Ad Widget

Collapse

Zabbix for syslog?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Carmex
    Junior Member
    • Dec 2018
    • 2

    #1

    Zabbix for syslog?

    Hi,

    I am just getting into Zabbix and think the monitoring stuff is outstanding. Can I use Zabbix to collect and analyze my syslog files? I am interested in getting pretty basic info and analytics. I need to keep account activity logged for compliance. Can Zabbix do this for me?

    Thanks in advance for any/all help.
  • jvillain
    Junior Member
    • Apr 2014
    • 12

    #2
    Yes you can. If you are thinking of using it as a replacement for splunk though I suspect there would be performance issues.

    Comment

    • andris
      Zabbix developer
      • Feb 2012
      • 228

      #3
      Zabbix can monitor log files (including syslog) to report records which match a given regexp, it can extract parts of records, it can count records matching a regexp, it can handle log rotation, it can handle log file storms. See log[], log.count[], logrt[], logrt.count[] items in documentation. In short Zabbix can notify you if something shows up in log files. At the same time it would not be a good idea to stream all log records into Zabbix - it is not designed as a log file warehouse.

      Comment

      • Carmex
        Junior Member
        • Dec 2018
        • 2

        #4
        Originally posted by jvillain
        Yes you can. If you are thinking of using it as a replacement for splunk though I suspect there would be performance issues.

        https://www.zabbix.com/documentation...ypes/log_items
        jvillain andris Sounds like have a bunch of devices sending syslogs to zabbix for archive is not a good idea in general. Do you have a recommendation for a syslog server?

        Comment

        • jvillain
          Junior Member
          • Apr 2014
          • 12

          #5
          If you are OK with a Linux distro then any Linux distro will work for archiving. Just modify rsyslog or syslog-ng and it will listen for connections. Use logrotate to compress them to save space. If you are looking for a cheap replacement for splunk that will parse the logs do a search for "elastic search". None of the options have the gloss of Splunk but Splunk can be crazy expensive.

          Comment

          • gbiondi
            Member
            • Nov 2016
            • 75

            #6
            Hi,
            you can give a look to Graylog..

            Comment

            Working...