Re: [logs] swatchrc file

From: Nate Campi (nateat_private)
Date: Sun Jan 19 2003 - 09:19:41 PST

  • Next message: H C: "RE: [logs] RE: NT Event Log and Web Server Attacks"

    swatch swatch(swatch_5at_private)@Fri, Jan 17, 2003 at 06:49:28PM +0000:
    > What i want to do is setup 7 swatchrc files.  One swatchrc file for every 
    > logfile.  Is this possible?  If so, do i just name my swatchrc files 
    > swatchrc1 through swatchrc7 and configure each one to look for specific 
    > information depending on what logfile it is pointed at?  For example, if i 
    > have swatchrc1 setup to look in /var/log/kernel and swatchrc2 to look in 
    > /var/log/messages would these be my startup scripts (remember i want to put 
    > these scripts somewhere where they will start automatically should the 
    > server be rebooted).
    A more efficient and less error-prone approach is to have a single
    swatch instance watch all your logs by either:
    1) having your syslog daemon send all logs to one logfile for this
    2) have your syslog daemon send all logs directly into swatch:
    Nate Campi  Wired UNIX Operations  TerraLycos DNS Operations
    When you say 'I wrote a program that crashed Windows', people just
    stare at you blankly and say 'Hey, I got those with the system, for
    LogAnalysis mailing list

    This archive was generated by hypermail 2b30 : Mon Jan 20 2003 - 09:35:46 PST