<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>An It-Slave in the digital saltmine &#187; op5 Logserver</title>
	<atom:link href="http://www.it-slav.net/blogs/category/op5-logserver/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.it-slav.net/blogs</link>
	<description>Another Blog from a Geek that has no life</description>
	<lastBuildDate>Fri, 02 Jul 2010 07:33:08 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>op5 bugtracker online and open for registration</title>
		<link>http://www.it-slav.net/blogs/2009/10/02/op5-bugtracker-online-and-open-for-registration/</link>
		<comments>http://www.it-slav.net/blogs/2009/10/02/op5-bugtracker-online-and-open-for-registration/#comments</comments>
		<pubDate>Fri, 02 Oct 2009 11:38:24 +0000</pubDate>
		<dc:creator>peter</dc:creator>
				<category><![CDATA[op5]]></category>
		<category><![CDATA[op5 Logserver]]></category>
		<category><![CDATA[op5 Monitor]]></category>
		<category><![CDATA[op5 Statistics]]></category>
		<category><![CDATA[merlin]]></category>
		<category><![CDATA[ninja]]></category>

		<guid isPermaLink="false">http://www.it-slav.net/blogs/?p=1385</guid>
		<description><![CDATA[https://bugs.op5.com/ is now also open for external users to sign up. By signing up you can post bug and feature requests, post bug-notes etc.

Before doing so, please check out the &#34;How to Submit Bug/Feature&#34; documentation available from within the bug tracker.

Note: op5 opensource projects Merlin, Ninja and Nacoma are for now available as categories on [...]]]></description>
			<content:encoded><![CDATA[<pre wrap=""><a href="https://bugs.op5.com/" class="moz-txt-link-freetext">https://bugs.op5.com/</a> is now also open for external users to sign up. By signing up you can post bug and feature requests, post bug-notes etc.

Before doing so, please check out the &quot;How to Submit Bug/Feature&quot; documentation available from within the bug tracker.

Note: op5 opensource projects Merlin, Ninja and Nacoma are for now available as categories on Project: op5 Monitor, it's simply to make it easy for us to show a product roadmap/changelog although it might be a bit &quot;unlogical&quot; for people using only Merlin.</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.it-slav.net/blogs/2009/10/02/op5-bugtracker-online-and-open-for-registration/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Teledemo: op5 Products presented by Collax</title>
		<link>http://www.it-slav.net/blogs/2009/04/21/teledemo-op5-products-presented-by-collax/</link>
		<comments>http://www.it-slav.net/blogs/2009/04/21/teledemo-op5-products-presented-by-collax/#comments</comments>
		<pubDate>Tue, 21 Apr 2009 12:05:18 +0000</pubDate>
		<dc:creator>peter</dc:creator>
				<category><![CDATA[Hints]]></category>
		<category><![CDATA[Links]]></category>
		<category><![CDATA[op5]]></category>
		<category><![CDATA[op5 Logserver]]></category>
		<category><![CDATA[op5 Monitor]]></category>
		<category><![CDATA[op5 Statistics]]></category>
		<category><![CDATA[Collax]]></category>

		<guid isPermaLink="false">http://www.it-slav.net/blogs/?p=982</guid>
		<description><![CDATA[I will be running a demo of op5 products at thursday April 23:th 16:00 CET.
The demo is hosted by Collax a op5 partner in Germany.

If you want to attend, register at:
http://www.collax.com/de/ueber-collax/events-collax-live/webcast-collax-monitoring-solution.html
]]></description>
			<content:encoded><![CDATA[<p>I will be running a demo of op5 products at thursday April 23:th 16:00 CET.</p>
<p>The demo is hosted by <a href="http://www.collax.com">Collax</a> a op5 partner in Germany.</p>
<p><br class="spacer_" /></p>
<p>If you want to attend, register at:</p>
<p><a href="http://www.collax.com/de/ueber-collax/events-collax-live/webcast-collax-monitoring-solution.html" target="_blank">http://www.collax.com/de/ueber-collax/events-collax-live/webcast-collax-monitoring-solution.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-slav.net/blogs/2009/04/21/teledemo-op5-products-presented-by-collax/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Minor release of op5 LogServer 3.4</title>
		<link>http://www.it-slav.net/blogs/2009/03/10/minor-release-of-op5-logserver-34/</link>
		<comments>http://www.it-slav.net/blogs/2009/03/10/minor-release-of-op5-logserver-34/#comments</comments>
		<pubDate>Tue, 10 Mar 2009 16:12:55 +0000</pubDate>
		<dc:creator>peter</dc:creator>
				<category><![CDATA[english]]></category>
		<category><![CDATA[op5]]></category>
		<category><![CDATA[op5 Logserver]]></category>

		<guid isPermaLink="false">http://www.it-slav.net/blogs/?p=868</guid>
		<description><![CDATA[Today we release op5 LogServer 3.4, a minor release containing the following features and fixes.

Code refactoring and bug fixes
Possibility to turn on and off full text indexing
Speed and robustness improvements to the query logic



 Code refactoring and bug fixes
Over time as a project grows there comes need for refactoring. In this release we have refactored [...]]]></description>
			<content:encoded><![CDATA[<p>Today we release op5 LogServer 3.4, a minor release containing the following features and fixes.</p>
<ul>
<li><a title="code refactoring and bug fixes" href="#code refactoring">Code refactoring and bug fixes</a></li>
<li><a title="Possibility to turn on and off full text indexing" href="#indexing">Possibility to turn on and off full text indexing</a></li>
<li><a title="Speed and robustness improvements to the query logic" href="#query">Speed and robustness improvements to the query logic</a></li>
</ul>
<p><span id="more-868"></span></p>
<h3><a title="code refactoring" name="code refactoring"></a><br />
 Code refactoring and bug fixes</h3>
<p>Over time as a project grows there comes need for refactoring. In this release we have refactored parts of the code to improve stability and maintainability. For example front-end controller design pattern was introduced in this release, which gave us the possibility to both improve security and simplify code. We fixed a possible message sorting issue and merged a couple of packages to simplify maintenance.</p>
<p><a title="indexing" name="indexing"></a></p>
<h3>Possibility to turn on and off full text indexing</h3>
<p>In op5 LogServer a user has 2 options for search in logs: one is the &#8216;host=test-host&#8217; kind of search and the other is the full-text search &#8211; the &#8216;test-host&#8217; kind of search, i.e. it just searches the whole log message for whatever you type. By default we create an index for full text search, that makes the full text search queries speedier. In some environments full text indexing of log messages are not really a good thing. For example if you have a lot of log messages from a firewall consisting messages that contains a lot of “non words”, binary data dumps and such. Log messages like that can hog your CPU<br />
 and affect the responsiveness of the op5 LogServer system.</p>
<p>You can now chose if you want to use full text indexing or not by a configurable setting in the GUI.</p>
<p><strong>Note:</strong> If you turn off the full text index, searches using full text search will be slower.<br />
 <a title="query" name="query"></a></p>
<h3>Speed and robustness improvements to the query logic</h3>
<p>Every search traverses the database by hour and ask it to return log messages up to the requested amount of matches, i.e. depending on how many messages you have chosen to view on the page. When the result of one hour is returned the query logic determines if it should query the database for another hour and also how many more matches that are required. This<br />
 gives us a more precise result.</p>
<p>This also leads us to a number of changes:</p>
<ul>
<li>&#8220;Unlimited search&#8221; mode as a special case is deprecated – now all the searches are done across all the DB</li>
<li>The green line in the timeline now shows the time frame where the search was done to find the present results, even covering multiple days.</li>
<li>The user can now stop the search (system will finish the search in current hour still – and then will stop)</li>
<li>The interaction with the database is more clean and a number of possible deadlocks are eliminated. </li>
</ul>
<h3>Installation and Upgrade Notes</h3>
<p>Upgrading requires op5 LogServer 3.0 or later. Upgrade is possible either by using yum or by using the .tar.gz install file available at <a title="support" href="/support/">http://www.op5.com/support/</a>.</p>
<h3>Documentation</h3>
<p>Documentation for version 3.4 of op5 LogServer is available at <a title="support" href="/support/">http://www.op5.com/support/</a></p>
<h3>Screenshots</h3>
<p><!-- JW "Simple Image Gallery PRO" Plugin (v1.2) starts here --></p>
<div class="sig_cont">
<div class="sig_thumb"><a class="thickbox" title="&lt;b&gt;Group Administration &lt;/b&gt;" rel="gb_imageset[sig0_f5fbffdd5234bfd51d7fd00ccaa1ec4a]" href="http://www.op5.com/op5media/op5/images/screenshots/logserver3.4/logserver_group_administration.gif" target="_blank"><img title="Click image to view" src="http://www.op5.com/op5media/temp/f92a8532501ef40157b38824207aa4a4.gif" alt="Click image to view" /></a></div>
</div>
<div class="sig_cont">
<div class="sig_thumb"><a class="thickbox" title="&lt;b&gt;Help &lt;/b&gt;" rel="gb_imageset[sig0_f5fbffdd5234bfd51d7fd00ccaa1ec4a]" href="http://www.op5.com/op5media/op5/images/screenshots/logserver3.4/logserver_help.gif" target="_blank"><img title="Click image to view" src="http://www.op5.com/op5media/temp/254670e869d1ed22342084335827022b.gif" alt="Click image to view" /><span class="sig_caption" style="width: 196px;" title="Click image to view"> </span></a></div>
</div>
<div class="sig_cont">
<div class="sig_thumb"><a class="thickbox" title="&lt;b&gt;Log Data &lt;/b&gt;" rel="gb_imageset[sig0_f5fbffdd5234bfd51d7fd00ccaa1ec4a]" href="http://www.op5.com/op5media/op5/images/screenshots/logserver3.4/logserver_logdata.gif" target="_blank"><img title="Click image to view" src="http://www.op5.com/op5media/temp/49a8802901828ac80bcdd08748a96430.gif" alt="Click image to view" /></a></div>
</div>
<div class="sig_cont">
<div class="sig_thumb"><a class="thickbox" title="&lt;b&gt;Manage Permissions &lt;/b&gt;" rel="gb_imageset[sig0_f5fbffdd5234bfd51d7fd00ccaa1ec4a]" href="http://www.op5.com/op5media/op5/images/screenshots/logserver3.4/logserver_manage_permissions.gif" target="_blank"><img title="Click image to view" src="http://www.op5.com/op5media/temp/526bc2c580ba9a19f2cfa90f739bccaa.gif" alt="Click image to view" /></a></div>
</div>
<div class="sig_cont">
<div class="sig_thumb"><a class="thickbox" title="&lt;b&gt;Portal Page 	 &lt;/b&gt;" rel="gb_imageset[sig0_f5fbffdd5234bfd51d7fd00ccaa1ec4a]" href="http://www.op5.com/op5media/op5/images/screenshots/logserver3.4/logserver_portal_page.gif" target="_blank"><img title="Click image to view" src="http://www.op5.com/op5media/temp/b2a7d34049d202f744fc7e8ad903aa09.gif" alt="Click image to view" /></a></div>
</div>
<p><a class="thickbox" title="&lt;b&gt;Query Builder &lt;/b&gt;" rel="gb_imageset[sig0_f5fbffdd5234bfd51d7fd00ccaa1ec4a]" href="http://www.op5.com/op5media/op5/images/screenshots/logserver3.4/logserver_query_builder.gif" target="_blank"><img title="Click image to view" src="http://www.op5.com/op5media/temp/349dbd759d4f643d7a87c4a9527d679c.gif" alt="Click image to view" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-slav.net/blogs/2009/03/10/minor-release-of-op5-logserver-34/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>op5 Logserver 3.3.0 is released</title>
		<link>http://www.it-slav.net/blogs/2008/12/16/op5-logserver-330-is-released/</link>
		<comments>http://www.it-slav.net/blogs/2008/12/16/op5-logserver-330-is-released/#comments</comments>
		<pubDate>Tue, 16 Dec 2008 13:03:46 +0000</pubDate>
		<dc:creator>peter</dc:creator>
				<category><![CDATA[english]]></category>
		<category><![CDATA[op5]]></category>
		<category><![CDATA[op5 Logserver]]></category>
		<category><![CDATA[sysadmin]]></category>

		<guid isPermaLink="false">http://www.it-slav.net/blogs/?p=518</guid>
		<description><![CDATA[op5 are proud to announce that op5 have released op5 Logserver 3.3.0
This is a minor upgrade.
Whats new?

Summary Reports
Bidirectional editing of filters
Hierarchical filters
Configurable deafult filter per user
Bugfixes

Read more about it in the release-notes and changelog
]]></description>
			<content:encoded><![CDATA[<p>op5 are proud to announce that op5 have released op5 Logserver 3.3.0</p>
<p>This is a minor upgrade.</p>
<p>Whats new?</p>
<ul>
<li>Summary Reports</li>
<li>Bidirectional editing of filters</li>
<li>Hierarchical filters</li>
<li>Configurable deafult filter per user</li>
<li>Bugfixes</li>
</ul>
<p>Read more about it in the <a href="http://www.op5.com/support/release-information/release-notes/doc_download/229-op5-logserver-33-release-notes-">release-notes</a> and <a href="http://www.op5.com/support/release-information/change-logs/op5-logserver-change-log">changelog</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.it-slav.net/blogs/2008/12/16/op5-logserver-330-is-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Howto Integrate op5 Monitor with op5 Logserver</title>
		<link>http://www.it-slav.net/blogs/2008/11/25/howto-integrate-op5-monitor-with-op5-logserver/</link>
		<comments>http://www.it-slav.net/blogs/2008/11/25/howto-integrate-op5-monitor-with-op5-logserver/#comments</comments>
		<pubDate>Tue, 25 Nov 2008 19:21:06 +0000</pubDate>
		<dc:creator>peter</dc:creator>
				<category><![CDATA[Hints]]></category>
		<category><![CDATA[english]]></category>
		<category><![CDATA[op5]]></category>
		<category><![CDATA[op5 Logserver]]></category>
		<category><![CDATA[op5 Monitor]]></category>
		<category><![CDATA[sysadmin]]></category>

		<guid isPermaLink="false">http://www.it-slav.net/blogs/?p=344</guid>
		<description><![CDATA[This guide is a step by step guide howto integrate op5 Monitor with op5 Logserver.
Background
I would like to have an alert if root has logged into my firewall. I think this is very important to know fast and where ever I am so I want a SMS sent to my cellphone. I have op5 Monitor [...]]]></description>
			<content:encoded><![CDATA[<p>This guide is a step by step guide howto integrate op5 Monitor with op5 Logserver.</p>
<h3>Background</h3>
<p>I would like to have an alert if root has logged into my firewall. I think this is very important to know fast and where ever I am so I want a SMS sent to my cellphone. I have op5 Monitor with a GSM modem.</p>
<h3>Theory</h3>
<p>When root login a message will show up in the syslog i.e. /var/log/authlog</p>
<pre>Nov 19 15:55:58 pedro sshd[12180]: Accepted password for root from 192.168.0.153 port 35896 ssh2
</pre>
<p>So I want op5 Monitor to detect this message in syslog and send a SMS if it occours.</p>
<p><span id="more-344"></span></p>
<p>The steps are:</p>
<ul>
<li>Send the message to op5 Logserver</li>
<li>Create a filter that filter out that message</li>
<li>Make op5 Monitor run this filter and send an alarm if it gets a hit.</li>
</ul>
<p><br class="spacer_" /></p>
<h3>Implementation</h3>
<p>1-First step is to have a working op5 Logserver that get this message. I assume that a op5 Logserver is installed and configured in this guide.</p>
<p>In /etc/syslogd.conf I have the following line:</p>
<pre>*.*                                                     @op5
</pre>
<p>It tells syslog to send every message to host op5, in this case it is my op5 Logserver, op5 Monitor and op5 Statistics machine. This is not recommended but my environment is very small.</p>
<p>2-Log in to op5 Logserver and verify that your login has been stored.</p>
<p>&#8220;Query builder&#8221;, enter  in Host box, enter &#8220;Accepted password for root&#8221; in message.</p>
<p><a href="http://www.it-slav.net/blogs/wp-content/uploads/2008/11/logserver_queryfilter.png"><img class="alignnone size-full wp-image-355" title="logserver_queryfilter" src="http://www.it-slav.net/blogs/wp-content/uploads/2008/11/logserver_queryfilter.png" alt="" width="500" height="312" /></a></p>
<p>3-Save the filter with a good name i.e. root_login_fw</p>
<p>4-Test that op5 Monitor can and detect the message</p>
<pre>[root@op5 plugins]# ./check_ls_log -f root_login_fw -i 60 -c 0
CRITICAL - 1 matches for general filter 'root_login_fw':Accepted password for root from 192.168.0.153 port 35896 ssh2|query_time=0.05ms nr_matches=1;5;0
</pre>
<p>-f is filtername</p>
<p>-i is minutes back it should query the database</p>
<p>It works!</p>
<address>note:If you have your logserver running on an another host, which should be the normal case, use -H  -l  -p .</address>
<p>5-Create the op5 Monitor Service check on your firewall</p>
<p>Login to op5 Monitor</p>
<p>Click Configure</p>
<p>Pick the firewall in the list of hosts</p>
<p>Click Go</p>
<p>Click &#8220;Services for fw&#8221;</p>
<p>Pick &#8220;Add new service&#8221;, Click Go</p>
<p>Enter &#8220;Root Login&#8221; in Service Description</p>
<p>check_ls_log in check_command</p>
<p>check_command_args -f root_login_fw -i 60 -c 0</p>
<p>Enter the contact information.</p>
<p>Press Apply</p>
<p>Press &#8220;Test this service&#8221; to verify that it works</p>
<p>Press Save and you are done.</p>
<p>6-If you have logged in recently it should look something like this when looking att you service:</p>
<p><a href="http://www.it-slav.net/blogs/wp-content/uploads/2008/11/logserverfinal.png"><img class="alignnone size-full wp-image-359" title="logserverfinal" src="http://www.it-slav.net/blogs/wp-content/uploads/2008/11/logserverfinal.png" alt="" width="500" height="312" /></a></p>
<address>Hint: Before you login to your firewall, do not forget to schedule downtime for this service. Otherwise you will get an SMS alerts and your availability reports will get effected. <br />
 </address>
<p>Links:</p>
<ul>
<li><a href="http://www.op5.com" target="_blank">op5</a></li>
<li><a href="http://www.op5.com/op5/products/monitor" target="_blank">op5 Monitor</a></li>
<li><a href="http://www.op5.com/op5/products/logserver" target="_blank">op5 Logserver</a></li>
<li><a href="http://www.op5.com/support/technical-information/how-to/324-monitor-to-logserver-integration" target="_blank">op5 How-To integrate to logserver integration</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.it-slav.net/blogs/2008/11/25/howto-integrate-op5-monitor-with-op5-logserver/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
