This topic deals with the creation and management of SYSLOG distributions in the system. The SYSLOG is a standard for computer message logging.
To create a SYSLOG distribution
1. Ensure you are the PULL distribution page. Refer parent topic Creating and Managing Distribution for details. If you have done it correctly the following page is displayed.
2. Click . The following fields and buttons are displayed.
3. Click inside the Distribution field and select a distribution from the drop-down list. This is a suggest drop-down. Here you can select an existing distribution name (this means adding a new path to an existing distribution) or create a new one.
4. Click inside the Enter a path in the Facility field and select a facility from the drop-down list.
Note: A SYSLOG distribution consists of one of more facilities, a distro & group links groups to distributions. When OTUS receives a syslog message it does the following:
•finds the server by the syslog message remote ip addr
•finds all the servers groups
•for each group it finds all the associated SYSLOG distros (by the group & distro link)
•for each SYSLOG distro, it looks at the defined facilities
•it only accepts SYSLOG messages with facilities that are defined in this distro
•optionally if the distro/facility was assigned an indexer it indexes the data with that indexer
You can also have 2 different syslog distros with the same facility, and for example one is indexed and one is not.
6. Click inside the Indexers field and from the drop-down select one or more indexers. You can search for an indexer by entering characters or words of the name of the indexer in the empty field located on drop of the drop-down list. To remove an indexer click the "X" of the name of the indexer.
Note: Indexers are optional. If none is entered only raw log files are stored on server.
7. Click . The new distribution is added to the list of distributions in the table.
To modify a syslog distribution
1. Double-click an editable field of a record in the table and it is enabled for editing. In the example the Indexers field of a record has been double-clicked.
2. Edit the field as required.
3. Click to save the changes. Click
to close without saving any changes made.
To delete a syslog distribution
1. Click to select the record of a Syslog distribution to be deleted.
2. Click . The delete confirmation dialog is displayed.
3. Click Yes to delete the record.
Caution: Exercise this function with care. The process cannot be undone. All data is deleted.