spidermouse
Posts: 39
Score: 0
Joined: 27.Jul.2006
Status: offline
|
If the rep has no idea why it is not working, then he should escalate the case to a higher level. Either way, it would be interesting to know if the Syslog messages are actually arriving on the Eventsmanager machine or not. Wireshark should give you a definite answer here. Next, check in the Eventsmanager interface if the Syslog messages show in the real-time monitor and if they are maybe rejected. IF they are rejected, then this is usually becasue there is no procesing rule that applies to the messages received and they are discarded. Maybe switch to "archive all" for a while so you can get the mesages into your DB and see what part of the message goes into what field of the DB. This way, it's much easier to alter the processing rules. If they don't show up in the real-time monitor, but wireshark DOES confirm the arrival of the messages on the machine, then the question is: why does Eventsmanger not see them? Is there another application installed that might intercept the syslog messages? Is there anything different on the Cisco 3750 messages compared to normal messages? What is the mechanism that allows Evetnsmanager to "see" those messages? GFI's Mail-products use SMTP sinks to capture the smtp traffic. What do GFI use to capture Syslogs? I'm sure there would be something similar...
|