<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: syslog-ng for sas rtdm log in SAS Customer Intelligence</title>
    <link>https://communities.sas.com/t5/SAS-Customer-Intelligence/syslog-ng-for-sas-rtdm-log/m-p/568003#M1195</link>
    <description>&lt;P&gt;I did not quite understand your question. &amp;nbsp; But if you are interested in information about syslog-ng then you may want to look at the knowledgebase at &lt;A href="https://support.oneidentity.com/syslog-ng-premium-edition/7.0.14" target="_blank"&gt;https://support.oneidentity.com/syslog-ng-premium-edition/7.0.14&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Moreover, I do not know which version of the product you are using. &amp;nbsp; But perhaps the following information helps you:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Metadata server logs are written usually to a folder named:&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;..../lev1/Web/WebAppServer/SASServer1_1/logs/ &amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The log4j configurations are stored in a folder named:&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;.../lev1/Web/Common/LogConfig&amp;gt;&lt;/P&gt;
&lt;P&gt;Before attempting to make changes, ensure that you know how log4j works and its syntax.&amp;nbsp; Extensive documentation is available via google.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Jun 2019 17:25:00 GMT</pubDate>
    <dc:creator>RajaMarla</dc:creator>
    <dc:date>2019-06-21T17:25:00Z</dc:date>
    <item>
      <title>syslog-ng for sas rtdm log</title>
      <link>https://communities.sas.com/t5/SAS-Customer-Intelligence/syslog-ng-for-sas-rtdm-log/m-p/567590#M1193</link>
      <description>&lt;P&gt;Hello everyone!&lt;/P&gt;&lt;P&gt;P.S Sorry for my English.&lt;BR /&gt;&lt;BR /&gt;I need&amp;nbsp;catch logs from Metadata server where level = INFO,&amp;nbsp;using syslog-ng.&lt;/P&gt;&lt;P&gt;So, I have a question how should&amp;nbsp;I configure syslog-ng.conf. In source I &lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN&gt;must indicate this:&lt;BR /&gt;source { file("/opt/sas/.../Metadata/metadataserver.sh"); };&amp;nbsp; and filter { level(info); }; or not?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="result-shield-container tlid-copy-target"&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN&gt;I do not fully understand how metadata server send log in default directory and where I must catch it's&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN&gt;.&lt;BR /&gt;And should I change&amp;nbsp;file /opt/sas/.../Metadata/logconfig.xml&amp;nbsp;? Make a new configure?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;P&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 12:29:03 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Customer-Intelligence/syslog-ng-for-sas-rtdm-log/m-p/567590#M1193</guid>
      <dc:creator>Loshadka</dc:creator>
      <dc:date>2019-06-20T12:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: syslog-ng for sas rtdm log</title>
      <link>https://communities.sas.com/t5/SAS-Customer-Intelligence/syslog-ng-for-sas-rtdm-log/m-p/568003#M1195</link>
      <description>&lt;P&gt;I did not quite understand your question. &amp;nbsp; But if you are interested in information about syslog-ng then you may want to look at the knowledgebase at &lt;A href="https://support.oneidentity.com/syslog-ng-premium-edition/7.0.14" target="_blank"&gt;https://support.oneidentity.com/syslog-ng-premium-edition/7.0.14&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Moreover, I do not know which version of the product you are using. &amp;nbsp; But perhaps the following information helps you:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Metadata server logs are written usually to a folder named:&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;..../lev1/Web/WebAppServer/SASServer1_1/logs/ &amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The log4j configurations are stored in a folder named:&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;.../lev1/Web/Common/LogConfig&amp;gt;&lt;/P&gt;
&lt;P&gt;Before attempting to make changes, ensure that you know how log4j works and its syntax.&amp;nbsp; Extensive documentation is available via google.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 17:25:00 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Customer-Intelligence/syslog-ng-for-sas-rtdm-log/m-p/568003#M1195</guid>
      <dc:creator>RajaMarla</dc:creator>
      <dc:date>2019-06-21T17:25:00Z</dc:date>
    </item>
    <item>
      <title>Re: syslog-ng for sas rtdm log</title>
      <link>https://communities.sas.com/t5/SAS-Customer-Intelligence/syslog-ng-for-sas-rtdm-log/m-p/568310#M1197</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thank for you answer!&lt;/P&gt;&lt;P&gt;I think, my description a problem is not a correct.&lt;/P&gt;&lt;P&gt;I try one more time &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Logs which I need writing, are located in /opt/sas94/SASConfig/Lev1/SASMeta/MetadataServer/Logs&lt;/P&gt;&lt;P&gt;But every day it make a new file for log, named&amp;nbsp; like that - SASMeta_MetadataServer_%d_%S{hostname}_%S{pid}.log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My syslog-ng version - syslog-ng 2.0.9&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want configure /syslog-ng.conf file to reading log with level "info" from /opt/sas94/SASConfig/Lev1/SASMeta/MetadataServer/Logs&lt;/P&gt;&lt;P&gt;and send it on UDP - protocol to specified server. But I dont't now how I make it, 'cos every day log-file change his name.&lt;BR /&gt;I try configure syslog-ng.conf like this:&lt;/P&gt;&lt;P&gt;source sas_log { file("/opt/sas94/SASConfig/Lev1/SASMeta/MetadataServer/Logs/SASMeta_MetadataServer_%d_%S{hostname}_%S{pid}.log"); };&lt;/P&gt;&lt;P&gt;but syslog don't understand this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wrote script-file:&lt;/P&gt;&lt;P&gt;#!/bin/bash&lt;/P&gt;&lt;P&gt;cd /opt/sas94/SASConfig/Lev1/SASMeta/MetadataServer/Logs/;&lt;BR /&gt;op=$(ls -t | head -1);&lt;BR /&gt;ech=$(echo $op);&lt;BR /&gt;tail -f -s 1 "$ech" | grep INFO ;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and specified it in source, but it doesn't working&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;Generally, I want what would syslog-ng every day read actual log-file, if it possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope I decrypt my idea right and simple &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 07:33:48 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Customer-Intelligence/syslog-ng-for-sas-rtdm-log/m-p/568310#M1197</guid>
      <dc:creator>Loshadka</dc:creator>
      <dc:date>2019-06-24T07:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: syslog-ng for sas rtdm log</title>
      <link>https://communities.sas.com/t5/SAS-Customer-Intelligence/syslog-ng-for-sas-rtdm-log/m-p/568311#M1198</link>
      <description>&lt;P&gt;&amp;gt;&amp;gt;Logs which I need writing, are located in /opt/sas94/SASConfig/Lev1/SASMeta/MetadataServer/Logs&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Sorry,&amp;nbsp;I'm mean not writing, I mean reading.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 07:35:31 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Customer-Intelligence/syslog-ng-for-sas-rtdm-log/m-p/568311#M1198</guid>
      <dc:creator>Loshadka</dc:creator>
      <dc:date>2019-06-24T07:35:31Z</dc:date>
    </item>
    <item>
      <title>Re: syslog-ng for sas rtdm log</title>
      <link>https://communities.sas.com/t5/SAS-Customer-Intelligence/syslog-ng-for-sas-rtdm-log/m-p/568416#M1199</link>
      <description>&lt;P&gt;You can try the following, which will write the "active" log to a single fixed log file name:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-&amp;nbsp; Backup/save the file&amp;nbsp;&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #333333; font-family: 'HelevticaNeue-light','Helvetica Neue',Helvetica,Arial,sans-serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; line-height: 21.33px; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;/opt/sas94/SASConfig/Lev1/SASMeta/MetadataServer/&lt;/SPAN&gt;logconfig.xml&amp;nbsp; as logconfig.xml.bak&lt;/P&gt;
&lt;P&gt;-&amp;nbsp; Edit the file&amp;nbsp;&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #333333; font-family: 'HelevticaNeue-light','Helvetica Neue',Helvetica,Arial,sans-serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; line-height: 21.33px; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;/opt/sas94/SASConfig/Lev1/SASMeta/MetadataServer/&lt;/SPAN&gt;logconfig.xml&amp;nbsp; (You will need to insert one line)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;lt;!-- Rolling log file with default rollover of midnight. --&amp;gt;&lt;BR /&gt;&amp;lt;appender class="RollingFileAppender" name="TimeBasedRollingFile"&amp;gt;&lt;BR /&gt;&lt;FONT color="#ff0000"&gt;&amp;lt;param name="File" value="&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #333333; font-family: 'HelevticaNeue-light','Helvetica Neue',Helvetica,Arial,sans-serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; line-height: 21.33px; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;/&lt;FONT color="#ff0000"&gt;opt/sas94/SASConfig/Lev1/SASMeta/MetadataServer/Logs&lt;/FONT&gt;&lt;/SPAN&gt;/SAS_MetadataServer.log"/&amp;gt;&lt;/FONT&gt;&lt;BR /&gt;&amp;lt;param name="Append" value="false"/&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- &amp;nbsp; Afterwards, stop/restart your services.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now, you can use the log file:&amp;nbsp;&lt;SPAN style="background-color: transparent; color: #333333; display: inline; float: none; font-family: &amp;amp;quot; helevticaneue-light&amp;amp;quot;,&amp;amp;quot;helvetica neue&amp;amp;quot;,helvetica,arial,sans-serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; line-height: 21.33px; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;/&lt;FONT color="#ff0000" style="line-height: normal;"&gt;opt/sas94/SASConfig/Lev1/SASMeta/MetadataServer/Logs&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT color="#ff0000"&gt;/SAS_MetadataServer.log&amp;nbsp; &lt;FONT color="#000000"&gt;in your syslog-ng.conf&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#ff0000"&gt;&lt;FONT color="#000000"&gt;&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #333333; font-family: 'HelevticaNeue-light','Helvetica Neue',Helvetica,Arial,sans-serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; line-height: 21.33px; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;source sas_log { file("&lt;SPAN style="background-color: transparent; color: #333333; display: inline; float: none; font-family: &amp;amp;quot; helevticaneue-light&amp;amp;quot;,&amp;amp;quot;helvetica neue&amp;amp;quot;,helvetica,arial,sans-serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; line-height: 21.33px; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;/&lt;FONT color="#ff0000" style="line-height: normal;"&gt;opt/sas94/SASConfig/Lev1/SASMeta/MetadataServer/Logs&lt;/FONT&gt;&lt;/SPAN&gt;/SAS_MetadataServer.log"); };&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#ff0000"&gt;&lt;FONT color="#000000"&gt;&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #333333; font-family: 'HelevticaNeue-light','Helvetica Neue',Helvetica,Arial,sans-serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; line-height: 21.33px; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;Note &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#ff0000"&gt;&lt;FONT color="#000000"&gt;&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #333333; font-family: 'HelevticaNeue-light','Helvetica Neue',Helvetica,Arial,sans-serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; line-height: 21.33px; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;1.&amp;nbsp; I do not know much about syslog-ng, so check the syntax carefully&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#ff0000"&gt;&lt;FONT color="#000000"&gt;&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #333333; font-family: 'HelevticaNeue-light','Helvetica Neue',Helvetica,Arial,sans-serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; line-height: 21.33px; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;2.&amp;nbsp; I did not test the above...but I believe the above would work.&amp;nbsp; You will need to test the above in a "test environment" before you change production configuration.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 16:24:46 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Customer-Intelligence/syslog-ng-for-sas-rtdm-log/m-p/568416#M1199</guid>
      <dc:creator>RajaMarla</dc:creator>
      <dc:date>2019-06-24T16:24:46Z</dc:date>
    </item>
    <item>
      <title>Re: syslog-ng for sas rtdm log</title>
      <link>https://communities.sas.com/t5/SAS-Customer-Intelligence/syslog-ng-for-sas-rtdm-log/m-p/568724#M1200</link>
      <description>&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;You decision is very good and simple.&lt;/P&gt;&lt;P&gt;I think, I try do that your say, if my decision not work.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I do next thing's:&lt;/P&gt;&lt;P&gt;As I say I wrote simple script:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-SPOILER&gt;&lt;P&gt;#!/bin/bash&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;while true;&lt;BR /&gt;do&lt;BR /&gt;cd &lt;FONT color="#ff0000"&gt;/opt/sas94/SASConfig/Lev1/SASMeta/MetadataServer/Logs/&lt;/FONT&gt;;&lt;BR /&gt;op=$(ls -t | head -1);&lt;BR /&gt;ech=$(echo $op);&lt;BR /&gt;tail -f -s 1 "$ech" | grep -P 'INFO'&amp;gt;&amp;gt;/&lt;FONT color="#ff0000"&gt;tmp/arcsight&lt;/FONT&gt;;&lt;BR /&gt;sleep 1;&lt;BR /&gt;done;&lt;/P&gt;&lt;/LI-SPOILER&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And&amp;nbsp; started it in nohup.&lt;/P&gt;&lt;P&gt;Syslog source - source { file &lt;FONT color="#ff0000"&gt;"/tmp/arcsight"&lt;/FONT&gt; .......); };&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, syslog reading log from /tmp/arcsight and send it to specified server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you one more time!&lt;BR /&gt;P.S. sorry for my English&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2019 12:38:16 GMT</pubDate>
      <guid>https://communities.sas.com/t5/SAS-Customer-Intelligence/syslog-ng-for-sas-rtdm-log/m-p/568724#M1200</guid>
      <dc:creator>Loshadka</dc:creator>
      <dc:date>2019-06-25T12:38:16Z</dc:date>
    </item>
  </channel>
</rss>

