TechSpace Knowledgebase
Search:     Advanced search
Browse by category:
Contact Us

Configuring a Syslog Agent in Windows Server 2012

Views: 476
Votes: 0
Posted: 27 Mar, 2016
by: Wonglangga S.
Updated: 23 Apr, 2016
by: Wonglangga S.

This article takes a look at what you need to know about syslog and how to configure your Windows Servers to send syslog.

Introduction 

Are you a Windows Admin who doesn’t know a lot about syslog? That’s pretty common as Windows Servers use “events”, not the IETF standard RFC3164 and RFC5424 syslog. Still, the Windows OS can use syslog if taking the right steps. Here’s what you need to know about syslog and how to configure your Windows Servers to send syslog.

Advertisement

What is Syslog?

An industry-standard standard system log reporting system, syslog, is used by most devices and operating systems in the datacenter. It includes messages related to systems management, security, debugging, and OS or application errors. Not only is syslog supported by all Linux and Unix-based operating systems but it is also supported by network devices (like routers, switches, and firewalls), storage devices, and even devices like printers. Because of its wide adoption, syslog is a great way to consolidate logging data from across the datacenter in a single place both for preservation and analysis. Analysis of syslog data is critical for security auditing, troubleshooting, and identifying misconfigurations. However, in many cases it is even useful for troubleshooting storage configurations, storage security, and even storage performance. Many devices in the datacenter (such as Cisco routers and switches) do not store historical syslog messages and, thus, it is crucial to consolidate them. If that syslog data is lost when the router looses power or crashes, it may be difficult or impossible to troubleshoot the issue with the device.

With syslog, every device sending syslog messages uses an agent to do so. Those messages from the agents are sent to a central syslog server. Every syslog message is sent with a particular “facility code”, used to identify the type of software that generated the message. Default syslog message are - auth, authpriv, daemon, cron, ftp, lpr, kern, mail, news, syslog, user, uucp, local0 - local7. Those messages are assigned a severity using one of the following classifications - Emergency, Alert, Critical, Error, Warning, Notice, Info, or Debug. In Linux, the syslog messages are usually stored in /var/log and most Linux operating systems offer a command line tool to send data to the log file calledlogger.

Syslog and the Windows Server OS

So what does all this have to do Windows Server 2012, you ask? With most other devices in the datacenter sending syslog messages to a centralized syslog server, what about Windows? The problem is that, unlike Linux, the Windows OS doesn’t include a syslog agent that is capable of sending syslog data to a syslog server. Without a syslog agent, not only can’t the Windows OS send syslog messages to a syslog server but it also can’t send syslog messages from any applications running in the Windows OS (like a web server or database).

I discovered this while testing the new syslog consolidation and analysis tool from VMware – vCenter Log Insight. Log Insight is a syslog server that performs not only consolidation but also real-time analysis of any logging data sent to it. It’s ideally suited for VMware vSphere virtual infrastructure as it connects directly to your vCenter server and ESXi hosts. It understands the statistics that it collects from the vSphere infrastructure and is a great tool for analyzing system logs and identify errors before they affect end users.

Syslog Agent Options for Windows 2012

If you use your favorite search engine and you do a search for “windows syslog agent”, you’ll get number of syslog agents to choose from (most of them being free). Here are some of the options that I found:

Please note:
I did not test any of these syslog agents except for one – Datagram SyslogAgent – (which happened to be the first one that I picked and tested below). Thus, I’m not saying that the one I selected was better or worse than the others, it just happened to be the one I used.

Also note that you shouldn’t confuse syslog servers with syslog agents. Syslog servers (or syslog hosts) collect syslog data and agents send that data. For Windows Server, you need an agent, not a collector (or server). For example,Solarwinds syslog server (formerly Kiwi syslog server) is a syslog server, not a syslog agent. If you don’t have a syslog server already, then that is a good option for general use or vCenter Log Insight is a good option if you are already using VMware vSphere.

Downloading and Installing Datagram Syslog Agent

For my testing, I selected the free Datagram SyslogAgent. From the product page, I clicked the Download and then selected the Datagram Syslog Agent 64-bit download (don’t choose the Syslog Server at the top of the page). Note that you can either go to this webpage directly from the server where you want to install the syslog agent on or you can download it on your local computer and then transport it the Windows server via the network or USB key.

If you extract the 2MB Syslog file that you downloaded, there are a few files but the only three important files are the PDF user’s manual, the SyslogAgent configuration tool, and the SyslogAgent that you need to install on the server.

Image
Figure 1:
 SyslogAgent Installation Files

In the sense of a traditional Windows application install, there is not one for the SyslogAgent service. You just run the SyslogAgentConfig tool and click Install under the Service Status section at the top.

Image
Figure 2:
 Installing the SyslogAgent Service

This will create the Windows service for the SyslogAgent.

Before you get too excited and start the service, let’s first configure it.

The minimum configuration would be:

  • That the service is install
  • A syslog server IP and port are configured
  • That either event or application logs are selected to be sent to the syslog host (for whatever type of events and/or applications you choose)
  • And that the syslog agent service is started.

To select where the log data from your Windows host will be sent, enter the IP address of the syslog host, as you see in the graphic, Figure 2, above. In my case, the Log Insight syslog server’s IP address was 10.0.1.120 and we were using UDP port 514.

With this enabled, I checked the Event Logs option and selected what type of event logs I wanted. For system monitoring, I would recommend sending “system logs” but you are welcome to send any type of logs you want such as security logs for 
auditing purposes.

Image
Figure 3:
 Selecting the Event Logs to Send to the Syslog Host

Optionally, you can configure the application log events to forward and even customize their facility and severity, as you see in Figure 4.

Image
Figure 4:
 Customizing Facility and Severity

Optionally, you can choose to send events from specific Windows applications to the syslog host, even specifying the executable for the custom application (as you see at the bottom of Figure 2).

Once you’ve got it configured, click Start Service.

You are welcome to double check your Windows services to see that the SyslogAgent is added and running as you see below in Figure 5.

Image
Figure 5:
 SyslogAgent Running in Services

With the syslog agent running, let’s go check our syslog server to see if it is receiving messages from our Windows 2012 Server.

Testing Syslog with VMware vCenter Log Insight

Let’s assume that your syslog server was installed and is running fine, at the IP address you specified on the agent. In my case, I am using the new VMware vCenter Log Insight as my syslog host but there are numerous options.

Over on the vCenter Log Insight console, indeed, I was quickly able to identify syslog traffic coming from my Windows 2012 Server (with a DNS name of HV1).

Image
Figure 6:
 Windows Server Syslog Message on vCenter Log Insight

The graphic shows that the syslog server is reporting administrative user logins and logouts (at least in this part of the log) – something that would be very valuable for security audit purposes. Keep in mind that the syslog entries from Windows won’t just be security info. They’ll contain important system and application events as well.

Others in this Category
document How to Clear Your Computer’s CMOS to Reset BIOS Settings
document Install Hyper-V and create a virtual machine
document Configure DHCP Using Policy-based Assignment
document What Are Domains and Forests?
document Phoenix ISA/MCA/EISA BIOS Beep Codes
document How to make a self extracting archive that runs your setup.exe with 7zip -sfx switch
document Configuring PHP Development Environment in Windows
document Installing and Configuring target iSCSI server on Windows Server 2012
document How To Make UEFI Bootable USB Flash Drive to Install Windows 8
document TCP/IP Command-line
document How to set up an Internet email account in Outlook 2013 or 2016
document Enable Hyper-V on Windows 8.1
document Quickly Turn ON/OFF Windows Firewall Using Command Line
document How to List All of the Windows and Software Updates Applied to a Computer
document How to Repair a Windows 7 System with an Installation Disc
document How to Create Bootable USB from a Windows ISO
document How to Create Bootable USB from an IMG File
document 20 Terminal shortcuts developers need to know
document How to Update Your BIOS
document Getting Started With Lync Mobile 2010 For Android Devices
document "Attachment size exceeds the allowable limit" error when you add a large attachment to an email message in Outlook
document How do I renew the IP address for my computer ?
document Is your Windows 10 PC slowing you down, and the SFC utility is unable to fix the problem? Then use DISM to repair the Windows image to enable SFC to do its job.
document How to make a full backup of a Windows 10 or Windows 8.1 PC
document How to create a System Restore Point in Windows 10 with a simple double-click
document How to properly remove the Windows.old folder on Windows 10
document How control your Windows 10 PC or phone with another computer with the Connect app
document How to use Bing images within Office and Edge on Windows 10 PC.
document How to fix taskbar search not working in Windows 10
document How to disable or uninstall OneDrive on Windows 10 PC
document How to re-activate Windows 10 after a hardware change
document How to change the system language across your whole Windows 10 PC
document Use Windows Defender Offline to remove tough viruses from your Windows 10 PC
document 16 Essential keyboard shortcuts everyone should know using Continuum for phones
document How to disable Action Center in Windows 10
document How to use Storage Spaces in Windows 10
document How to generate a Battery Report in Windows 10.
document HOW TO CONTROL YOUR PRIVACY IN CHROMEBOOKS VS. WINDOWS 10
document Create Fake File in Window PC in Any Size and Any Format
document INCREASE BATTERY LIFE OF LAPTOP EASILY
document How to perform an image backup in Windows 8.1 or 10
document Block Windows 10 Upgrade
document Chrome reset for adware issues
document Revert from Windows 10 back to previous operating system
document Windows 7 Guide to using Microsoft Security Essentials
document Force Dragon Naturally Speaking to load a particular user profile
document Texthelp Read and Write Gold Prediction returns strange results or receives double letters
document Connect Powershell to your Windows Azure subscription
document How to set up desktop background image rotation in Windows 8
document How to adjust your Laptops screen brightness in Windows 8/8.1
document Microsoft Security Essential Install, Windows 7
document Set the default Microsoft Word template back to a blank document
document Schedule Windows to shutdown or restart after a time limit
document 20 Windows 8 and 8.1 shortcuts
document Bypass Windows 8 and 8.1 login screen
document All the Ways You Can Still Get Windows 10 for Free
document The Complete Guide to Giving Better Family Tech Support
document How to Stop Skype from Running in the Background on Windows 10
document How to Upgrade to a Larger Hard Drive Without Reinstalling Windows
document How to Find and Remove Duplicate Files on Windows
document Scammers Are Using a Fake Version of AdwCleaner to Trick People
document How to Use OneDrive as Your Default Save Location on Windows 8.1
document How To Fix a Blue Screen of Death
document How To Fix Comdlg32.dll Not Found or Missing Errors
document How to Fix Fm20.dll Not Found or Missing Errors
document How to Fix Gdi32.dll Not Found or Missing Errors
document How To Fix Libxml2.dll Not Found or Missing Errors
document How to Fix Mfc42.dll Not Found or Missing Errors
document How to Fix Mfc90.dll Not Found or Missing Errors
document How To Fix Msvcp71.dll Not Found or Missing Errors
document How To Fix Msvcp80.dll Not Found or Missing Errors
document How To Fix Msvcr70.dll Not Found or Missing Errors
document How To Fix Msxml6.dll Errors
document How to Fix Ole32.dll Not Found or Missing Errors
document How To Fix Oleaut32.dll Not Found or Missing Errors
document How To Fix Shell32.dll Not Found or Missing Errors
document How To Fix Sqlite3.dll Not Found or Missing Errors
document How To Fix Ssleay32.dll Not Found or Missing Errors
document How To Fix STOP 0x00000005 Errors
document How To Fix STOP 0x0000007B Errors
document Keep the Windows 10 Taskbar Visible While Using the On-Screen Keyboard
document EdgeDeflector Forces Cortana to Use Your Default Web Browser
document How to Move the Clock to Right-Most Corner on the Taskbar in Windows 10
document Add Control Panel (Or Any Program) To Your Right-Click Menu With a Registry Tweak
document Six Keyboard Shortcuts Every Computer User Should Know
document How to Upgrade Your Computer's Login Screen
document How to Use Windows 8's New File History Backup (aka Time Machine for Windows)
document What Kind of Maintenance Do I Need to Do on My Windows PC?
document How to Do a Clean Install of Windows Without Losing Your Files, Settings, and Tweaks
document How to disable Microsoft Windows 10 keylogger (enabled by default)
document How to Use the Cortana Voice Assistant in Windows 10
document How to Map a Network Drive in Windows 10
document How to Sync Your iPhone with Windows 10
document How to turn Off Windows Update in Windows 10
document How to Change a NetBIOS Name
document How to turn off Windows Automatic Updates in Windows 8/8.1
document How To Disable Updates in Windows 7
document How to Run Disk Cleanup on a Windows 7 Computer
document How to Check If Windows 10 Is Activated or Not
document How to Check CPU Speed
document How to Create a Shortcut to Windows Update in Windows 10
document How to Enter the BIOS Setup Utility or Boot Menu with windows
document How to Install Drivers
document How to Check the Application Event Log for Errors
document How to Optimize Windows 10 Performance by tweaking Visual Effects
document How to Setting Password Protected Print Jobs
document How to Change User Account Name in Windows 10
document How to Set Up and Use Remote Desktop for Windows 10
document How to Find Drivers for Devices Using a Hardware ID
document How to Changing BIOS mode from UEFI to Legacy
document How to Speed Up Windows 10
document How to Outlook 2010 - Rebuild the index file
document How To Fix Outlook 2016 Search Problems
document How to Release and renew IP address
document How to HP Printers - USB Printer Setup (Windows)
document How to disable Windows Defender in Windows 7
document How to Turn On or Off Windows Defender in Windows 8 and 8.1
document How to Use Simple IF Statements in Excel
document Why Does 64-Bit Windows Need Two Program Files Folders?
document How to Assign a Static IP Address in Windows 7, 8, 10, XP, or Vista
document How to manually add a print server port?
document How to Join Your Computer to a Domain
document How to Force a Blue Screen in Windows
document How to Use All of Windows 10 Backup and Recovery Tools
document How To Repair HDD with DLC 2015
document How to change XAMPP apache server port?
document How to find computer serial number
document How to use Rufus to create a bootable USB drive to install (almost) any OS
document How do I format a USB Flash Drive to NTFS file system?
document Change RAID Type of a Volume or Disk Group
document Create an Admin User Account Using CMD Prompt (Windows)
document How to Find Your MAC Address in Windows 10
document How To Repair Windows 10
document Repair an Office application
document Add an email account to Outlook for PC
document How to install Office 365 on Windows PC
document How to test your home internet connection speed



RSS