Forums

Skip to content

Advanced search
  • Quick links
    • Unanswered topics
    • Active topics
    • Search
  • FAQ
  • Login
  • Register
  • Board index Assistance Networking & Security
  • Search

Trouble making a Cisco Aironet 1100 WAP log to metalog

Having problems getting connected to the internet or running a server? Wondering about securing your box? Ask here.
Post Reply
Advanced search
5 posts • Page 1 of 1
Author
Message
dsegel
Tux's lil' helper
Tux's lil' helper
Posts: 127
Joined: Fri Jan 31, 2003 8:41 pm

Trouble making a Cisco Aironet 1100 WAP log to metalog

  • Quote

Post by dsegel » Thu May 10, 2007 2:31 pm

I need to set up logging from an Aironet 1100 WAP on my linux box running metalog, but I can't figure out how to configure metalog to actually listen to the data being sent by the Aironet.

The Aironet docs state:
The current software generates the following categories of syslog messages:
•Error messages at the emergencies level.
•Error messages at the alerts level.
•Error messages at the critical level.
•Error messages about software or hardware malfunctions, displayed at the errors level.
•Interface up/down transitions and system restart messages, displayed at the notification level.
•Reload requests and low-process stack messages, displayed at the informational level.
•Output from the debug commands, displayed at the debugging level.

Example of Setting Up a UNIX Syslog Daemon

To set up the syslog daemon on a 4.3 BSD UNIX system, include a line such as the following in the file /etc/syslog.conf:
local7.debugging /usr/adm/logs/tiplog

The local7 keyword specifies the logging facility to be used.

The debugging keyword specifies the syslog level. See Table 1 for other keywords that can be listed.

The UNIX system sends messages at or above this level to the specified file, in this case /usr/adm/logs/tiplog. The file must already exist, and the syslog daemon must have permission to write to it.

For the System V UNIX systems, the line should read as follows:

local7.debug /usr/admin/logs/cisco.log
I have the Aironet set to send all (debugging level) messages to my linux box, and I do see data coming in via tcpdump. I tried this in metalog.conf, but nothing it written to the file:

Aironet messages :
facility = "local7"
minimum = 7
logdir = "/var/log/wireless"

Is there somewhere I need to tell metalog to listen to incoming data from other than localhost?
Top
think4urs11
Bodhisattva
Bodhisattva
User avatar
Posts: 6659
Joined: Wed Jun 25, 2003 9:51 pm
Location: above the cloud

  • Quote

Post by think4urs11 » Thu May 10, 2007 3:53 pm

Correct me when i'm wrong but as far as i know metalog is not able at all to log syslog messages coming from the network.
Use syslog-ng instead.
Nothing is secure / Security is always a trade-off with usability / Do not assume anything / Trust no-one, nothing / Paranoia is your friend / Think for yourself
Top
dsegel
Tux's lil' helper
Tux's lil' helper
Posts: 127
Joined: Fri Jan 31, 2003 8:41 pm

  • Quote

Post by dsegel » Thu May 10, 2007 4:20 pm

That would be unfortunate, but at least it explains what I'm (not) seeing.

I'll look into syslog-ng. Thanks for the info.
Top
kashani
Advocate
Advocate
User avatar
Posts: 2030
Joined: Mon Sep 02, 2002 6:38 am
Location: San Francisco
Contact:
Contact kashani
Website

  • Quote

Post by kashani » Thu May 10, 2007 5:16 pm

Think4urS11 is right metalog can not accept logging from the network.

If you're considering syslog-ng this post might help.
http://forums.gentoo.org/viewtopic-t-37 ... logng.html

kashani
Will personally fix your server in exchange for motorcycle related shop tools in good shape.
Top
dsegel
Tux's lil' helper
Tux's lil' helper
Posts: 127
Joined: Fri Jan 31, 2003 8:41 pm

  • Quote

Post by dsegel » Thu May 10, 2007 8:47 pm

I got it working with syslog-ng, but my main purpose for doing this was to debug some RADIUS authentication issues, and now that I have the logging working the RADIUS issues have gone away for the time being. I've spent so much time trying to figure out what is causing the problem that I'm not even sure I'm happy that the problem is gone...

I've never been so mad that something is working properly.

:x
Top
Post Reply

5 posts • Page 1 of 1

Return to “Networking & Security”

Jump to
  • Assistance
  • ↳   News & Announcements
  • ↳   Frequently Asked Questions
  • ↳   Installing Gentoo
  • ↳   Multimedia
  • ↳   Desktop Environments
  • ↳   Networking & Security
  • ↳   Kernel & Hardware
  • ↳   Portage & Programming
  • ↳   Gamers & Players
  • ↳   Other Things Gentoo
  • ↳   Unsupported Software
  • Discussion & Documentation
  • ↳   Documentation, Tips & Tricks
  • ↳   Gentoo Chat
  • ↳   Gentoo Forums Feedback
  • ↳   Duplicate Threads
  • International Gentoo Users
  • ↳   中文 (Chinese)
  • ↳   Dutch
  • ↳   Finnish
  • ↳   French
  • ↳   Deutsches Forum (German)
  • ↳   Diskussionsforum
  • ↳   Deutsche Dokumentation
  • ↳   Greek
  • ↳   Forum italiano (Italian)
  • ↳   Forum di discussione italiano
  • ↳   Risorse italiane (documentazione e tools)
  • ↳   Polskie forum (Polish)
  • ↳   Instalacja i sprzęt
  • ↳   Polish OTW
  • ↳   Portuguese
  • ↳   Documentação, Ferramentas e Dicas
  • ↳   Russian
  • ↳   Scandinavian
  • ↳   Spanish
  • ↳   Other Languages
  • Architectures & Platforms
  • ↳   Gentoo on ARM
  • ↳   Gentoo on PPC
  • ↳   Gentoo on Sparc
  • ↳   Gentoo on Alternative Architectures
  • ↳   Gentoo on AMD64
  • ↳   Gentoo for Mac OS X (Portage for Mac OS X)
  • Board index
  • All times are UTC
  • Delete cookies

© 2001–2026 Gentoo Foundation, Inc.

Powered by phpBB® Forum Software © phpBB Limited

Privacy Policy

 

 

magic