Skip navigation

Event log Monitoring and consolidation

Event Sentry  
 
Live Demo: Event Sentry Live Demo 
Screenshots: Event Sentry Screenshot Event Sentry Screenshot Event Sentry Screenshot 
Help: Event Sentry Help Event Sentry Help 
Event Sentry Features Event Sentry Print this Page Event Sentry Features 


Syslog Daemon

Syslog Daemon EventSentry includes a built-in syslog daemon that can be used to consolidate log data from any device that supports the syslog protocol. EventSentry's syslog daemon (UDP and TCP are both supported) can be configured to consolidate incoming Syslog messages to the central database and/or log incoming Syslog messages to the Windows Application event log.

The syslog protocol is supported by various Unix/Linux flavors (e.g. Linux©, RedHat©, SUSE©, OpenBSD, NetBSD, FreeBSD, Sun© Solaris©, Apple© OSX 10.x, various Cisco and other high-end network devices).

Syslog To Database

Database Import Icon If you enable the Syslog daemon to log incoming message to a database, then you can conveniently search through all collected Syslog events through the EventSentry web reporting system. You can configure the Syslog To Database feature to either log all incoming Syslog messages (you can define exceptions) to the database, or only log selected messages to the database.

Syslog To Event Log

If you enable the Syslog To Event Log feature then EventSentry will log incoming Syslog messages to the Application event log. You can configure exactly which messages you want to log to the Application event log, and also map the eight Syslog severities to one of the three Windows event log severities. By completely integrating with the Windows event log, incoming Syslog messages can be treated just like any other event log messages and processed with the EventSentry event log filters. For example, you can

  • forward syslog messages to email or any other notification (e.g. pager)
  • apply thresholds, recurring filter settings etc. to Syslog messages
  • ... and much more!

Advanced Settings

The EventSentry Syslog daemon supports the UDP and TCP protocol and supports the following configuration options:

  • Subnets: You can specify which IP addresses or subnets can send Syslog messages to the EventSentry Syslog daemon
  • Thresholds: You can set limits and only accept a certain amount of packages for a given time period.
  • Mapping: You can map syslog severities (e.g. EMERG, NOTICE, etc.) to Windows event log severities (e.g. INFORMATION, WARNING, ERROR etc.)