Security & Management

Using MOM 2005 to monitor Non-Windows devices: Part 1

Configure Microsoft Operation Manager 2005 to monitor Unix devices by using Syslog

If you are using Microsoft Operation Manager 2005 and want to monitor the Unix devices by MOM Operator Console, You must need to configure the Unix devices to forward the Syslog messages to the MOM Agent Computer, and the MOM Management Server to receive and handle the Syslog messages.
 
On the MOM Management Server
 
To create a Syslog port provider
1. In the left pane of the MOM Administrator console, right-click Providers.
2. On the context menu, click New Provider, specify Application Log as the data provider type, and then click Next.
3. For the provider name, enter Syslog port provider.
4. For the provider log type, select Syslog port, and then click Finish.
 
To create an event rule that uses the Syslog port provider
1. First create a rule group named Syslog and associate this rule group with a computer group named Syslog messages receiver that included the Syslog message receiver computer (MOM Agent Computer).
2. In the left pane of the MOM Administrator console, expand the rule group, right click Event Rules, and then click New Event Rule.
3. Select Collect Specific Events (Collection), and then click Next.
4. In the list, select the Syslog port provider and then click Next.
5. Enter Collect Syslogs for the name of the rule, ensure that the Enabled check box is selected, and then click Finish.
6. In the left pane of the MOM Administrator console, expand the rule group, right click Event Rules, and then click New Event Rule.
7. Select Alert on or Respond to Event (Event),click Next.
8. In the list, select the Syslog port provider and then click Next.
9. In the Criteria Page, click Advanced button, and choose Parameter 1 in field, choose contains substring and enter the Syslog message level (example: crit, err, warning..) in value. Click Add to List.
10. Click Close and then click next. Check the Generate Alert in the Alert Page and configure the Alert properties.
11. Enter the name Received Syslog message level from Syslog for the rule name (example: Received Warning from Syslog). Click Finish.
12. Create additional rules for other syslog message level to generate alerts.
 
On the Unix device
 
1. Configure the entry in system logger configuration file (Syslog.conf) that maps syslog messages to the IP address of a Syslog message receiver (MOM Agent Computer). In the Syslog.conf file, tabs separate the message type and the IP address. The message type is of the form facility.level, such as kern.error, which signifies a kernel error.
The following facility values are recognized by MOM: auth, cron, daemon, ftp, kern, local0, local1, local2, local3, local4, local5, local6, local7, lpr, mail, mark, news, syslog, user, and uucp.
The following priority levels, from highest to lowest, are recognized by MOM: emerg, alert, crit, error, warning, notice, info, and debug.
Example:      *.err        @192.168.0.150
2. Restart the system logger daemon (syslogd) on the UNIX device.

 
 
Posted: Fri, Oct 21 2005 17:51 by daniel | with 4 comment(s)
Filed under:

Comments

Mike said:

Gluck im Spiel, Ungluck in der Liebe.
# August 23, 2006 9:49 PM

Jeorge Lukasing said:

Very many thanks for a good work. Nice and useful. Like it!
# August 27, 2006 5:59 AM

inventory pc software said:

Thanks for the great tips about inventory pc software and [URL=http://eteamz.active.com/businessloan/files/inventory-pc-software.html]inventory pc software[/URL]
# August 27, 2006 7:45 PM

KlaudSCH said:

Greetings!

I'm newbie here and I want to ask for some help.

Can you give me some info and some links where I can get general help on using forum.

I think that this info can be usefull for all newbies.

Thanks!

P.S. Sorry for my making this topic in wrong section

____

<a href=xgloq.net>Texas</a>...I'm lovin' it :)

# July 10, 2007 2:21 AM
Leave a Comment

(required) 

(required) 

(optional)

(required)