Forward Windows system Event logs to a Linux Syslog Server with no agent
You need to use a Syslog agent, as Windows doesn't provide one.
...the Windows OS doesn’t include a syslog agent that is capable of sending syslog data to a syslog server. Without a syslog agent, not only can’t the Windows OS send syslog messages to a syslog server but it also can’t send syslog messages from any applications running in the Windows OS (like a web server or database).
Both that source page, and Googling for "Windows Syslog Agent" provide many different Syslog agents you can try.
Related videos on Youtube
Comments
-
tobe1424 almost 2 years
We have a SCOM 2012 server.
We have SNARE agents for PCI compliance, but now we want to save money by gathering all events for all Windows servers using its native features.
We also have a centralized Linux server running SYSLOG that will aggregate the logs to our log retention appliance (this is all for PCI purposes)
Thus, my question:
Can a windows server (SCOM 2012) forwards the events logs to a Linux syslog server? I assume this would occur by following a standard flat file format or something similar.
Thanks
-
tobe1424 over 9 yearsI see. As I google, I continue to see how an agent is the way to go. Specifically SNARE. However, we are trying to implement an agentless solution.
-
tobe1424 over 9 yearsWould I be able to retrieve event logs from a windows server using a WMI client for linux such as wbemcli? Would it be possible with wbemcli or other means to have windows push event logs to a linux syslog server or respond to queries from the syslog server? I discovered the ideas from the link below. But they could be irrelevant. superuser.com/questions/174578/…
-
tobe1424 over 9 yearsHaving a SCOM server in place, would linux be able to pull the logs from this one particular serverand be able to differentiate the logs from every windows server they were collected from? Or will linux think that the logs all originated from the windows centralized log server (SCOM 2012)? Would there be a way to differentiate the logs?
-
Ƭᴇcʜιᴇ007 over 9 yearsI answered your question, please one question per question. :) What you've asked in the comments here seem like good candidates for new questions.
-
tobe1424 over 9 yearsroger! well noted