Results 1 to 15 of 15

Thread: Syslog for Iseries

  1. #1
    Code400 Newbie
    Join Date
    Mar 2009
    Location
    Virginia
    Posts
    4
    Rep Power
    0

    Syslog for Iseries

    Hello from an avid "Guest" who has just now decided to create an account.

    I have received so much help from these forums as an unregistered guest, I would like to give back a little, and I was wondering about the amount of interest there would be in my first full-production tool I developed from the ground up.

    What is it? Ive called it (temporarilly at least until I can become more creative) SyslogI and it is a Java program which formats the entries as they are written to the QHST log into proper Syslog messages and then forwards the messages to your centralized Logging server. The need for this program came from my institution's need to satisfy central logging requirements set forth by the auditors. We were already logging messages from all other servers to a central server as well as our network devices, and needed to do the same with the Iseries for things like login failures, system errors and the like.


    So I came up with an idea that I would use the syslogD utility included in the Iseries PASE environment. However, this did not fully pan out, as it really didnt log any messages at all due to the iseries not having native 'hooks' into SyslogD.

    So I built a Java Syslog daemon as well as a qhst monitor/processor to format what is in the qhst logs properly, assign a severity code based on what IBM assigns (00 - 99) and then forward a proper RFC compliant message to our collector.

    I am about to enter into production testing, and as I do this it occurred to me that others might be in need of a similar product, and in a similar situation where their institution is not able to fork over the thousands of dollars which current offerings require.


    To be sure, what I have at current is not near as robust as some of the more "Commercial" offerings, however it does offer a step in the right direction, (Adding proper rules in say Kiwi can monitor for specifically login failures to satisfy HIPPA and other compliances) and I was wondering if I were to release it to the community at large, would there be enough interest?


    Thanks for your comments and Ideas. I look forward to everyone's response.

    Lee

  2. # 666
    Circuit advertisement
    Join Date
    Aug 1965
    Location
    Yakutsk, Russia
    Posts
    1,000,000
     

  3. #2
    Driver of cars, eater of food jamief's Avatar
    Join Date
    Jan 2004
    Location
    Belvidere, IL - United States of America
    Age
    49
    Posts
    9,416
    Rep Power
    12606

    Re: Syslog for Iseries

    Lee

    Welcome out of the shadows.........Sounds like a great tool
    could you post some screen shots?

    jamie
    All my answers were extracted from the "Big Dummy's Guide to the As400"
    and I take no responsibility for any of them.

    www.code400.com

  4. #3
    Code400 Newbie
    Join Date
    Mar 2009
    Location
    Virginia
    Posts
    4
    Rep Power
    0

    Re: Syslog for Iseries

    Thanks for the great welcome.

    As soon as I get some messages logged to the central server, I will post a screenshot, however it will just be the resultant log file collected via the central logging host

  5. #4
    Code400 Newbie
    Join Date
    Mar 2009
    Location
    Virginia
    Posts
    4
    Rep Power
    0

    Re: Syslog for Iseries



    Screenshot of forwarded messages (obviously sanitized for privacy/security) to the central syslog server. The parts which are "erased" are usernames, the final portion of the IP address , and the name of our Iseries. (which comes after the messages date/time stamp.

    As you can see, Im including the MessageID, text of the message, and assigning a syslog severity based off a translation of the IBM severity and also based off some thought of my own. In particular, the challenge is that the Iseres assigns severities based on an idea that every session is an attached device (like the old dumb terminals) so when one simply closes a session without signing off properly and exiting Client access properly, the Iseries sees the event as a critical error for an 'attached device' which of course it isnt.

    Anyhow, any ideas on this would be welcomed as I develop the connector further

  6. #5
    Experienced Forum Member
    Join Date
    Aug 2009
    Location
    California
    Posts
    95
    Rep Power
    0

    Re: Syslog for Iseries

    Now the question is how do you monitor QSYSOPR without locking the message queue? Or is it just polling and dumping QHST?

    I would think you would need QSYSOPR and/or QSYSMSG as well?

    -JA

  7. #6
    Code400 Newbie
    Join Date
    Apr 2010
    Location
    Mississippi
    Posts
    2
    Rep Power
    0

    Re: Syslog for Iseries

    Has anyone been able to successfully "point" iSeries logs (QHST) to an external syslog server?

    I requested info from IBM support and was told they don't support this.

    Any ideas?

  8. #7
    Experienced Forum Member
    Join Date
    Aug 2009
    Location
    California
    Posts
    95
    Rep Power
    0

    Re: Syslog for Iseries

    I wrote a commercial product some years back to do that and wound up having to create a TCP/IP sockets programs with RPG. If you download and look at the RFC for syslog you will see it's really straight forward since you just send the messages without any sort of response.

    -JA

  9. #8
    Code400 Newbie
    Join Date
    Apr 2010
    Location
    Mississippi
    Posts
    2
    Rep Power
    0

    Re: Syslog for Iseries

    Quote Originally Posted by John Andersen View Post
    I wrote a commercial product some years back to do that and wound up having to create a TCP/IP sockets programs with RPG. If you download and look at the RFC for syslog you will see it's really straight forward since you just send the messages without any sort of response.

    -JA
    Did I miss the link for the download? I'm not seeing that....sorry, it's Monday ... can you post that link?

  10. #9
    Code400 Newbie
    Join Date
    Oct 2010
    Location
    Virginia Beach, VA
    Posts
    3
    Rep Power
    0

    Re: Syslog for Iseries

    Reading this thread it sounds like you have a piece of code I would be interested in. I'm looking for a program that I can call and pass it the Facality & Serverty code along with a message and have it sent to a GFI SYSLOG Server.

    I've tried an RPG program sending message via UDP but most got lost, then I tried sending message via TCP and had it working as long as I control the qty of messages send. Then some updates were put on the GFI server and they turned the logging from the fiewall & SQL server on and now none of my messages make it.

    So I'm hoping that your method to send SYSLOG message will work better.

    Thanks,
    Dan

  11. #10
    Experienced Forum Member
    Join Date
    Aug 2009
    Location
    California
    Posts
    95
    Rep Power
    0

    Re: Syslog for Iseries

    @QMAGIC101

    Checkout the RFC for SYSLOG, I think it is RFC 5424 which can be read at the following URL:
    http://tools.ietf.org/search/rfc5424

    Because it uses UDP instead of TCP there are no guarantees, but I never had any problems with missing messages. If your SYSLOG server follows the RFC (and it had better) just make sure your sockets program formats the messages properly.

    The program I worked on years ago was a commerical product available from these guys www.trigeo.com

  12. #11
    Experienced Forum Member
    Join Date
    Aug 2009
    Location
    California
    Posts
    95
    Rep Power
    0

    Re: Syslog for Iseries

    oh, one more thing. To test your messages are being sent correctly from the 400 I would suggest creating a program that opens up a port and just listens. I did this pretty quickly using perl on a Windows box when testing it out originally before formatting the messages.

  13. #12
    Code400 Newbie
    Join Date
    Oct 2010
    Location
    Virginia Beach, VA
    Posts
    3
    Rep Power
    0

    Re: Syslog for Iseries

    John,

    Would you be interested in creating a little program that I could pass some parms to (syslog IP address, Facility Code, Serverity Code & Message text) and have your program format it and send it to a GFI Syslog server?

  14. #13
    Code400 Newbie
    Join Date
    Mar 2009
    Location
    Virginia
    Posts
    4
    Rep Power
    0

    Re: Syslog for Iseries

    If there is interest, I'll toss together some quick doc/install instructions and put it up somewhere downloadable. Let me dust it all off, and I'll get it uploaded somewhere over the next couple...


    Ive been running this for around 2 years now without issue, and much to the delight of my peers.

  15. #14
    Code400 Newbie
    Join Date
    Oct 2010
    Location
    Virginia Beach, VA
    Posts
    3
    Rep Power
    0

    Re: Syslog for Iseries

    I would find this very helpful if you would post what you have. I've not had any luck getting this to work correctly.

    Thanks,
    Dan

  16. #15
    Driver of cars, eater of food jamief's Avatar
    Join Date
    Jan 2004
    Location
    Belvidere, IL - United States of America
    Age
    49
    Posts
    9,416
    Rep Power
    12606

    Re: Syslog for Iseries

    I would also like to see it.....
    Please Post.


    Jamie
    All my answers were extracted from the "Big Dummy's Guide to the As400"
    and I take no responsibility for any of them.

    www.code400.com

  17. # 666
    Circuit advertisement
    Join Date
    Aug 1965
    Location
    Yakutsk, Russia
    Age
    21
    Posts
    1,000,000
     

Facebook Comments


Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •