Also, all my events are displaying time that is 5 hours behind.  My hosts are set to EST, but doesn't seem to reflect it in the logs.

0 Kudos
6 Replies
DSTAVERT
Immortal
Immortal

ESXi use UTC time and does not use timzones.

-- David -- VMware Communities Moderator
0 Kudos
DSTAVERT
Immortal
Immortal

You can change the logging level at the ESXi host files directly but you can, (depending on what syslog server you are using) filter the messages.

http://communities.vmware.com/thread/285254 to modify the logging level.

-- David -- VMware Communities Moderator
0 Kudos
wb2
Contributor
Contributor

so that number of logs wouldn't be out of the ordinary then?

0 Kudos
DSTAVERT
Immortal
Immortal

Not particularly but I don't know your system. A simple small mail server can generate millions of lines every day. I would really consider filtering the logs or at least using something to regularly scan and parse the logs for things of interest like error or reset or . . .  and emailing the results to you. There is no point to collecting the logs unless you do something with them.

What syslog server are you using?

-- David -- VMware Communities Moderator
0 Kudos
wb2
Contributor
Contributor

I just started using splunk this past week.  I'm just testing it out.  What syslog servers do you recommend?

0 Kudos
DSTAVERT
Immortal
Immortal

I think Splunk can provide syslog services. Not totally sure. I have used both rsyslog and syslog-ng. They both take a bit of time to understand how to format the filtering rules but once you can it is possible to create very sophisticated filtering of log files. You can write filtered logs to a database. There are agents available for Windows that can also be used to forward Event logs to either as well. Syslog and rsyslog are usually available with any Linux distribution. There are also several Web interfaces for displaying logged data.

I am not familiar with what is available for Windows other than Kiwi syslog. I have used that on occasion

-- David -- VMware Communities Moderator
0 Kudos