I’m putting this in my syslog
We’ve been wanting some centralized syslogging at work. While we are waiting to purchase a commercial system, we’ve been looking at some free ones. The one that caught my attention was Zenoss.
Setting up this thing has been a nightmare. I never did get it to work right with Fedora. Today, I switched to Ubuntu. The Zenoss install on Ubuntu was effortless. However, the Apache, PHP5, MySQL, and phpMyAdmin setup left something to be desired. But after I got all those playing nice the Zenoss install itself was simple.
The Dashboard looks cool. I like the layout and it’s all web based so we can check the logs from anywhere without the need for an extra terminal.
Now we need to log something. The Zenoss guys suggest a couple different ways of getting the Windows syslogs to the Zenoss server. We’re playing with them to see which way gives us the best results. One thing I’m not thrilled with is that we have to do a lot of categorizing of the events ourselves. Training this thing will take some time. I would have thought the server would have been a little smarter than that. I might be wrong though, we haven’t tested it extensively yet.
Since we’re all about discussion, what are you (if anything) doing to keep track of your syslogs? Is anyone going as far as tracking workstations as well as servers? Are there some other alternatives you would suggest?


