<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: PHPlogcon message parser for SNARE</title>
	<atom:link href="http://blog.schauenburg.nl/2010/01/31/phplogcon-message-parser-for-snare/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.schauenburg.nl/2010/01/31/phplogcon-message-parser-for-snare/</link>
	<description></description>
	<lastBuildDate>Fri, 09 Jul 2010 14:11:33 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: aerlas</title>
		<link>http://blog.schauenburg.nl/2010/01/31/phplogcon-message-parser-for-snare/comment-page-1/#comment-678</link>
		<dc:creator>aerlas</dc:creator>
		<pubDate>Fri, 09 Jul 2010 14:11:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.schauenburg.nl/?p=418#comment-678</guid>
		<description>Hi Jeff !
Maybe it&#039;s too late, but 3 important points to verify : 

1 - Snare Client side : in &quot;Network config&quot;, check you enabled &quot;Enable SYSLOG Header?&quot;.

2 - Rsyslog server side : in /etc/rsyslog.conf, check you have this line :
$EscapeControlCharactersOnReceive on

3 - Loganalyzer : Go in &quot;Admin center&quot; &gt;&gt; &quot;Sources&quot;. And verify that you have selected &quot;Adiscon Winsyslog&quot; (in Logline type)

Then, after a &quot;/etc/init.d/rsyslog restart&quot;, this must be ok.</description>
		<content:encoded><![CDATA[<p>Hi Jeff !<br />
Maybe it&#8217;s too late, but 3 important points to verify : </p>
<p>1 &#8211; Snare Client side : in &#8220;Network config&#8221;, check you enabled &#8220;Enable SYSLOG Header?&#8221;.</p>
<p>2 &#8211; Rsyslog server side : in /etc/rsyslog.conf, check you have this line :<br />
$EscapeControlCharactersOnReceive on</p>
<p>3 &#8211; Loganalyzer : Go in &#8220;Admin center&#8221; &gt;&gt; &#8220;Sources&#8221;. And verify that you have selected &#8220;Adiscon Winsyslog&#8221; (in Logline type)</p>
<p>Then, after a &#8220;/etc/init.d/rsyslog restart&#8221;, this must be ok.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeff</title>
		<link>http://blog.schauenburg.nl/2010/01/31/phplogcon-message-parser-for-snare/comment-page-1/#comment-672</link>
		<dc:creator>Jeff</dc:creator>
		<pubDate>Sat, 05 Jun 2010 05:21:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.schauenburg.nl/?p=418#comment-672</guid>
		<description>I spent some time trying to get this to work.  I have rsyslog dumping to mysql and loganalyzer installed and configured.  

I have the msgparser installed with the correct name of the file and inside the file.  I do not get any errors when starting rsyslog or loganalyzer.  I can also click on message parsers from the admin center with no errors.

The problem is that the parser does not seem to be parsing.  It seems like anyway i try to enable the parser the logs enter the same way.  From no parser to specified.  Even if I direclty edit config.php sources or if i do it from admin center and speciry it.  It just looks the same always.

Do I have snare incorrectly configured?</description>
		<content:encoded><![CDATA[<p>I spent some time trying to get this to work.  I have rsyslog dumping to mysql and loganalyzer installed and configured.  </p>
<p>I have the msgparser installed with the correct name of the file and inside the file.  I do not get any errors when starting rsyslog or loganalyzer.  I can also click on message parsers from the admin center with no errors.</p>
<p>The problem is that the parser does not seem to be parsing.  It seems like anyway i try to enable the parser the logs enter the same way.  From no parser to specified.  Even if I direclty edit config.php sources or if i do it from admin center and speciry it.  It just looks the same always.</p>
<p>Do I have snare incorrectly configured?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aerlas</title>
		<link>http://blog.schauenburg.nl/2010/01/31/phplogcon-message-parser-for-snare/comment-page-1/#comment-606</link>
		<dc:creator>Aerlas</dc:creator>
		<pubDate>Wed, 21 Apr 2010 10:35:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.schauenburg.nl/?p=418#comment-606</guid>
		<description>ahaha, the solution was easy ... ^^ 
check the topic, to see it :)

http://kb.monitorware.com/snare-msg-parser-t10171.html#p18859</description>
		<content:encoded><![CDATA[<p>ahaha, the solution was easy &#8230; ^^<br />
check the topic, to see it <img src='http://blog.schauenburg.nl/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><a href="http://kb.monitorware.com/snare-msg-parser-t10171.html#p18859" rel="nofollow">http://kb.monitorware.com/snare-msg-parser-t10171.html#p18859</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aerlas</title>
		<link>http://blog.schauenburg.nl/2010/01/31/phplogcon-message-parser-for-snare/comment-page-1/#comment-605</link>
		<dc:creator>Aerlas</dc:creator>
		<pubDate>Tue, 20 Apr 2010 09:54:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.schauenburg.nl/?p=418#comment-605</guid>
		<description>Hi SWAT !!

I met an error ... 
When i put your (wonderful :) parser file, LogAnalyzer can&#039;t show me the list of parsers... (bug ?)

The error says : &quot;Fatal error: Class &#039;MsgParser_eventsnare&#039; not found in /var/www/loganalyzer/include/functions_config.php on line 243&quot;

So, i made some try, like rename msgparser.iis.class.php in msgparser.iiiiiiiiiis.class.php, by exemple ... same error.

It&#039;s like Loganalyzer didn&#039;t find the name of any new parser ... 


Have you an idea ? I reinstalled all the log system (debian / rsyslog / phplogcon (loganalyzer 3.0)) .. 

Thanks :)


PS : I already wrote a subject on it here : 
http://kb.monitorware.com/snare-msg-parser-t10171.html#p18859</description>
		<content:encoded><![CDATA[<p>Hi SWAT !!</p>
<p>I met an error &#8230;<br />
When i put your (wonderful <img src='http://blog.schauenburg.nl/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  parser file, LogAnalyzer can&#8217;t show me the list of parsers&#8230; (bug ?)</p>
<p>The error says : &#8220;Fatal error: Class &#8216;MsgParser_eventsnare&#8217; not found in /var/www/loganalyzer/include/functions_config.php on line 243&#8243;</p>
<p>So, i made some try, like rename msgparser.iis.class.php in msgparser.iiiiiiiiiis.class.php, by exemple &#8230; same error.</p>
<p>It&#8217;s like Loganalyzer didn&#8217;t find the name of any new parser &#8230; </p>
<p>Have you an idea ? I reinstalled all the log system (debian / rsyslog / phplogcon (loganalyzer 3.0)) .. </p>
<p>Thanks <img src='http://blog.schauenburg.nl/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>PS : I already wrote a subject on it here :<br />
<a href="http://kb.monitorware.com/snare-msg-parser-t10171.html#p18859" rel="nofollow">http://kb.monitorware.com/snare-msg-parser-t10171.html#p18859</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cnu</title>
		<link>http://blog.schauenburg.nl/2010/01/31/phplogcon-message-parser-for-snare/comment-page-1/#comment-517</link>
		<dc:creator>cnu</dc:creator>
		<pubDate>Thu, 25 Feb 2010 10:41:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.schauenburg.nl/?p=418#comment-517</guid>
		<description>Hello, I made some mistakes. But now it works. Thank You.  

Other Question, is it possible to edit the Severity and so on, to get it coloured ?  &quot;Success Audit&quot; and &quot;Information&quot; in green and &quot;Warning&quot; in red ? br cnu</description>
		<content:encoded><![CDATA[<p>Hello, I made some mistakes. But now it works. Thank You.  </p>
<p>Other Question, is it possible to edit the Severity and so on, to get it coloured ?  &#8220;Success Audit&#8221; and &#8220;Information&#8221; in green and &#8220;Warning&#8221; in red ? br cnu</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SWAT</title>
		<link>http://blog.schauenburg.nl/2010/01/31/phplogcon-message-parser-for-snare/comment-page-1/#comment-481</link>
		<dc:creator>SWAT</dc:creator>
		<pubDate>Fri, 12 Feb 2010 22:23:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.schauenburg.nl/?p=418#comment-481</guid>
		<description>just use a correct facility and priority to send it the logs to a separate logfile, you do not need to add prefixes.

Example of one of my own loglines in the logfile:
Feb 12 22:17:53 ARRAKIS MSWinEventLog#0111#011System#011314#011vr feb 12 22:17:45 2010#01185#011SAVOnAccess#011N/A#011N/A#011Error#011ARRAKIS#011None#011#011 File [...\directx.dll.mui]&#039;s scan succeeded following a timeout/busy condition - it is being logged in case it contributed to that condition. Process svchost.exe, (start check timestamp [ 1caac2ad1basehc]).  #011113</description>
		<content:encoded><![CDATA[<p>just use a correct facility and priority to send it the logs to a separate logfile, you do not need to add prefixes.</p>
<p>Example of one of my own loglines in the logfile:<br />
Feb 12 22:17:53 ARRAKIS MSWinEventLog#0111#011System#011314#011vr feb 12 22:17:45 2010#01185#011SAVOnAccess#011N/A#011N/A#011Error#011ARRAKIS#011None#011#011 File [...\directx.dll.mui]&#8217;s scan succeeded following a timeout/busy condition &#8211; it is being logged in case it contributed to that condition. Process svchost.exe, (start check timestamp [ 1caac2ad1basehc]).  #011113</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cnu</title>
		<link>http://blog.schauenburg.nl/2010/01/31/phplogcon-message-parser-for-snare/comment-page-1/#comment-475</link>
		<dc:creator>cnu</dc:creator>
		<pubDate>Thu, 11 Feb 2010 12:19:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.schauenburg.nl/?p=418#comment-475</guid>
		<description>Hello, I tried your wrapper. But no success :-(. I installed SNARE, and configured our central rsyslog server. 

rsyslog server is configured for windows messages with the line:
:fromhost, startswith, &quot;vu&quot;                 /var/log/win_eventlog.log

I get the message like this: 2010-02-11T13:00:49+01:00 vuxxxx8 MSWinEventLog 1 Security 489 Thu Feb 11 13:00:26 2010 538 Security ANONYMOUS LOGON Well Known Group Success Audit vuxxxx8 Logon/Logoff  User Logoff:    #011User Name:#011ANONYMOUS LOGON    #011Domain:#011#011NT AUTHORITY    #011Logon ID:#011#011(0x0,0x3025986)    #011Logon Type:#0113     472
2010-02-11T13:00:49+01:00 vu39198 MSWinEventLog 1 Security 490 Thu Feb 11 13:00:27 2010 540 Security ANONYMOUS LOGON Well Known Group Success Audit vuxxxx8 Logon/Logoff  Successful Network Logon:   #011User Name:#011    #011Domain:#011#011    #011Logon ID:#011#011(0x0,0x34D6D1C)    #011Logon Type:#0113    #011Logon Process:#011NtLmSsp     #011Authentication Package:#011NTLM    #011Workstation Name:#011    #011Logon GUID:#011-   473


But the complete message is only available in the &quot;Message&quot; column. Nothing in Severity, Eventlog Type and so on. Can you help me ?

Maybe change the delimiter from SNARE ? br cnu</description>
		<content:encoded><![CDATA[<p>Hello, I tried your wrapper. But no success <img src='http://blog.schauenburg.nl/wp-includes/images/smilies/icon_sad.gif' alt=':-(' class='wp-smiley' /> . I installed SNARE, and configured our central rsyslog server. </p>
<p>rsyslog server is configured for windows messages with the line:<br />
:fromhost, startswith, &#8220;vu&#8221;                 /var/log/win_eventlog.log</p>
<p>I get the message like this: 2010-02-11T13:00:49+01:00 vuxxxx8 MSWinEventLog 1 Security 489 Thu Feb 11 13:00:26 2010 538 Security ANONYMOUS LOGON Well Known Group Success Audit vuxxxx8 Logon/Logoff  User Logoff:    #011User Name:#011ANONYMOUS LOGON    #011Domain:#011#011NT AUTHORITY    #011Logon ID:#011#011(0&#215;0,0&#215;3025986)    #011Logon Type:#0113     472<br />
2010-02-11T13:00:49+01:00 vu39198 MSWinEventLog 1 Security 490 Thu Feb 11 13:00:27 2010 540 Security ANONYMOUS LOGON Well Known Group Success Audit vuxxxx8 Logon/Logoff  Successful Network Logon:   #011User Name:#011    #011Domain:#011#011    #011Logon ID:#011#011(0&#215;0,0&#215;34D6D1C)    #011Logon Type:#0113    #011Logon Process:#011NtLmSsp     #011Authentication Package:#011NTLM    #011Workstation Name:#011    #011Logon GUID:#011-   473</p>
<p>But the complete message is only available in the &#8220;Message&#8221; column. Nothing in Severity, Eventlog Type and so on. Can you help me ?</p>
<p>Maybe change the delimiter from SNARE ? br cnu</p>
]]></content:encoded>
	</item>
</channel>
</rss>
