Hi
I am trying to set up a unified logging environment for Solaris, HP-UX and Windows NT/2000 servers. The centralized logging and reporting server will run syslog-ng and accept syslog messages (with an agent converter for NT/2000) from all the servers on the network. I will then use swatch to report against these logs, both near real-time for critical events and daily reports for events which must be monitored but are not considered critical.
All Solaris boxes will configured to use the Basic Security Module and audit against events such as successful/failed logins, su and so on. Given that the auditd writes it's files in binary and a tool such as praudit must be used to report against them, I was wondering if anyone knew of a way of integrating this into syslog-ng, maybe by using local0 -7, or there is package out there that does this? We live in hope ......
Regards
Olivia