Re: [logs] CISCO Pix via syslog on Solaris

From: Chris Brenton (cbrenton@private)
Date: Wed Nov 12 2003 - 07:40:36 PST

  • Next message: Alan Sparks: "Re: [logs] Recommendations for a syslog checker"

    On Mon, 2003-11-10 at 19:39, Raffael Marty wrote:
    >
    > I never saw the "[10.0.111.10.2.2]" part before! What is the 2.2 part after the IP and why does the entry not contain the hostname (just like normal syslog entries) instead of the bracket-thing? Is this something specific to Solaris? How can I change that setting?
    
    Not sure about the 2.2 (facility level maybe?) but my guess on the IP is
    that the logging host could not resolve 10.0.111.10. This could be
    because there is no name server entry for this IP, the name server was
    not reachable, etc.
    
    You might want to make a /etc/hosts entry for this IP. This will solve
    the problem as well as save you from having to do NS queries.
    
    HTH,
    C
    
    
    _______________________________________________
    LogAnalysis mailing list
    LogAnalysis@private
    http://lists.shmoo.com/mailman/listinfo/loganalysis
    



    This archive was generated by hypermail 2b30 : Thu Nov 13 2003 - 08:55:51 PST