Re: [logs] swatchrc file

From: Nate Campi (nateat_private)
Date: Sun Jan 19 2003 - 09:19:41 PST

  • Next message: H C: "RE: [logs] RE: NT Event Log and Web Server Attacks"

    swatch swatch(swatch_5at_private)@Fri, Jan 17, 2003 at 06:49:28PM +0000:
    > 
    > What i want to do is setup 7 swatchrc files.  One swatchrc file for every 
    > logfile.  Is this possible?  If so, do i just name my swatchrc files 
    > swatchrc1 through swatchrc7 and configure each one to look for specific 
    > information depending on what logfile it is pointed at?  For example, if i 
    > have swatchrc1 setup to look in /var/log/kernel and swatchrc2 to look in 
    > /var/log/messages would these be my startup scripts (remember i want to put 
    > these scripts somewhere where they will start automatically should the 
    > server be rebooted).
    
    A more efficient and less error-prone approach is to have a single
    swatch instance watch all your logs by either:
    
    1) having your syslog daemon send all logs to one logfile for this
       purpose 
    
    2) have your syslog daemon send all logs directly into swatch:
       <URL:http://www.campin.net/newlogcheck.html#swatch>
    
    -- 
    Nate Campi  Wired UNIX Operations  TerraLycos DNS Operations
    
    When you say 'I wrote a program that crashed Windows', people just
    stare at you blankly and say 'Hey, I got those with the system, for
    free' 
    
    _______________________________________________
    LogAnalysis mailing list
    LogAnalysisat_private
    http://lists.shmoo.com/mailman/listinfo/loganalysis
    



    This archive was generated by hypermail 2b30 : Mon Jan 20 2003 - 09:35:46 PST