Search found 95 matches

by dworthcsl
Wed Apr 27, 2016 11:48 am
Forum: Nagios Log Server
Topic: Logstatsh crashing
Replies: 3
Views: 413

Logstatsh crashing

Hi, We are running NLS version 1.4.0 on RHEL 7.2. We are currently running a 2 node cluster and over the past several weeks I have noticed to that port 5544 is not listening. This past week I created an XI check to monitor the port for both servers. The last restart of the NLS processes was on Monda...
by dworthcsl
Tue Apr 19, 2016 3:05 pm
Forum: Nagios Log Server
Topic: Forward or export data from NLS to another source
Replies: 12
Views: 1425

Re: Forward or export data from NLS to another source

Thanks. I will give it a try. I totally agree with you on the last statement. I intended NLS to be the last stop for logging. However, random initiatives pop up that we are asked to participate in. ;)
by dworthcsl
Mon Apr 18, 2016 1:55 pm
Forum: Nagios Log Server
Topic: Forward or export data from NLS to another source
Replies: 12
Views: 1425

Re: Forward or export data from NLS to another source

We got things working with tcp. They are looking to see if that will work for them. I did try to use syslog as the output. I ran the following on each server to install the plugin ./plugin install logstash-output-syslog Validating logstash-output-syslog Installing logstash-output-syslog Installation...
by dworthcsl
Mon Apr 18, 2016 12:35 pm
Forum: Nagios Log Server
Topic: Forward or export data from NLS to another source
Replies: 12
Views: 1425

Re: Forward or export data from NLS to another source

Cool, thanks. Will that forward all data coming in to another source? Also, what if we wanted to limit it to specific query?

Thanks,
by dworthcsl
Thu Apr 14, 2016 2:32 pm
Forum: Nagios Log Server
Topic: Forward or export data from NLS to another source
Replies: 12
Views: 1425

Re: Forward or export data from NLS to another source

This is what I got back from the people that manage SIEM. There are literally hundreds of protocols accepted by QRadar, I’ve pulled out the few that we use most often. QRadar will accept LEEF or CEF formatted logs using the syslog, TLS syslog, or log file protocols. When we’re using the log file pro...
by dworthcsl
Thu Apr 14, 2016 1:27 pm
Forum: Nagios Log Server
Topic: Forward or export data from NLS to another source
Replies: 12
Views: 1425

Re: Forward or export data from NLS to another source

Thanks, found it. Do you have any documentation or examples that I can look at or use to build a rule? I am new to NLS/ELK.
by dworthcsl
Thu Apr 14, 2016 8:50 am
Forum: Nagios Log Server
Topic: Forward or export data from NLS to another source
Replies: 12
Views: 1425

Re: Forward or export data from NLS to another source

I am still trying to get that information as to the format for SIEM.

How or where do I manage the output in NLS?

Thanks,
by dworthcsl
Wed Apr 13, 2016 2:58 pm
Forum: Nagios Log Server
Topic: Forward or export data from NLS to another source
Replies: 12
Views: 1425

Forward or export data from NLS to another source

Hi, We have an internal initiative to send logs to an outside source that is using IBM SIEM. I have been asked if it is possible to to forward logs from NLS as it comes in and send it to an external source. Is this something that I can do with NLS? If not, is there a way to export log data and send ...
by dworthcsl
Mon Mar 21, 2016 9:33 am
Forum: Nagios XI
Topic: Scheduled Downtime for Services in Hostgroup not working
Replies: 7
Views: 550

Re: Scheduled Downtime for Services in Hostgroup not working

Hi,

I just ran into this as well. Just before a large DR test. :( I was able to get around by disabling notifications for the servers.

I am running 5.2.5 as well.

Regards,
David
by dworthcsl
Fri Mar 11, 2016 1:32 pm
Forum: Nagios Log Server
Topic: Send Oracle xml Audit files to NLS
Replies: 5
Views: 825

Re: Send Oracle xml Audit files to NLS

Thats fine. I will do that now.

Thanks.