Hi, In our Data Center , we build a central log analysis system. We use syslog-ng as our central log server . Now about forty web servers, database servers and application servers forward their syslog records to the central log server. Logwatch is used as log analysis software, it analize syslog record it received and send result to the correspondent system administer. We use logwatch's default configuration. What's confusing me now is how to move on . Because logwatch is too simple , it can not find out all the problems ,such as "file system is full ". Can any experienced person give me some advice. Wu Haiyan _______________________________________________ LogAnalysis mailing list LogAnalysisat_private http://lists.shmoo.com/mailman/listinfo/loganalysis
This archive was generated by hypermail 2b30 : Mon Feb 17 2003 - 19:44:16 PST