ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    SysLog Forwarding for XenServer

    Scheduled Pinned Locked Moved IT Discussion
    rsyslogxenserverloggingkibanaelkelasticsearch
    110 Posts 10 Posters 24.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DustinB3403D
      DustinB3403
      last edited by

      And I'm in.

      Now to setup XenServer to send stuff to Kibana.

      1 Reply Last reply Reply Quote 0
      • DustinB3403D
        DustinB3403
        last edited by

        OK So I'm in, and apparently logs are getting sent to this VM.... now how do I see them... lol....

        So much to learn...

        StrongBadS 1 Reply Last reply Reply Quote 0
        • StrongBadS
          StrongBad @DustinB3403
          last edited by

          @DustinB3403 said in SysLog Forwarding for XenServer:

          OK So I'm in, and apparently logs are getting sent to this VM.... now how do I see them... lol....

          So much to learn...

          Have you looked in Kibana yet?

          DustinB3403D 1 Reply Last reply Reply Quote 0
          • DustinB3403D
            DustinB3403 @StrongBad
            last edited by

            @StrongBad Yes, and nothing is showing up.

            So there might be something I messed up while configuring it, or there just isn't anything set to show yet.

            1 Reply Last reply Reply Quote 0
            • StrongBadS
              StrongBad
              last edited by

              They show up quickly. We're the logs pretty regular before the change?

              DustinB3403D 1 Reply Last reply Reply Quote 1
              • StrongBadS
                StrongBad
                last edited by

                LMFAO. Regular. Logs.

                1 Reply Last reply Reply Quote 1
                • DustinB3403D
                  DustinB3403 @StrongBad
                  last edited by

                  @StrongBad said in SysLog Forwarding for XenServer:

                  They show up quickly. We're the logs pretty regular before the change?

                  With just a basic syslog server setup and forwarding enabled when I viewed /var/log/messages it was blowing by

                  1 Reply Last reply Reply Quote 0
                  • DustinB3403D
                    DustinB3403
                    last edited by

                    0_1471021829374_chrome_2016-08-12_13-10-17.png

                    1 Reply Last reply Reply Quote 0
                    • DustinB3403D
                      DustinB3403
                      last edited by

                      0_1471021953539_chrome_2016-08-12_13-12-17.png

                      1 Reply Last reply Reply Quote 0
                      • DustinB3403D
                        DustinB3403
                        last edited by

                        I still have a few compressed logs (things that aren't marked to be forward to Elk/Kibana)

                        1 Reply Last reply Reply Quote 0
                        • DustinB3403D
                          DustinB3403
                          last edited by

                          0_1471022072411_XenCenterMain_2016-08-12_13-14-25.png

                          Obviously I'll need to change the syslog file to make sure those are only sent off host.

                          But why aren't they appearing in Elk/Kibana...

                          1 Reply Last reply Reply Quote 0
                          • DustinB3403D
                            DustinB3403
                            last edited by

                            Everything here seems happy.

                            0_1471022151987_chrome_2016-08-12_13-15-37.png

                            1 Reply Last reply Reply Quote 1
                            • DustinB3403D
                              DustinB3403
                              last edited by

                              I still don't know why the logging isn't showing up in Kibana. . .

                              scottalanmillerS 1 Reply Last reply Reply Quote 0
                              • scottalanmillerS
                                scottalanmiller @DustinB3403
                                last edited by

                                @DustinB3403 said in SysLog Forwarding for XenServer:

                                I still don't know why the logging isn't showing up in Kibana. . .

                                What do the local logs say? On both ends. There should be Logstash logs saying what has happened.

                                DustinB3403D 1 Reply Last reply Reply Quote 0
                                • DustinB3403D
                                  DustinB3403 @scottalanmiller
                                  last edited by

                                  @scottalanmiller said in SysLog Forwarding for XenServer:

                                  @DustinB3403 said in SysLog Forwarding for XenServer:

                                  I still don't know why the logging isn't showing up in Kibana. . .

                                  What do the local logs say? On both ends. There should be Logstash logs saying what has happened.

                                  I'm still new to syslog, so what should I be looking at to answer this question?

                                  1 Reply Last reply Reply Quote 0
                                  • stacksofplatesS
                                    stacksofplates
                                    last edited by stacksofplates

                                    You could just use Graylog. It uses rsyslog instead of file-beat (which doesn't work with journalctl anyway).

                                    1 Reply Last reply Reply Quote 0
                                    • DustinB3403D
                                      DustinB3403
                                      last edited by

                                      Since I'm having a hell of time getting this going, I setup a KiwI Syslog on a VM from one of my host, and it just works.

                                      Just enabling the logging to the IP address, and let it go.

                                      scottalanmillerS 1 Reply Last reply Reply Quote 0
                                      • scottalanmillerS
                                        scottalanmiller @DustinB3403
                                        last edited by

                                        @DustinB3403 said in SysLog Forwarding for XenServer:

                                        Since I'm having a hell of time getting this going, I setup a KiwI Syslog on a VM from one of my host, and it just works.

                                        Just enabling the logging to the IP address, and let it go.

                                        Instead of posting the logs to diagnose?

                                        DustinB3403D 1 Reply Last reply Reply Quote 0
                                        • DustinB3403D
                                          DustinB3403 @scottalanmiller
                                          last edited by

                                          @scottalanmiller Again, where do I look for them....

                                          BRRABillB scottalanmillerS 2 Replies Last reply Reply Quote 0
                                          • BRRABillB
                                            BRRABill @DustinB3403
                                            last edited by

                                            @DustinB3403 said in SysLog Forwarding for XenServer:

                                            @scottalanmiller Again, where do I look for them....

                                            Check the logs.

                                            (Boy I am glad I am not withing physical reach of you! 😉 )

                                            1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 5
                                            • 6
                                            • 4 / 6
                                            • First post
                                              Last post