How to convert windows logs into syslog Format and send them to the remote sysylog server, syslogsysylog
2. Configuration
Then open URL: http: // 192.168.37.23: 6161/and enter the Default User snare and the password set above.
The management interface is displayed,
We configured syslog mainly to set the following parameters. We should know what it is when we see 514.
3. Verify
View the syslog log on linux.
The remaining steps are the same as using word to perform log configuration and System Remote Management settings.
4. Support for ossim
If you want to use ossim again, you need to modify
Process = rSyslogd
Start = no; launch plugin process when agent starts
Stop = no; shutdown plugin process when agent stops
Startup =/etc/init. d/rsyslog start
Shutdown =/etc/init. d/rsyslog stop
Source = log
Location =/var/log/snare. log
Create_file = true
To
Alienvault:/etc/ossim # cat/etc/rsyslog. d/snare. conf
If $ msg contains '192. 168.1.8 'then-/var/log/snare. log
If $ rawmsg contains 'eventlog' then-/var/log/snare. log
~
Then restart the ossim-agent and rsyslog services.