Remote Syslog logging - need help

Hi guys.

Im making my way through the hardening guide and im currently stuck on logging of syslog remote.

Ive updated/etc/syslog.conf to show the following

local6. / Var/log/vmkernel *.*@10.1.1.5 notice

issued esxcfg-firewall - o 514, udp, outside, syslog

and said to syslogd reread the configuration file with kill - SIGHUP 'cat /var/run/syslogd.pid '.

But I'm not logging information of seeeing vmkernel on the source appear in the vmkernel destination host log file using tail-f/var/log/vmkernel

Any ideas guys?

Logging remotely to another ESX makes no sense.

I created a linux VM for purposes of looging and now syslog-ng works very well for me.

---

VMware vExpert 2009

http://blog.vadmin.ru

Tags: VMware

Similar Questions

  • When my computor starts, the screen displays administrator profressionelle of windows xp, I don't remember the password I had used and cannot log - need help

    When my computor starts, the screen displays administrator profressionelle of windows xp, I don't remember the password I had used and cannot log - need help

    The solution is here:

  • Vista x 86 the screen freezes after 20 minutes - captured some logs - need help

    Hi-
    I checked all the settings of power and as the laptop is plugged in (it's a Dell Vostro 1700), I changed all the settings to never Hibernate, never sleep and turned off the screen saver.  I'm not saying the monitor turns off after 45 minutes.

    The screen still freezing occurs, and the only way to get out of it, is a hard reset of the operating system (power button).

    Here are 2 logs system, I found, actually rebooted device itsself so after freezing.
    Log name: System
    Source: iaStor
    Event ID: 9
    Level: error
    Description: The device, \Device\Ide\iaStor0, did not in the expiration time.

    Less than 1 min later that the next system log appeared, shows that he has been forced to restart.

    Log name: System
    Source: USER32
    Event ID: 1074
    Level: information
    Description: The process wininit.exe has inititaed restart the computer, workstation, on behalf of the user for the following reason: no title for this reason could be found.
    Reason code: 0 x 50006
    Comment: The system process 'C:\windows\system32\lsass.exe' ended unexpectedly with status-1073741819 code.  The system will now shut down and restart.

    You can check one thing in your power settings? Are - this you hard drive worth powerdown after 20 minutes? You will find that in the advanced power settings.

  • I need help with an installation failure to interpret and troubleshoot a Setup log.

    Background: A few years ago, many editors of cinema used Final Cut Pro 6 (also contained in Final Cut Studio 2) for their editing projects.  Shared Apple Final Cut X uses a different format that is not compatible with FCP6.  Sometimes, these editors are called to work on a few historical projects that have been published in FCP6 and need this version to run now.

    Starting with OS X Lion, FCP6 would install not in Lion and thereafter.

    According research by Jeremy Johnston as noted on his blog, he discovered that Apple has inserted a file in the folder CoreServices in the Library folder of the system folder that causes versions the version Final Cut Pro X (and other older Apple programs in the same situation) do not settle.  He suggested changes to this file that would seek to prevent interfering with the installation of FCP6 in Lion, many users of final cut PRO 6 were successful in their efforts to install in Lion and work with it.

    Later in a discussion update on installing FCP6 in Mavericks, HawaiianHippie determined that the simplest way to perform the installation of FCP6 was simply copy this file and remove it from the system folder, install FCP6 and then restore the copied file:

    https://discussions.Apple.com/message/26309669#26309669

    I used this method with success to install FCS2 in Yosemite:

    [click on images to enlarge]

    However, in my attempts to install FCS2 in El Capitan, it fails in the last 5% to install the first DVD:

    First of all, I need advice on how to display an extremely large Setup log in this thread (on MacRumors, it is a method to insert a 'code' in a small box that can be the object of a scrollbar if necessary to read all along).  I am unable to find such a method to post here.

    Then once approved, I need help to determine which component is causing the installation to fail and perhaps this element can be omitted from the installation:

    If this element is not required, then maybe FCP6 can be installed successfully without it.  And if that omitted element is necessary, perhaps a manual method to install it can be determined by pacifists.

    It is my goal to help those who need to install and use FCP6 on their new Macs running El Capitan.

    Here is the post on MacRumors with pre-installed Setup log:

    http://forums.MacRumors.com/threads/i-need-help-with-an-installation-failure-to-interpret-and-troubleshoot-an-Installer-log.1954786/#post-22541389

  • Need help with the port forwarding for a XBox remote Streaming

    I have a router R6200v2 and need help with port forwarding.

    I came across this set of instructions for setting up stream port forwarding XBox remotely from anywhere

    http://kinkeadtech.com/2015/07/how-to-stream-Xbox-one-to-Windows-10-from-anywhere-with-Internet/

    I have no idea when it comes to such things and I want to make sure I do it correctly without messing up my existing home network.

    Port Forwarding and triggering Port pages setup look very different from what the guy uses. Can someone walk me through what I do to set up please?

    Hi @varxtis,

    You must enter them in the field for a start external Port and external completion Port. You will need to send individually except for the range of 49000-65000. The steps are as follows.

    1. create a Service name (it could be something else that you cannot use the same service name twice. Ex. XBOX1, XBOX2 and so forth.)

    2. Select the type of service (TCP, UDP or both)

    3 entry 5050 times a start external Port and external endpoints.

    4. Select the IP address of your XBOX.

    5. Select apply.

    6 do the same for other port numbers. To the beach, use 49000 for the external departure Port and for the external completion Port 65000.

    Kind regards

    Dexter

    The community team

  • Need help, trying to decipher my Panel event logs control for security and applications.

    Hi, I need help trying to figure out how to decipher my control panel the security event logs and logs application for account hacking.

    All the advice to learn how to see what who are normal and what is malicious?

    Occurrences of breach possible system, based on very high traffic for the opening of session and closing session and special privilege settings.

    Please notify.

    HP Pavilion DV9700 entertainment

    Windows Vista SP1 Home Premium 32

    I'll leave this thread closed, since I work with other people on another forum on this topic.

  • Need help with following error Message: ERROR of OPENING WET7CABLE. LOG FILE on my Windows XP laptop

    Please need help with an Error Message on my cell phone. The message is as follows: ERROR of OPENING WET7CABLE. LOG FILE

    This message came after running a disk that was provided by Belkin cable easy transfer (FU279) on my old laptop with Windows XP Home Edition you are trying to transfer my files from my old computer laptop w/Win XP on a new computer laptop w/Win 7. This record is for the Windows XP upgrade to Windows 7 and transfer the files.

    I want to thank all in advance for your answers.

    Nelson Santiago

    Hi NELSONSANTIAGO,

    1. when exactly you receive the error message?

    2. is the Belkin easy transfer cable recognized by the Windows XP computer?

    This file may be located on the Belkin Easy Transfer Cable installation disc.

    For more information on how to use or configure the Belkin Easy Transfer cable in Windows XP, see the link below the manual on the Belkin site and check if that helps.

    http://en-UK-support.Belkin.com/app/product/detail/p/4825

  • My set-up agency & ABC developed for us. We no longer use the Agency. I have 2 log-in - but 1) cannot change my billing settings & 2) cannot update models due to lack of access. Need help to change this.

    My set-up agency & ABC developed for us. We no longer use the Agency. I have 2 log-ins - but 1) cannot change my billing settings & 2) cannot update models due to lack of access. Need help to change this.

    Hi Rebecca,.

    You should get in touch with our accounts team to work a solution to your problem. Drop them a note at: contact us | Adobe Business Catalyst

    Cristinel

  • I need help! "An access denied error was returned while attempting to change a service. You may need to log on using an administrator account to perform changes specifice. »

    This is the message I get trying to disable my system startup items Configuration utility. I never had this problem before. I don't have my account and a guest account.

    I need help! Thank you

    A common cause of this is a spyware, Trojan horse or other parasite which means it's time to analyze for all these items. Be sure to include free AVG AntiSpyware in the analysis.

    Then, when you have a clear idea, there are no parasites try TWEAKUI and set the account you want to auto logon.

    Good luck! Please rate me upward if you find my post helpful. Thank you!

  • I need help unlocking my windows 7 welcome screen, my brother did something and I can't log my computer. My name shows and is LOCKED saids and my password does not work

    I need help unlocking my windows7 someone has something of everything lock my computer I donot the password of my computer, please help me

    Restart the machine should solve the problem.

  • Need help to see an alarm for an AP story/event

    I need help to see an alarm last occurred about two months ago, here's the information:

    I had a point to access Cisco 1524 down has a location around the week of April 15.  This access point is in a very remote place and is very rarely used so I did not have to examine the problem until about a month later.  It turns out that the Cat5 cable was damaged in an act of vandalism and the AP returned to the top after I solved the problem of cable.

    An investigation is underway and I wish I could say the detective the exact moment wherever the AP first reported down to the WCS.  I know that the alarm was there as I just never took the time to record the date and time.

    When I go to the alarms it go far enough to see when this happened.  Is - this information stored anywhere so I can pull a report and see the date and time of the AP are down?  I have searched and searched the boat launch of the report, but for the life of me, I can't find this information.

    I have the version 6.0.132.0 of the WCS.

    Thanks for any help that can be provided.

    Bucky

    Bucky,

    WCS logs have a finite number of alarms, they can store. If the event is more listed, then he was in and there is no way to recover this message alarm to see exactly when it was generated.

    Sorry...

    Lee

  • Need help Reparing via USB/burned disc with ISO

    I need help, repair corrupted on my computer files.  I'll explain what are the errors I get and what I have done to try to fix.  Because I feel I have tried everything, I'm thinking to update or repair via a USB port or the drive with an ISO will solve the problem.

    Apparently, everything was going well on my computer until I updated to Windows 8.1.  After I updated, integrated into my laptop keyboard no longer works as well as many other problems of pilot.  I wrote chalk this up to compatibility problems and decided to contact Microsoft Live Help.  Unfortunately, the Microsoft representative could not solve the problem after checking my computer remotely.  They recommended that contact Acer (the manufacturer of my computer).
    After another Office remote access with Acer, they were also able to help me and led me to believe that my computer had been hijacked.  Because the way my computer working fine before the update, I refused the very persistent representative, encouraging me to spend $ 500 to the UN-hijack and install security software, which I already ran.
    1. If my first attempt to solve the problem has been completely re - install Windows 8.  I have reset the factory settings and deleted all the files associated with my computer.  This problem resolved most of the issues I had, including the broken keyboard.  Then I noticed that I was getting errors with Windows Smart Screen Filter and a quick search on this question led me to a few other suggestions.
    2 administrator: command prompt
    sfc/scannow
                                 Full check of 53%. Windows resource protection found corrupt files but was unable to solve some of them. Details are provided in convertible bonds. Journal windir\Logs\CBS\CBS.log. For example C:\Windows\Logs\CBS\CBS.log. Note that logging is not currently supported in offline maintenance scenarios.
    When I tried to open log, "access denied."
    3. I tried using auto repair in the Advanced Boot Options.  Yet once, automatic repair couldn't fix my PC.  I was able to open the log file for this and noted that all of the tests completed successfully, however.
    4. I searched in the Panel > troubleshooting but did not find anything of note.

    5 I also looked a little system information by typing msinfo32 in the command prompt.  Under software environment and looking at the system drivers revealed that about half of them have stopped as the State.

    Objective: At the end of the day, I want to correct all the corrupt system files update to Windows 8.1.  In light of my last experience, I hesitate to do so since he almost broke my computer the last time I did.

    Any help or insight is greatly appreciated.

    Other info: I bought this laptop earlier this year with 8 pre-installed Windows.

    Hello

    ·         You have the Acer recovery disk?

    ·         You have the product key Windows 8?

    ·         What is the brand and model of the Acer?

    Note: I highly recommend back up all your important files and folders on an external storage device before performing any type of repair operating system or upgrade.

    Given that Windows 8 has been pre-installed on your Acer computer. I suggest you to use Acer recovery disk to restore PC to factory settings. For more information, consult the phone manual or contact Acer technical support.

    If you must reinstall Windows 8 or you want to install it on one partition and you do not have installation media, you can create it using the installer of Windows 8. To create a support, that you must use a PC running Windows 8.1, Windows 8, or Windows 7, and it must have the same architecture (32 or 64-bit) that you want to install Windows 8 on PC. You will also need your product key of Windows 8.

    Note: If you do not have a product key for Windows 8, you cannot create the installation media. You cannot use a product key of Windows 8 for this.

     

    Create an installation media for Windows 8

    http://Windows.Microsoft.com/en-in/Windows-8/create-reset-refresh-media

    I hope this helps. If you need help with Windows, let us know and will be happy to help you.

  • Need help to diagnose the regular system analysis on iMac - processors maxed out

    I need help to identify the cause of a problem that occurs at least 2 - 3 times per day using my iMac (27-inch, mid 2010) running 10.11.5.

    I will use my iMac and then all at once things will start to really trolling. To the point of being completely unusable. Even if I'm able to move my cursor, then click to drag the windows around the screen nothing does really.

    I have iStat menus running so that can see graphics in my menu bar that all 4 cores are completely overfished. Occasionally, I was fast enough to launch the activity monitor to try to see what applications / services are responsible for, the use of % CPU column is completely empty of values, so I can't identify the culprits in a reliable way. I try to keep that column sorted by % CPU use in the hope that he could reveal something and normally it's the kernel_task who is up there.

    I use a Wacom Bamboo dated Tablet (MTE - 450 has) instead of a mouse, and at one point, I was convinced the pilot of PenTabletDrive it is based on was to blame. I contacted Wacom on this subject, and although there is no known issues they pointed out that although the latest drivers will allow me to use the tablet that they no longer support older devices. I was wondering if there was a problem of communication between the device and a driver that is no longer supported. I installed the latest driver supported for my tablet, but the problems persist.

    It may be interesting to note that, when my computer is in this semi-frozen state, I am able to launch the window enough force and quit all open applications leaving me with only the Finder. I guess that means that there are none of my apps running and it is probably one of the services. If I restart the Finder system grinds to a completely enclosed holt.

    I hope someone can let me know what I can find in the Console or elsewhere to help me finally zero in on what is to blame. I can share a log if that helps.

    Thank you in advance!

    Information that might be useful:

    Kept by I tend to be running: Adobe InDesign, Photoshop, Acrobat (all CC 2015), Mail, Safari with several tabs & Dropbox sync constantly.

    Download and run EtreCheck, created by one of his own assistants here in CSA. It is a diagnostic tool that is very useful for us to find problems. It will also give us additional specifications on your Mac. After his execution after the logfile here. It will never contain any personal information.

  • wnr2000v4 has stopped working. I need help tech for Dummies

    router just stopped yesterday. tried every thing under the Sun for 10 hours. overwhelmed by the info. I just want to know

    If ineed a nine (which I can't afford right now) I don't have a desk top. only a laptop. When I plug it into the router

    I have internet. Help, please! When I try to connect to the network with password it tells me that things have changed please

    opening of session. I connect and it says the same thing. I need help technology for Dummies!

    The power supply light is orange since we bought it. No I can't connect in the router. Yes, I've been connected with the Ethernet cable. Yes cable connection worked my operating system is windows 10. What the heckl is Syslog? Yes, I have reset several times. I spent so much time trying to figure out if he actually die. Somewhere on the site of netgear line he says the actual words "end of life". I went and bought a new router.

    Thanks to all who tried to help. It was very appreciated

  • D010wm Stream 11 HP: I have NEED HELP!

    I really need help. I have problems with my laptop, I have 6 crash logs, one with a driver Realtek as the culprit, A corrupt Partition Recovery (cooling system and Reset) and blocks of black screen on wake up. I can't understand what is wrong with it. I have 8.1 with Bing 64-bit win

    Edit: Before you go here for this post, I had to stop the laptop because it would not click and couldn't 'see' my Sd Card.

    6 accidents are 5 pass run out of memory noexicute, and 1 is a driver irql not less or equal

    Hello

    Looks like you may need to use recovery media to recover your PC. If you have created your own recovery discs, you can try to contact HP support on obtaining recovery media - https://support.hp.com/us-en/contact-hp/product/HP-Stream-11-d000-Notebook-PC/7372144/model/7563443#Z7_3054ICK0KGTE30AQO5O3KA30F3

Maybe you are looking for