Ä¿ÇǴнº, ½Ã½ºÅÛ ¿£Áö´Ï¾îÀÇ ½°ÅÍ Ä¿ÇÇÇâÀÌ ³ª´Â *NIX
Ä¿ÇǴнº
½Ã½ºÅÛ/³×Æ®¿÷/º¸¾ÈÀ» ´Ù·ç´Â °÷
* HanIRCÀÇ #coffeenix ¹æ
[ Àåºñ ¹× ȸ¼± ÈÄ¿ø ]
HOME > ½Ã½ºÅÛ °ü¸® / ¼­¹ö¿î¿µ > ·Î±×(log) / syslog µµ¿ò¸»
°Ë»ö : »çÀÌÆ® WHOIS À¥¼­¹ö Á¾·ù


  windowsÀÇ eventlog¸¦ syslog ¼­¹ö·Î º¸³»±â ÀÛ¼ºÀÏ : 2012/10/31 18:55
 
  • ±Û¾´ÀÌ : ÁÁÀºÁøÈ£ ( http://coffeenix.net/ )
  • Á¶È¸¼ö : 18706
          [ ÀÌÀüÈ­¸é / ¼öÁ¤ ]   ºñ¹Ð¹øÈ£ :     Àμâ¿ë È­¸é
      Á¦  ¸ñ : windowsÀÇ eventlog¸¦ syslog ¼­¹ö·Î º¸³»±â
    ÀÛ¼ºÀÚ : ÁÁÀºÁøÈ£(truefeel, http://coffeenix.net/ )
    ÀÛ¼ºÀÏ : 2012.10.29(¿ù)


    Windows ¼­¹ö¿¡¼­ ¹ß»ýÇÏ´Â À̺¥Æ®·Î±×(Eventlog)¸¦ ½Ç½Ã°£À¸·Î syslog ¼­¹ö·Î º¸³»ÁÖ´Â eventlog-to-syslog ÅøÀÌ ÀÖ´Ù. Windows ¼­¹öÀÇ '¼­ºñ½º'¿¡ µî·ÏÇؼ­ 'start'¸¸ ÇØÁÖ¸é ÁöÁ¤ÇÑ syslog ¼­¹ö·Î ·Î±×¸¦ º¸³»ÁØ´Ù. °£´ÜÇÏ°í ±ò²ûÇÑ ±¸Á¶·Î µÇ¾î À־ ´Ù¸¥ ÅøÀ» º¼ ÇÊ¿ä¾ø´Ù.


    1. eventlog-to-syslog ¼³Ä¡

    http://code.google.com/p/eventlog-to-syslog/ ¿¡ zipÆÄÀÏÀ» ¹Þ¾Æ¿Â´Ù.
    ±×Áß¿¡¼­ evtsys.dll °ú evtsys.exe¸¦ c:\windows\system32 ¿¡ º¹»çÇÏ¸é ³¡³­´Ù.


    2. ¼­ºñ½º¿¡ µî·ÏÇϱâ

    evtsys -i ¿É¼ÇÀ¸·Î ¼­ºñ½º¿¡ µî·ÏÇÑ´Ù. ÀÌ ¶§ ·Î±×¸¦ ¹ÞÀ» syslog ¸®´ª½º ¼­¹ö IP¿Í Æ÷Æ®¸¦ ÇÔ²² ÁöÁ¤ÇÑ´Ù. ±âº» Æ÷Æ®´Â 514¹øÀÌ´Ù.

     
    C:\Windows\System32>evtsys -i -h <¸®´ª½º syslog¼­¹öÀÇ IP> -p <syslog Æ÷Æ®>
     


    ¡Ø ¼­ºñ½º¿¡¼­ ¾ø¾Ù ¶§´Â -u ¿É¼ÇÀ» »ç¿ëÇÏ¸é µÈ´Ù.

    '¼­ºñ½º'¿¡¼­ µî·Ï È®ÀÎÇÏ°í, startÇÑ´Ù.


    [ 'Eventlog to Syslog'°¡ ¼­ºñ½º ¸ñ·Ï¿¡ Ãß°¡µÇ¾î ÀÖ´Ù. ]




    3. ¸®´ª½º syslog ¼³Á¤

    syslog-ng ´ë½Å¿¡ CentOS 6.x¿¡ ±âº» ¼³Ä¡µÇ´Â rsyslogd¸¦ »ç¿ëÇß´Ù. ·Î±× ÀúÀå Á¶°ÇÀº ´ÙÀ½°ú °°´Ù.

    1) windows ¼­¹ö¸í¿¡´Â ¸ðµÎ CNX°¡ Æ÷ÇԵǾî ÀÖ´Ù.
    2) windows ¼­¹ö¸¦ Á¦¿ÜÇÑ ¸ðµç ·Î±×´Â  log.all¿¡ ÀúÀåÇÑ´Ù.
    3) windows ¼­¹öÀÇ        ¸ðµç ·Î±×´Â  log.CNX¿¡ ÀúÀåÇÑ´Ù.
    4) windows ¼­¹ö        °¢°¢ÀÇ ·Î±×´Â 'log.¼­¹ö¸í'¿¡ ÀúÀåÇÑ´Ù.

    [ /etc/rsyslogd.conf ÀϺΠ]
     
    $template FILE_org, "/data/log/log.%HOSTNAME%"
    $template FILE_low, "/data/log/log.%HOSTNAME:::LOWERCASE%"
    $template FILE_upp, "/data/log/log.%HOSTNAME:::UPPERCASE%"

    # *nix
    if not ($hostname contains 'CNX')  then  /data/log/log.all
    if not ($hostname contains 'CNX')  then  ?FILE_org

    # windows
    if      $hostname contains 'CNX'   then¡¡¡¡¡¡ /data/log/log.CNX
    if      $hostname contains 'CNX'   then¡¡¡¡¡¡ ?FILE_low
     



    [ syslog ·Î±×¸¦ ¸ð´ÏÅ͸µÇÑ °á°ú (¸í·É) tail -f log.CNX | ./view.pl ]

    ¡Ø $hostname ´ë½Å $source º¯¼ö¸íÀ» »ç¿ëÇصµ µ¿ÀÏ.
    ¡Ø ·Î±× ÆÄÀÏ highlightÇÏ´Â ¹æ¹ýÀº '4. Âü°í ÀÚ·á' ½ºÅ©¸³Æ® È°¿ë

    4. Âü°í ÀÚ·á

    * rsyslog ¹®¼­
      http://www.rsyslog.com/doc/manual.html
    * ·Î±× ¸ð´ÏÅ͸µ½Ã ƯÁ¤ ¹®ÀÚ¸¦ highlightÇϱâ (±Û ÁÁÀºÁøÈ£)
      http://coffeenix.net/board_view.php?bd_code=1562
      Ä¿ÇǴнº Ä«Æä ÃÖ±Ù ±Û
    [04/19] Á¦ÁÖ&#5
    [04/18] ??? ?????
    [04/17] ???? onion ?????? -
    [04/11] ±¹°¡&#5
    [04/10] Stride Into Dream:
    [03/20] Re: ¿Â¶óÀΰÔÀÓÀÇ Á¾ÁÖ±¹ ´ëÇѹα¹
    [10/20] Cross Compiler ±ò
    [07/14] SSL ¬¡¬°
    [04/26] Re: µµ½ºÈ­¸é ¿ø°ÝÁ¶Á¾ ¿©ºÎ
    [04/25] µµ½ºÈ­¸é ¿ø°ÝÁ¶Á¾ ¿©ºÎ
    [10/30] Cshell¿¡¼­ ³­¼ö ¼³Á¤
    [10/23] °øÇ×öµµÁÖ½Äȸ»ç SE ±¸ÀÎ Ëì
    [01/26] Re: wgetÀ¸·Î ´Ù¸¥¼­¹ö¿¡ÀÖ´Â µð·ºÅ丮¸¦ °¡Á®¿À·Á°íÇÕ´Ï´Ù.
    [01/25] wgetÀ¸·Î ´Ù¸¥¼­¹ö¿¡ÀÖ´Â µð·ºÅ丮¸¦ °¡Á®¿À·Á°íÇÕ´Ï´Ù.
    [01/11] ƯÁ¤ ¾Èµå·ÎÀ̵å WebView ¹öÀü¿¡¼­ SSL ¹®Á¦ (WebView ¹ö±×)
      New!   ÃÖ±Ù¿¡ µî·ÏÇÑ ÆäÀÌÁö
      KiCad EDA Suite project (Free/Libre/Open-Source EDA Suite) (CAD)
      ¿ÀÇÂij½ºÄÉÀ̵å ijµå (OpenCASCADE CAD)
      QCad for Windows --- GNU GPL (Free Software)
      The Hello World Collection
      IPMI¸¦ È°¿ëÇÑ ¸®´ª½º ¼­¹ö°ü¸®
      DNS ¼³Á¤ °Ë»ç
      nagiosgraph ¼³Ä¡ ¹æ¹ý
      Slony-I ¼³Ä¡ ¹æ¹ý (postgresql replication tool)
      Qmail±â¹ÝÀÇ Anti spam ½Ã½ºÅÛ ±¸ÃàÇϱâ
      clusterssh

    [ ÇÔ²²ÇÏ´Â »çÀÌÆ® ]




    ¿î¿µÁø : ÁÁÀºÁøÈ£(truefeel), ¾ß¼ö(yasu), ¹ü³ÃÀÌ, sCag
    2003³â 8¿ù 4ÀÏ~