FAQ

Performance Tests and Results

Determining the overall performance of a tool is not an easy task. Adiscon sometimes gets asked what the actual performance values for products like WinSyslog and MonitorWare Agent are, especially the processing rate of received syslog messages. This cannot be answered easily, because there are a lot of factors to be considered. Here are the … Continue reading "Performance Tests and Results" ...

Questions about Queues

Is the queue limit applied to all services or per service? The queue limit is for all services combined. Be it a syslog listener, eventlog or file monitor. It does not differ between services, the memory queue is for all. The queue is basically to buffer message bursts that are higher than what MonitorWare Agent … Continue reading "Questions about Queues" ...

How to perform a mass rollout?

How to perform a mass rollout? Last Update 2013-01-02 by Florian Riedl A mass rollout in the scope of this topic is any case where the product is rolled out to more than 5 to 10 machines and this rollout is to be automated. This is described first in this article. A special case may … Continue reading "How to perform a mass rollout?" ...

How can I get rid of control characters and linefeeds?

How can I get rid of control characters and linefeeds? Created 2011-02-17 by Florian Riedl Some syslog sources create strange message formats. In many cases, this is of no concern. In other cases, this can disturb reviewing logs. For example, if you are using the InterActive SyslogViewer, control characters in the message create strange placeholder … Continue reading "How can I get rid of control characters and linefeeds?" ...

FAQ – MonitorWare Agent

Frequently Asked Questions Some things are simply often asked. Here we provide the answers! So it is a good idea to check this area if you run into queries. ...

How to perform a mass update rollout?

How to perform a mass update rollout? Created 2008-10-10 by Florian Riedl A mass rollout in the scope of this topic is any case where the product is rolled out to more than 5 to 10 machines and this rollout is to be automated. This is described in detail in the Article How to perform … Continue reading "How to perform a mass update rollout?" ...

How to get MonitorWare Agent 4.4 working on Windows NT4?

How to get MonitorWare Agent 4.4 working on Windows NT4? Created 2008-02-28 by Andre Lorbach The last official version of MWAgent which is supported on Windows NT4 is version 3.1 Build 292. Due to customer requests, we have created a special build of MonitorWare Agent version 4.4a which will also work on Windows NT4. However … Continue reading "How to get MonitorWare Agent 4.4 working on Windows NT4?" ...

Is SMS-alerting possible with a GSM modem and the Send to Communications Port-Action?

Is SMS-alerting possible with a GSM modem and the Send to Communications Port-Action? Created 2008-02-13 by Florian Riedl. Which tools to use … Every of our products (EventReporter, MonitorWare Agent and WinSyslog) contain a action which is able to send messages to the communications port of the PC. The question is, if it is possible, … Continue reading "Is SMS-alerting possible with a GSM modem and the Send to Communications Port-Action?" ...

Default Timevalues Setting in EventReporter/MonitorWare Agent/WinSyslog explained.

Default Timevalues Setting in EventReporter/MonitorWare Agent/WinSyslog explained. Created 2008-01-24 by Andre Lorbach. The general options of each product (EventReporter, MonitorWare Agent and WinSyslog) contain a setting for the “Default Timevalues”. This setting can be set to Localtime and UTC (Universal Coordinated Time) which is default. If you switch this setting to Localtime, you may wounder … Continue reading "Default Timevalues Setting in EventReporter/MonitorWare Agent/WinSyslog explained." ...

How To Enter the License Information

How To Enter the License Information Article created 2007-06-13 by Florian Riedl This article describes how to enter the license information you received via mail by buyingone of our products. The Article is applicable to EventReporter, MonitorWare Agent and WinSyslog and other products. ...

How to use Stored Procedures with ‘write database’?

How to use Stored Procedures with ‘write database’? Created 2007-05-08 by Rainer Gerhards. EventReporter, MonitorWare Agent and WinSyslog support stored procedures in their ‘write database’ actions. This option is supported for Microsoft SQL Server only. With other database systems, it might work, but Adiscon does not guarantee it. Stored procedures are used just like database … Continue reading "How to use Stored Procedures with ‘write database’?" ...

Can I use the old EventLog Monitor with Vista?

Can I use the old EventLog Monitor with Vista? Created 2007-04-18 by Florian Riedl. Windows Vista available since early 2007. Due to the changes Microsoft introduced with Vista, the procedure for monitoring event logs with the non-Vista event log monitor has changed.  Adiscon introduced the native Vista EventLog Monitor V2 which requires no specific prerequisites. … Continue reading "Can I use the old EventLog Monitor with Vista?" ...

I get format message errors (code 317). What does this mean?

I get format message errors (code 317). What does this mean? Created 2007-04-10 by Florian Riedl. You can come across this specific error, by reviewing your EventLog data. The EventLog Monitor writes an entry to the EventLog and then retries. If debug is activated, a entry will be created there, too, looking like this: “2212 … Continue reading "I get format message errors (code 317). What does this mean?" ...

Which Event Log Monitor to use for Vista?

Which Event Log Monitor to use for Vista? Created 2007-04-10 by Rainer Gerhards. Starting with EventReporter 8.3 and MonitorWare Agent 4.3 two different event log monitor services are provided. They are called “Event Log Monitor” (V1) and “Event Log Monitor V2”. In short, the V2 version is recommended for Windows Vista (and above, e.g. Longhorn … Continue reading "Which Event Log Monitor to use for Vista?" ...

Database Formats

Database Formats These sample here implement the MonitorWare Common Database Format in widely used database systems. Attention Sybase users: the “Message” name is reserved in your database system and cannot be used as a field name. It needs to be changed, otherwise the table create will fail. Be sure to also change it in to … Continue reading "Database Formats" ...

To what extent MonitorWare Agent 4.x / WinSyslog 7.x Support SNMP?

To what extent MonitorWare Agent 4.x / WinSyslog 7.x Support SNMP? Created 2007-01-30 by Florian Riedl. I am using MonitorWare Agent 4.x / WinSyslog 7.x on my NT Server. To what extent MonitorWare Agent 4.x / WinSyslog 7.x Support SNMP? MonitorWare Agent and WinSyslog are capable of either sending or receiving SNMP Traps. Usually SNMP … Continue reading "To what extent MonitorWare Agent 4.x / WinSyslog 7.x Support SNMP?" ...

How to run MonitorWareLine Products on Windows Cluster Servers?

How to run MonitorWareLine Products on Windows Cluster Servers? Created 2006-07-17 by Timm Herget You want to run i.e. WinSyslog on a Windows 2003 Cluster but you are not sure if it will work properly on this platform and if there are any particular issues to be aware of in this configuration? In our sample, … Continue reading "How to run MonitorWareLine Products on Windows Cluster Servers?" ...

MonitorWare Agent 4.x – Database Structure

MonitorWare Agent 4.x – Database Structure Created 2003-05-05 by Wajih-ur-Rehman. Last Updated 2006-06-21 by Timm Herget. What is the new Database Structure for MonitorWare Agent 4.x? The Database Structure for MonitorWare Agent 4.x is almost the same as that of the older versions with the exception of SystemEventsProperties Table which is new in this new … Continue reading "MonitorWare Agent 4.x – Database Structure" ...

What is the log file format for generating reports with Monilog for MonitorWare Agent, WinSyslog and EventReporter?

What is the log file format for generating reports with Monilog for MonitorWare Agent, WinSyslog and EventReporter? Created 2006-06-20 by Timm Herget I am using MonitorWare Agent 4.x / EventReporter 8.x / WinSyslog 7.x What are the settings that I would have to make such that the log file is generated in a format that … Continue reading "What is the log file format for generating reports with Monilog for MonitorWare Agent, WinSyslog and EventReporter?" ...

How to store custom properties of a log message in a database

How to store custom properties of a log message in a database Created 2006-03-27 by Timm Herget This step-by-step guide describes a scenario where WinSyslog receives syslog data from a Fortigate firewall, parses the messages via post processing action and writes the custom parsed properties into a database. Step 1 – Creating the Syslog Server … Continue reading "How to store custom properties of a log message in a database" ...

How to process Syslog messages from Solaris 8/9 systems?

How to process Syslog messages from Solaris 8/9 systems? Created 2006-03-15 by Andre Lorbach. This article describes how to workaround problems which occur when you are receiving and processing Syslog messages from Solaris 8/9 systems. The Problem: The problem exists in the way, the Syslog messages are formatted from Solaris 8/9. As an example, we … Continue reading "How to process Syslog messages from Solaris 8/9 systems?" ...

Can Event Reporter work with custom event logs / evt-files?

Can Event Reporter work with custom event logs / evt-files? Created 2006-02-15 by Timm Herget There are 2 FAQ Articles available regarding this question because it is different if you want to monitor custom event logs or custom *.evt files. Please see the links below for further information about this: Can EventReporter read Custom EventLogs? … Continue reading "Can Event Reporter work with custom event logs / evt-files?" ...

Why does the Client remain at the older version after “successfully” upgrading to newer version?

Why does the Client remain at the older version after “successfully” upgrading to newer version? Created 2005-11-09 by Timm Herget Do you experience a problem similar to the following? – After the upgrade, the client reported to have updated the service to 7.x but the client was still version 6.x. Then you are right here. … Continue reading "Why does the Client remain at the older version after “successfully” upgrading to newer version?" ...

What is the log file format for generating reports with Monilog?

What is the log file format for generating reports with Monilog? Created 2005-08-02 by Timm Herget What are the settings that I would have to make such that the log file is generated in a format that is acceptable to Monilog? There are a few things that have to be set in order to generate … Continue reading "What is the log file format for generating reports with Monilog?" ...

WMI returns 98 percent value while querying LoadPercentage property in Windows 2000. What about this issue?

WMI returns 98 percent value while querying LoadPercentage property in Windows 2000. What about this issue? Created 2005-06-23 by Hamid Ali Raja The CPU monitor of MonitorWare Agent uses the Windows WMI System to query the CPU and memory related information from system. On Windows 2000, there is a known Windows Management Instrumentation (WMI) bug … Continue reading "WMI returns 98 percent value while querying LoadPercentage property in Windows 2000. What about this issue?" ...

Export settings to a registry file

Export settings to a registry file Created        2005-06-14 by Hamid Ali Raja Last Updated 2006-04-27 by Timm Herget How can I export my settings to a registry file? To export your settings to a registry file, please do the steps described below. Please note that you do NOT use the binary registryfile export-option! Step … Continue reading "Export settings to a registry file" ...

Nextel to Receive Emails

Nextel to Receive Emails Created 2005-04-26 by Hamid Ali Raja I am using Nextel services. Is it possible to receive MonitorWare Alerts on my mobile device? If you are enjoying Nextel services, you can use your mobile devices to receive alerts and emails from MonitorWare Products. You just specify your email using the Nextel phone … Continue reading "Nextel to Receive Emails" ...

Enabling Security Auditing

Enabling Security Auditing Created 2005-03-30 by Hamid Ali Raja. My application is not logging security events. What can be done? Sometimes EventReporter or MonitorWare Agent is not logging your security events. It may be because of the fact that security auditing is disabled in the Windows security policies. To enable the Security Auditing, please follow … Continue reading "Enabling Security Auditing" ...

Hardware Configurations for Receiving Messages

Hardware Configurations for Receiving Messages Created 2004-12-08 by Hamid Ali Raja I want to receive messages from various sources on my central server. What should be the hardware configurations for it? It depends on the average and expected number of messages that each of the devices will generate. In general, you can write the syslog … Continue reading "Hardware Configurations for Receiving Messages" ...

Authentication problem while using MySQL Version 4.X

Authentication problem while using MySQL Version 4.X Created 2004-11-11 by Hamid Ali Raja I am facing problem while writing to MySQL 4.X database using Write to Database action. What should I do? This issue is related to MySQL authentication protocol built in MySQL 4.1 and above versions. This protocol is based on password hashing algorithm … Continue reading "Authentication problem while using MySQL Version 4.X" ...

Which Product Should I Purchase?

Which Product Should I Purchase? Created 2003-02-16 by Wajih-ur-Rehman. Updated 2004-09-09 by Tamsila-Q-Siddique. 1. Overview This article gives an overview of MonitorWare Line of Products and provides a guideline to select the right product. This article discusses EventReporter, MonitorWare Agent, WinSyslog, MonitorWare Console, Monilog and AliveMon. MonitorWare Agent, WinSyslog and EventReporter work on common concepts … Continue reading "Which Product Should I Purchase?" ...

How can I send my configuration in a support case?

How can I send my configuration in a support case? Created 2004-07-15 by Tamsila-Q-Siddique. I am using MonitorWare Agent / WinSyslog / EventReporter. How can I send the current configuration for a incident? When working on a support incident, it is often extremely helpful to re-create a customer environment in the Adiscon lab. To aid … Continue reading "How can I send my configuration in a support case?" ...

What is the recommended order of Stopping MonitorWare Agent / EventReporter / WinSyslog Service?

What is the recommended order of Stopping MonitorWare Agent / EventReporter / WinSyslog Service? Created 2004-07-08 by Tamsila-Q-Siddique. I have MonitorWare Agent / EventReporter / WinSyslog Service on my W2K machine. And I am using Online Viewer with MSSQL as the backend. I have to reboot the machine after automatic updates for the OS or … Continue reading "What is the recommended order of Stopping MonitorWare Agent / EventReporter / WinSyslog Service?" ...

How can I make Event ID part of the actual Syslog message while forwarding to a Syslog Server?

How can I make Event ID part of the actual Syslog message while forwarding to a Syslog Server? Created 2004-06-24 by Tamsila-Q-Siddique. We are using MonitorWare Agent / EventReporter to forward Windows Event logs to a Syslog Server. The resulting syslog message doesn’t have the Event IDs in them. How can we make Event ID … Continue reading "How can I make Event ID part of the actual Syslog message while forwarding to a Syslog Server?" ...

System Requirements for Monitoring NetWare Files

System Requirements for Monitoring NetWare Files Created on 2003-08-08 by Rainer Gerhards. Updated on 2004-06-16 by Tamsila-Q-Siddique. MonitorWare Agent needs to access files on NetWare via an UNC share. It is known that some versions of the Novell and/or Microsoft software have some issues with services accessing files on a UNC share on NetWare. Microsoft … Continue reading "System Requirements for Monitoring NetWare Files" ...

Why does the File Monitor Service experience difficulties when accessing files located on a NetWare Server?

Why does the File Monitor Service experience difficulties when accessing files located on a NetWare Server? Created 2004-06-16 by Tamsila-Q-Siddique. I am attempting to watch files on a NetWare Server. On my W2K machine MonitorWare Agent can monitor files on itself wonderfully but it will not monitor files on the NetWare Server. We are receiving … Continue reading "Why does the File Monitor Service experience difficulties when accessing files located on a NetWare Server?" ...

Why do I get “Type Mismatch” or “Page Not Found” Error when using the Online Web Access Viewer?

Why do I get “Type Mismatch” or “Page Not Found” Error when using the Online Web Access Viewer? Created 2004-06-15 by Tamsila-Q-Siddique I have verified all the settings in the “ConfigSettings.asp” page and it looks fine. All Permissions are granted. But when I access the Online Web Access Viewer the “Type Mismatch” or “Page Not … Continue reading "Why do I get “Type Mismatch” or “Page Not Found” Error when using the Online Web Access Viewer?" ...

Why does the Port Probe Service Fails?

Why does the Port Probe Service Fails? Created 2004-06-15 by Tamsila-Q-Siddique I have configured a PortProbe Service to check for activity of the SMTP Service on our mail server. MonitorWare Agent has full Internet access and I am not using any proxy servers or DNS-aliases for the mailserver. The PortProbe service is running but it … Continue reading "Why does the Port Probe Service Fails?" ...

How to forward the messages with the original IP in the header instead of sender’s IP address?

How to forward the messages with the original IP in the header instead of sender’s IP address? Created 2004-06-14 by Tamsila-Q-Siddique We are forwarding some of Syslog messages using WinSyslog / MonitorWare Agent, but when the message shows up at the other location, it appears with the forwarding servers IP address instead of the originating … Continue reading "How to forward the messages with the original IP in the header instead of sender’s IP address?" ...

How to avoid “file already in use” error in the Online Web Access Viewer?

How to avoid “file already in use” error in the Online Web Access Viewer? Created 2004-05-27 by Michael Meckelein. You often get an error “file already in use” if you use the Online Web Access Viewer together with a MS Access database. The message you get look like this one: AccessMicrosoft OLE DB Provider for … Continue reading "How to avoid “file already in use” error in the Online Web Access Viewer?" ...

Why does the Online Web Access Viewer displays wrong page reference?

Why does the Online Web Access Viewer displays wrong page reference? Created 2004-04-23 by Tamsila-Q-Siddique I am using MySQL as the underline database. The online web access viewer only displays 1 page of records even though there are 100 or more records. The page reference in the upper right hand corner says “Page 1 of … Continue reading "Why does the Online Web Access Viewer displays wrong page reference?" ...

Forwarding IIS Logs to a central File

Forwarding IIS Logs to a central File Created 2004-04-02 by Timm Herget and Rainer Gerhards. I would like to centralize IIS log files to a central log server. The files on that central server should be in the exact same format they are on the IIS machines. This can be done with MonitorWare Agent 2.0 … Continue reading "Forwarding IIS Logs to a central File" ...

How can I use a second sound card with the Play Sound Action?

How can I use a second sound card with the Play Sound Action? Created 2004-03-25 by Tamsila-Q-Siddique I have got a second sound card on my machine, how can I use it with the Play Sound Action? PlaySounds action plays a sound on the local machine. It is possible to play wave files and some … Continue reading "How can I use a second sound card with the Play Sound Action?" ...

How to install MonitorWare Agent in silent mode?

How to install MonitorWare Agent in silent mode? Created on by Andre Lorbach. Because MonitorWare Agent is using the Windows Installer (MSIE) it is very easy to start the Installation in silent mode. There are two ways to do it. 1. Using the MonitorWare Agent msi-file (Only possible if Windows Installer version 2.0 is installed … Continue reading "How to install MonitorWare Agent in silent mode?" ...

How can I copy the current configuration to the other servers?

How can I copy the current configuration to the other servers? Created 2004-01-26 by Tamsila-Q-Siddique I have got “x” number of copies of EventReporter, MonitorWare Agent or Winsyslog. How can I copy the current configuration to the other servers so we can save time? I want to copy all of the services and rulesets I’ve … Continue reading "How can I copy the current configuration to the other servers?" ...

Do I need a new Key for an Upgrade?

Do I need a new Key for an Upgrade? Created 2004-01-23 by Tamsila-Q-Siddique Will the same key work when I upgrade from 1.x version to 2.x version? You can use this license key for any 1.x version of MonitorWare Agent. But this license key will not work if you want to upgrade from 1.x to … Continue reading "Do I need a new Key for an Upgrade?" ...

What does Event ID 1011 mean?

What does Event ID 1011 mean? Created 2004-01-16 by Tamsila-Q-Siddique What does event 1011 mean? Our MonitorWare Line of Products e.g. EventReporter, MonitorWare Agent etc. periodically reads the Windows Event Log. While reading the Windows Event Log, they try to read the last record that was processed in the last run. We had opt for … Continue reading "What does Event ID 1011 mean?" ...

What is the difference between MonitorWare Agent Workstation and Server?

What is the difference between MonitorWare Agent Workstation and Server? Created 2004-01-13 by Rainer Gerhards What is the difference between MonitorWare Agent Workstation (WS) and Server (SRV)? The basic difference is based on the operating system the product runs on. If it is a workstations operating system like Windows XP, you need MonitorWare Agent Workstation. … Continue reading "What is the difference between MonitorWare Agent Workstation and Server?" ...

Timestamp in field “ReceivedAt” and “DeviceReportedTime” stored in the database is wrong ?

Timestamp in field “ReceivedAt” and “DeviceReportedTime” stored in the database is wrong ? Updated 2003-12-05 by Tamsila-Q-Siddique The local PC-Time and other reported device time is correct but the the time stamp in “RecievedAt” and “DeviceReportedTime” field stored in the database is wrong ? The time in field “ReceivedAt” and “DeviceReportedTime” which is stored in … Continue reading "Timestamp in field “ReceivedAt” and “DeviceReportedTime” stored in the database is wrong ?" ...

Does UNC Pathes work for WinSyslog, EventReporter and MonitorWare Agent ?

Does UNC Pathes work for WinSyslog, EventReporter and MonitorWare Agent ? Created 2003-11-21 by Tamsila-Q-Siddique. When UNC (\\severname\sharename\path) was given in the file path (in your defined “Write to File” action) Winsyslog, Eventreporter and MonitorWare Agent didn’t work? Yes, UNC works for Winsyslog, Eventreporter and MonitorWare Agent, but due to Windows design you must meet … Continue reading "Does UNC Pathes work for WinSyslog, EventReporter and MonitorWare Agent ?" ...

Records are not displayed on the Web when MYSQL was the underline database ?

Records are not displayed on the Web when MYSQL was the underline database ? Created 2003-11-19 by Tamsila-Q-Siddique Records are not displayed on the web when I use MySQL ? Records aren’t displayed on the web when I use MySQL. The data isn’t retrieved even though the database is being populated and logs are being … Continue reading "Records are not displayed on the Web when MYSQL was the underline database ?" ...

Error on startup (Error event ID: 7026) explained.

Error on startup (Error event ID: 7026) explained. Created  2003-11-06 by Andre Lorbach. Many Adiscon products (e.g. WinSyslog, EventReporter or MonitorWare Agent) are available in a 30 days trial version. After this time, the Service will stop working and if you are not logged on interactive, you will not see an error message. However, an … Continue reading "Error on startup (Error event ID: 7026) explained." ...

What is the difference between SETP and Syslog?

What is the difference between SETP and Syslog? Created 2003-10-21 by Wajih-ur-Rehman What is the difference between SETP and Syslog and what advantages does SETP offer over Syslog? Following are some of the points related to traditional Syslog: Its a UDP based protocol. It doesn’t provide any guarantees of message delivery. It doesn’t parses the … Continue reading "What is the difference between SETP and Syslog?" ...

Setup Error 1923

Setup Error 1923 Created on 09-10-2003 by Lutz Koch. I receive error 1923 when installing a MonitorWare Product like EventReporter, WinSyslog or MonitorWare Agent. What to do? If you update one of those Products to a newer Version, you might get the following warning message: Cause: If you changed the Services properties (for example the … Continue reading "Setup Error 1923" ...

Step by Step Guide for Viewing Syslog Messages on Web

Step by Step Guide for Viewing Syslog Messages on Web Created 2003-08-07 by Wajih-ur-Rehman Can you give me step by step guidelines for viewing Syslog Messages on Web? Here is the step by step procedure for configuring Online Web interface for viewing Syslog Messages. First, make sure that IIS is installed and running. Then follow … Continue reading "Step by Step Guide for Viewing Syslog Messages on Web" ...

How to monitor a file on a remote machine?

How to monitor a file on a remote machine? Created on 2003-08-07 by Michael Meckelein. By default, MonitorWare Agent service uses the local system account. This account has no permission on remote machines. If you want to monitor a file on a remote system, the MonitorWare Agent service must log on as a user with … Continue reading "How to monitor a file on a remote machine?" ...

Logging to Different Files

Logging to Different Files Created 2003-08-05 by Wajih-ur-Rehman How can I log the data from different devices to different files? You can log the data of different devices in different files with just one click! Simply check “Include Source in file name” and restart the service. Different logfiles will be created and each filename will … Continue reading "Logging to Different Files" ...

Database Connection Problem

Database Connection Problem Created 2003-08-05 by Wajih-ur-Rehman I am unable to Log the data to the database although I have provided the DSN to the software? Please note that even if you have created the DSN with some login and password, you would still have to write that login and password in the Graphical User … Continue reading "Database Connection Problem" ...

Error opening language file

Error opening language file Created 2003-08-05 by Lutz Koch When I start a MonitorWare Product, I get the following error: “FATAL error opening the MonitorWare/WinSyslog/EventReporter/MoniLog language file. Please repair this using the Monitorware/WinSyslog/EventReporter/MoniLog Installer” The reason for this error is that the language file got somehow deleted or renamed. This can occur with MonitorWare Agent, … Continue reading "Error opening language file" ...

How to use the Event Severity filter?

How to use the Event Severity filter? Created 2003-07-29 by Andre Lorbach The ‘Event Severity’ can be used to filter by event type. The following values are possible and valid: EVENTLOG SUCCESS 1 EVENTLOG ERROR TYPE 2 EVENTLOG WARNING TYPE 4 EVENTLOG INFORMATION TYPE 8 EVENTLOG AUDIT_SUCCESS 16 EVENTLOG AUDIT_FAILURE 32 To filter by multiple … Continue reading "How to use the Event Severity filter?" ...

Adiscon products and the Microsoft SQL Server 2000 Desktop Engine

Adiscon products and the Microsoft SQL Server 2000 Desktop Engine Created 2003-07-24 by Lutz Koch. How do MSDE security risks relate to Adiscon products? As a general policy, MSDE is *not* installed with any of our products. Even though this may cause some additional setup work for customers, we have decided to do so because … Continue reading "Adiscon products and the Microsoft SQL Server 2000 Desktop Engine" ...

What is “Event ID 107”?

What is “Event ID 107”? Created on 2003-06-16 by Usman Khawaja Message: “Couldn’t read last record for Security log (state 87) – nLastRecord set to 0 to recover.” This actually is no error, but a status message. There can be three reasons for this message: This message occurs when by any chance the last entry … Continue reading "What is “Event ID 107”?" ...

How to setup file monitoring for ISA Server?

How to setup file monitoring for ISA Server? Created 2003-05-23 by Lutz Koch. How to setup file monitoring for ISA Server? Since ISA Server logfiles are W3C based simple textfiles, they can be processed by MonitorWare Agent. To monitor the ISA logfiles, you just have to setup a File monitor service in the Agent: Right-click … Continue reading "How to setup file monitoring for ISA Server?" ...

How to create complex filter conditions?

How to create complex filter conditions? Created 2003-05-13 by Usman Khawaja. I would like to create some more complex filters by combining ANDs and ORs. (condition “a” AND condition “b”) OR (condition “c” AND condition “d”) OR … where “condition a” could be one of the choices like “syslog priority < 4 “, etc. In … Continue reading "How to create complex filter conditions?" ...

Difference between ReceivedAt and DeviceReportedTime

Difference between ReceivedAt and DeviceReportedTime Created 2003-05-10 by Wajih-ur-Rehman. What is the difference between ReceivedAt and DevicedReportedTime? I will explain you the difference by giving you two different scenarios: Scenario 1: Using MonitorWare Agent as Event Log Monitor and Forwarding the data to another MonitorWare Agent using Syslog In this case, the DeviceReportedTime is actually … Continue reading "Difference between ReceivedAt and DeviceReportedTime" ...

MonitorWare Agent 4.x – Database Structure Advantages

MonitorWare Agent 4.x – Database Structure Advantages Created 2003-05-05 by Wajih-ur-Rehman. Last Updated 2006-06-21 by Timm Herget. What are the advantages of this new Database Structure for MonitorWare Agent 4.x? Since most of the important information about any event is present in the message content and since the new MonitorWare Agent parses out this information … Continue reading "MonitorWare Agent 4.x – Database Structure Advantages" ...

Numeric values for event severity levels

Numeric values for event severity levels Created 2003-04-14 by Lutz Koch. What are the numeric values for event severity levels? The severity of an event describes the importance of an event. These severity levels are represented by numeric values. Those values are: Severity Numeric value SUCCESS 1 ERROR 2 WARNING 4 INFORMATION 8 AUDIT_SUCCESS 16 … Continue reading "Numeric values for event severity levels" ...

How to set the Windows 2000 event log size?

How to set the Windows 2000 event log size? Created 2003-04-14 by Rainer Gerhards. I know that the Windows event log size settings are not optimal. So how can I change them and what are better values? Indeed, the default settings are just 512 KB and overwrite after 7 days. While the 512 KB settings … Continue reading "How to set the Windows 2000 event log size?" ...

MonitorWare Agent as Syslog and SETP Server

MonitorWare Agent as Syslog and SETP Server Created 2003-04-04 by Wajih-ur-Rehman. If I am forwarding the data from different MonitorWare Agents via SETP to a central MonitorWare Agent acting as a SETP Server, will I be able to send Syslog messages to this central server too? Yes you will be able to send the Syslog … Continue reading "MonitorWare Agent as Syslog and SETP Server" ...

Configurations for SETP and Syslog Server

Configurations for SETP and Syslog Server Created 2003-04-04 by Wajih-ur-Rehman. I want to have a MonitorWare Agent acting as a Central Server such that it can accept both SETP as well as Syslog Messages and log them to a database. What configurations should i make? You will create the following configuration settings for MonitorWare Agent … Continue reading "Configurations for SETP and Syslog Server" ...

Configurations for Forwarding the Events

Configurations for Forwarding the Events Created 2003-04-04 by Wajih-ur-Rehman. I have MonitorWare Agents running on various Windows Machines/Servers. I want to forward all the Windows Event Log messages to the central MonitorWare Agent. What configurations should i make? For all the Window machines, which are forwarding the data to the central server, following should be … Continue reading "Configurations for Forwarding the Events" ...

My license key seems not to work – what to do?

My license key seems not to work – what to do? Created 2003-03-28 by Wajih-ur-Rehman. I entered my license information through the client interface but it still says that it is a “trial version”. How to solve this problem? Following are some of the reasons for your problem: If your license name does not have … Continue reading "My license key seems not to work – what to do?" ...

Migrating the Rules from EventReporter to MonitorWare Agent

Migrating the Rules from EventReporter to MonitorWare Agent Created 2003-07-22 by Wajih-ur-Rehman How can I migrate the rules that I have defined in EventReporter to MonitorWare Agent? This FAQ is only applicable to those who are using EventReporter 6.x and MonitorWare Agent 1.2 or higher. Follow the steps below: Click on Start and go to … Continue reading "Migrating the Rules from EventReporter to MonitorWare Agent" ...

How can I extend MonitorWare Database?

How can I extend MonitorWare Database? Created 2003-10-21 by Wajih-ur-Rehman How can I extend MonitorWare Database? You can create new fields and tables by appending u- before the names. This way the names of your custom fields and tables will never conflict with our fields and table names respectively since we will never add a … Continue reading "How can I extend MonitorWare Database?" ...

How can I forward IIS logs to a syslog deamon?

How can I forward IIS logs to a syslog deamon? Created on 2002-10-04 by Rainer Gerhards. MonitorWare Agent can forward Microsoft Internet Information Server (IIS) log files to any syslog deamon (or syslo server, if you like). Fortunately, IIS stores web log files as plain text files in the file system. Even better, other processes … Continue reading "How can I forward IIS logs to a syslog deamon?" ...

How to setup MonitorWare Products to use MySQL as database?

How to setup MonitorWare Products to use MySQL as database? Created on 2002-08-09 by Andre Lorbach. To use a MySQL Database with WinSyslog, EventReporter or MonitorWare Agent, you need to install some components (If you haven’t) first. Go to http://www.mysql.com/downloads/index.html. If you don’t have any MySQL Server, download MySQL-3.23.5 for Windows for example (Or a … Continue reading "How to setup MonitorWare Products to use MySQL as database?" ...

I have an invalid source in my received syslog message – what to do?

I have an invalid source in my received syslog message – what to do? Created on 2002-03-17 by Rainer Gerhards. If I look at the received syslog message source system, I see invalid names like “su”, “root” and the like. These correspond to some part of the syslog message. In any case, it is not … Continue reading "I have an invalid source in my received syslog message – what to do?" ...

How to configure Cisco products for logging?

How to configure Cisco products for logging? Created on 2001-01-13 by Rainer Gerhards. All Cisco products we know support logging to a syslog host like WinSyslog. This article covers all devices that use IOS (e. g. routers and switches). Syslog logging needs both to be configured as well as turned on. To configure, you must … Continue reading "How to configure Cisco products for logging?" ...