Ä¿ÇǴнº, ½Ã½ºÅÛ ¿£Áö´Ï¾îÀÇ ½°ÅÍ
  windowsÀÇ eventlog¸¦ syslog ¼­¹ö·Î º¸³»±â ÀÛ¼ºÀÏ : 2012/10/31 18:55
 
  • ±Û¾´ÀÌ : ÁÁÀºÁøÈ£ ( http://coffeenix.net/ )
  • Á¶È¸¼ö : 18715
     
    Á¦  ¸ñ : windowsÀÇ eventlog¸¦ syslog ¼­¹ö·Î º¸³»±â
    ÀÛ¼ºÀÚ : ÁÁÀºÁøÈ£(truefeel, http://coffeenix.net/ )
    ÀÛ¼ºÀÏ : 2012.10.29(¿ù)


    Windows ¼­¹ö¿¡¼­ ¹ß»ýÇÏ´Â À̺¥Æ®·Î±×(Eventlog)¸¦ ½Ç½Ã°£À¸·Î syslog ¼­¹ö·Î º¸³»ÁÖ´Â eventlog-to-syslog ÅøÀÌ ÀÖ´Ù. Windows ¼­¹öÀÇ '¼­ºñ½º'¿¡ µî·ÏÇؼ­ 'start'¸¸ ÇØÁÖ¸é ÁöÁ¤ÇÑ syslog ¼­¹ö·Î ·Î±×¸¦ º¸³»ÁØ´Ù. °£´ÜÇÏ°í ±ò²ûÇÑ ±¸Á¶·Î µÇ¾î À־ ´Ù¸¥ ÅøÀ» º¼ ÇÊ¿ä¾ø´Ù.


    1. eventlog-to-syslog ¼³Ä¡

    http://code.google.com/p/eventlog-to-syslog/ ¿¡ zipÆÄÀÏÀ» ¹Þ¾Æ¿Â´Ù.
    ±×Áß¿¡¼­ evtsys.dll °ú evtsys.exe¸¦ c:\windows\system32 ¿¡ º¹»çÇÏ¸é ³¡³­´Ù.


    2. ¼­ºñ½º¿¡ µî·ÏÇϱâ

    evtsys -i ¿É¼ÇÀ¸·Î ¼­ºñ½º¿¡ µî·ÏÇÑ´Ù. ÀÌ ¶§ ·Î±×¸¦ ¹ÞÀ» syslog ¸®´ª½º ¼­¹ö IP¿Í Æ÷Æ®¸¦ ÇÔ²² ÁöÁ¤ÇÑ´Ù. ±âº» Æ÷Æ®´Â 514¹øÀÌ´Ù.

     
    C:\Windows\System32>evtsys -i -h <¸®´ª½º syslog¼­¹öÀÇ IP> -p <syslog Æ÷Æ®>
     


    ¡Ø ¼­ºñ½º¿¡¼­ ¾ø¾Ù ¶§´Â -u ¿É¼ÇÀ» »ç¿ëÇÏ¸é µÈ´Ù.

    '¼­ºñ½º'¿¡¼­ µî·Ï È®ÀÎÇÏ°í, startÇÑ´Ù.


    [ 'Eventlog to Syslog'°¡ ¼­ºñ½º ¸ñ·Ï¿¡ Ãß°¡µÇ¾î ÀÖ´Ù. ]




    3. ¸®´ª½º syslog ¼³Á¤

    syslog-ng ´ë½Å¿¡ CentOS 6.x¿¡ ±âº» ¼³Ä¡µÇ´Â rsyslogd¸¦ »ç¿ëÇß´Ù. ·Î±× ÀúÀå Á¶°ÇÀº ´ÙÀ½°ú °°´Ù.

    1) windows ¼­¹ö¸í¿¡´Â ¸ðµÎ CNX°¡ Æ÷ÇԵǾî ÀÖ´Ù.
    2) windows ¼­¹ö¸¦ Á¦¿ÜÇÑ ¸ðµç ·Î±×´Â  log.all¿¡ ÀúÀåÇÑ´Ù.
    3) windows ¼­¹öÀÇ        ¸ðµç ·Î±×´Â  log.CNX¿¡ ÀúÀåÇÑ´Ù.
    4) windows ¼­¹ö        °¢°¢ÀÇ ·Î±×´Â 'log.¼­¹ö¸í'¿¡ ÀúÀåÇÑ´Ù.

    [ /etc/rsyslogd.conf ÀϺΠ]
     
    $template FILE_org, "/data/log/log.%HOSTNAME%"
    $template FILE_low, "/data/log/log.%HOSTNAME:::LOWERCASE%"
    $template FILE_upp, "/data/log/log.%HOSTNAME:::UPPERCASE%"

    # *nix
    if not ($hostname contains 'CNX')  then  /data/log/log.all
    if not ($hostname contains 'CNX')  then  ?FILE_org

    # windows
    if      $hostname contains 'CNX'   then¡¡¡¡¡¡ /data/log/log.CNX
    if      $hostname contains 'CNX'   then¡¡¡¡¡¡ ?FILE_low
     



    [ syslog ·Î±×¸¦ ¸ð´ÏÅ͸µÇÑ °á°ú (¸í·É) tail -f log.CNX | ./view.pl ]

    ¡Ø $hostname ´ë½Å $source º¯¼ö¸íÀ» »ç¿ëÇصµ µ¿ÀÏ.
    ¡Ø ·Î±× ÆÄÀÏ highlightÇÏ´Â ¹æ¹ýÀº '4. Âü°í ÀÚ·á' ½ºÅ©¸³Æ® È°¿ë

    4. Âü°í ÀÚ·á

    * rsyslog ¹®¼­
      http://www.rsyslog.com/doc/manual.html
    * ·Î±× ¸ð´ÏÅ͸µ½Ã ƯÁ¤ ¹®ÀÚ¸¦ highlightÇϱâ (±Û ÁÁÀºÁøÈ£)
      http://coffeenix.net/board_view.php?bd_code=1562


    Ä¿ÇǴнº, ½Ã½ºÅÛ ¿£Áö´Ï¾îÀÇ ½°ÅÍ / URL : http://coffeenix.net/board_view.php?bd_code=1741