ATTENTION: We are currently working an issue with posting. Thank you for your patience while we work on a resolution.
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2387
Views
0
Helpful
8
Replies

TMS & syslog server

NEYAZI BASAN
Level 1
Level 1

Hi,

 I want to make my TMS server pointing to the syslog server, how to do this?

 

1 Accepted Solution

Accepted Solutions

Patrick Sparkman
VIP Alumni
VIP Alumni

I just checked the TMS admin guides, and even our TMS.  None of them mention the ability to use a syslog server, so it looks like this isn't possible, unless there is some other way to do it that isn't documented or within the TMS web interface.

If this is something that you'd really like to see included, suggest you contact your Cisco Account Manager and file a feature request.

View solution in original post

8 Replies 8

Patrick Sparkman
VIP Alumni
VIP Alumni

I just checked the TMS admin guides, and even our TMS.  None of them mention the ability to use a syslog server, so it looks like this isn't possible, unless there is some other way to do it that isn't documented or within the TMS web interface.

If this is something that you'd really like to see included, suggest you contact your Cisco Account Manager and file a feature request.

Martin Koch
VIP Alumni
VIP Alumni

You have various log sources, the TMS logfiles, the eventlog.

I would assume there are tools which could wrap that info and send it to a syslog

or some other kind of server or grab it to some other tool (like splunk).

 

Besides that you can at least send traps via snmp to an external agent.

 

In addition some components support syslog by itself (like vcs, mcu, ...)

 

 

Might be interesting to know what kind of info you want to see in the syslog.

 

Please remember to rate helpful responses and identify

Pretty much I want to able to caputre audit event that relate to security. I intend to use DB connect, to grab the data withing SQL, I know its not the recommended way, but cant think of any other way to get the data into  syslog or splunk

I have the same issue with the TMS audit. I need to send it to syslog server, and splunk. Do anyone know where the TMS audit log location is at?

From what I've read there is no log that contains audit information as it's stored in the database, see CSCuz84595.

I guess I will need to somehow extract that data from SQL then? Also do you know if splunk have a TA for this? I would like to be able to extract the audit data and import into splunk

Thai V. Tong
Principal Information Security Engineer
(703) 674-4270 (W)
Thai.Tong@ManTech.com



________________________________

This e-mail and any attachments are intended only for the use of the addressee(s) named herein and may contain proprietary information. If you are not the intended recipient of this e-mail or believe that you received this email in error, please take immediate action to notify the sender of the apparent error by reply e-mail; permanently delete the e-mail and any attachments from your computer; and do not disseminate, distribute, use, or copy this message and any attachments.

I don't know anything about Spunk, sorry.

Looks like a combination of pulling events from the database using DB-Connect and possible pulling from Cisco Prime Infrastructure if supports telepresence devices.