Ad Widget

Collapse

Can zabbiz work as a syslog to ease reporting/monitoring of logs?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • James Wells
    Senior Member
    • Jun 2005
    • 664

    #16
    Originally posted by transitv
    Hmm, this sounds like it contradicts your earlier reply. To clarify, are you saying that if I just want to use zabbix (in addition to monitoring servers) to act as a syslog "storage" and viewing/reporting device that it won't work as well as php-syslog-ng (and syslog-ng)?
    I missed that. Sorry. Yes, at present, Zabbix is not as good, but that is almost exclusively a function of the UI. I looked at the code for PHPSyslog-NG and the code is pretty basic stuff. Shouldn't be difficult to integrate it with Zabbix, or at least on a host / item basis. Enabling the multi-host functionality, however, will take a bit more work, but should be fairly easy as well.

    EDIT: BTW, that was not meant to be a forward, backward, sideways, whatever slap. The code is clean and well written, it is simply that it is implementing a simple DB query and formatting the output.
    Last edited by James Wells; 19-03-2007, 22:31.
    Unofficial Zabbix Developer

    Comment

    • transitv
      Junior Member
      • Dec 2006
      • 22

      #17
      Cool, perhaps once 1.4 is out we can get with Alexei and see about the logistics of making these additions. I'd be happy to help (when time permits), but we should start with a full discussion of how it will all work and if it's even worth the trouble...

      Comment

      • Alexei
        Founder, CEO
        Zabbix Certified Trainer
        Zabbix Certified SpecialistZabbix Certified Professional
        • Sep 2004
        • 5654

        #18
        I agree. It could very very nice addition to ZABBIX!
        Alexei Vladishev
        Creator of Zabbix, Product manager
        New York | Tokyo | Riga
        My Twitter

        Comment

        • tronite
          Senior Member
          • Jun 2007
          • 147

          #19
          Originally posted by James Wells
          Greetings,

          Yes and no. By default Zabbix is unable to properly track changes to a syslog style log file. The reason for this is that the Agent doesn't know how to process the time format correctly. However, I have been asked by a couple of people at work to fix this, so unless Alexei fixes it soon, I will be doing so in my bulk patches. Once this is done, you will have not only the features that php-syslog-ng provides, but also, but also the features of swatch and some of the features of splunck and spelunk.

          I should point out that Zabbix can support log4j, log4s, and apache style log files.
          Seems like you make a habit of saying yes and no.

          Comment

          • toppi
            Junior Member
            • May 2010
            • 1

            #20
            It must be useful to incorporate a syslog server into Zabbix. Is there any solution in Zabbix 1.8.* version?

            Comment

            • Logicwrath
              Junior Member
              • Feb 2007
              • 27

              #21
              I would love to see some integration into zabbix. I think until something like that exists the open source program LogAnalyzer looks promising. I would want the ability to create alerts.

                View system messages via web Syslog messages Windows Events Status Reports Statistics Web based   LogAnalyzer is part of Adiscon’s MonitorWare line of monitoring applications. It runs both under Windows and Unix/Linux. The database can be populated by MonitorWare Agent, WinSyslog or EventReporter on the Windows side and by rsyslog on the Unix/Linux side. … Continue reading "Home"


              I am considering using it myself.

              Things I would LOVE include:

              splunk style co-relation... yea baby
              triggers

              Comment

              • obeiro
                Junior Member
                Zabbix Certified Specialist
                • Sep 2010
                • 7

                #22
                I would love some syslog integration too.

                Meanwhile LogZilla is my workaround

                Comment

                • zalex_ua
                  Senior Member
                  Zabbix Certified Trainer
                  Zabbix Certified SpecialistZabbix Certified Professional
                  • Oct 2009
                  • 1286

                  #23
                  Guys, look here. This new solution may be of interest to you.

                  Better syslog message handling for Zabbix

                  Comment

                  • nelsonab
                    Senior Member
                    Zabbix Certified SpecialistZabbix Certified Professional
                    • Sep 2006
                    • 1233

                    #24
                    LOL!!! This is funny. This thread was started by a spammer, but it has turned out to be somewhat useful. :-)

                    Splunk is another good tool for log file monitoring. You can even have splunk parse your logs, generate reports which you could conceivably push into Zabbix.

                    Splunk however does have a drug dealer like model... They give away the first 500MB of logging per month for free, then if you want support it's a few $K but you still only get 500MB, then to get 1GB of logging it twice the price of the 500MB with support, from there the price drops per MB of logging. Be warned, Splunk can chew CPU and disk space almost more than Zabbix.
                    RHCE, author of zbxapi
                    Ansible, the missing piece (Zabconf 2017): https://www.youtube.com/watch?v=R5T9NidjjDE
                    Zabbix and SNMP on Linux (Zabconf 2015): https://www.youtube.com/watch?v=98PEHpLFVHM

                    Comment

                    Working...