Turn your Cisco PIX Syslog files into Graphs using Syslog Junction.

I was setting up a bunch of monitoring at work as we hadn’t have that much implemented. I ran into this application in a random fashion. Sys Junction is an application that graphs out syslog data from Cisco PIX firewalls.

I was setting up a bunch of monitoring at work as we hadn’t have that much implemented. I ran into this application in a random fashion. Sys Junction is an application that graphs out syslog data from Cisco PIX firewalls.

The setup is simple, you download the install archive, extract it and then run the install script “run.sh”. You will need to make sure that the file has executable permissions, since my install was a linux install (they also have a windows version). Run “chmod u+x run.sh” beforehand. You would think that from reading the documentation the install would occur, but no install actually occurs. Once you type “run.sh” the application forks into the background and starts printing random logging information on your terminal. It doesn’t even install as a service, you have to do this yourself.

Now that you have Syslog Junction running, you can open up your web browser and point it to “http://127.0.0.1:11052” or the IP address of the server you have it running on. You should see a login screen, enter in the default login information which is “admin/letmein”. And bam you either see graphs or no graphs!

I didn’t have graphs! I look back now and think, should have spent 3 hours on trying to get this to finally work or not? Was it worth all the trouble of trying to figure out the problem instead of having a Install Document or any type of information other than a couple pages of a PDF file with only a couple pages of information.

After look at the logs in the folder “logs”, I see in the file “SLJunction.log”. So I decide to tail it to see whats in it. And Viola! I get an error message

2007-11-20 16:12:29,640 ERROR sljunction.SLJunctionApp - Unable to start Syslog server. Address already in use

So I ponder to myself and do what anybody in my position would do, start grinding out the debugging tools. So I run netstat:


[[email protected]:/var/www/default/SLJunction/logs]# netstat -nlp | grep syslog
udp 110400 0 0.0.0.0:514 0.0.0.0:* 4646/syslogd

Oh and look syslog had the -r option for remote machine logging. So I disabled syslog and start Syslog Junction again and no more error. But instead of getting pretty graphs, I get blank ones again.

After further testing it look as though you have to make sure that your Cisco PIX is sending only Informational syslog data otherwise it pick up the traffic.

All in all, a good application, but time consuming!

Visit the Syslog Junction site.

0 Shares:
You May Also Like

AMD to introduce 45nm process AM3 CPU family in 2H08

AMD to introduce 45nm process AM3 CPU family in 2H08 - AMD schedules to launch its 45nm process socket AM3 family processors in the second half of 2008. The processors will support HyperTransport 3.0 and will have a built-in DDR2/DDR3 memory controller. The processors will be backward compatible with the previous AM2 and AM2+ socket motherboards, according to sources at motherboard makers. AMD's AM3 family will include the quad-core Deneb and DenebFX, dual-core Propus and Regor, and single-core Sargas. Shipments of 45nm products are predicted to surpass those of 65nm products within half a year from launch, noted the sources.

Although Socket AM3 processors will be backwards compatible with previous socket AM2 and AM2+ motherboards, socket AM3 motherboards will not be able to support the previous socket AM2 and AM2+ processors. Therefore shipment volumes of socket AM3 motherboards will depend on the speed of transition to DDR3 memory, added the sources

View: The full story
News source: DigiTimes

Read full story...

[NeoWin-Main]

Safari 3.0.2 Beta

Safari 3.0.2 Beta - Safari has always been the fastest browser on the Mac and now it's the fastest browser on Windows, loading and drawing web pages up to twice as fast as Microsoft Internet Explorer 7 and up to 1.6 times faster than Mozilla Firefox 2.

Why you'll love Safari:

* Blazing Performance2x Faster - Safari is the fastest web browser on any platform.
* Elegant User Interface - Safari's clean look lets you focus on the web - not your browser.
* Easy Bookmarks - Organize your bookmarks just like you organize music in iTunes.
* Pop-up Blocking - Say goodbye to annoying pop-up ads and pop-under windows.
* Inline Find - Search any text on any website with the integrated Find banner.
* Tabbed Browsing - Open and switch between multiple web pages in a single window.
* SnapBackSnapback - Instantly snap back to search results or the top level of a website.
* Forms AutoFill - Let Safari complete online forms for you, automatically and securely.

Read full story...

[NeoWin-Software]

Dell reaches deal to sell computers at Staples

It looks as though Dell has reached a deal with the Office Supply Chain Staples to offer Dell products within their stores. You will see Dell equipment sold inside Staples starting November 11th.
Dell has reached a deal with the office supply chain Staples to offer Dell desktop and notebook computers, monitors, printers, ink, and toner. Starting November 11, Staples will begin selling Dell products both in its physical stores and online at Staples.com. Initial models to be sold in the Staples chains include the Inspiron 1721 and 1521 notebooks, and Inspiron 530 desktops.