Syslog


SapphireIMS supports collection of Syslog messages from any device. These include Linux systems as well as other devices. This topic describes the Syslog Viewer, to view the dashboard for analysis and view the summary and raw data.

A Syslog message is based on RFC 3164 standards. Given below are the various fields in the logs.

Serial No

Information

Description

1

Facility Code

Indicates the type of program logging the even. Examples are 'kern' (Kernel, 'user' (User) etc.

2

Severity Level

Specifies the Severity of the message, for example, 'Alert', 'Critical', 'Informational' etc.

 3

Program

The actual program which generates the event, for example, 'crond' or 'sshd'.

4

Log Source

The client from which the logs are being collected.

Note.gifNote: In the case of a forwarder or relay being used, the Log Source field will have the host name of the forwarder and not the originator of the log message.

5

Message

The text contained in the message.

6

Host Name

The Host Name or IP address of the client which originated the log message.

7

Timestamp

The time at which the log event was generated

 

Note.gifNote: The devices need to have Syslog enabled and the configuration set to forward Syslog messages to SapphireIMS.

 

Viewing the Dashboard

 

Fault-SysLog-Dashboard.jpg

 

 

Fault-EvntLog-SaveProfile.jpg

Fault-SysLog-FilterSelect.jpg

 

Summary View

The Events can be displayed in a tabular form in the Summary view where the count of the events can be aggregated in various ways.

 

Fault-SysLog-Summary.jpg

Fault-SysLog-SummaryProfile.jpg

 

 

Raw Data

The Raw Data for the Event Log can also be viewed as a listing.

Fault-SysLog-RawData.jpg

Fault-SysLog-RawDataProfile.jpg

 

Setting up Analysis Filters

Fault-EvntLog-AnalyzeFilter.jpg

 

Changing the Refresh Interval

 

Fault-EvntLog-RfrshEntry.jpg

 

Saving Views and Reports as a PDF file

Fault-EvntLog-PDF-1.jpg

Fault-EvntLog-PDF-2.jpg

 

Exporting Views and Reports to an Excel file