Closed rtty88 closed 5 months ago
When you mean list view, is it the number of message par page, (that the filters Messages) or the length of the message (that's the Trim inside the filter part) ?
As for the destination / source, it depends of the type of messages send by syslog, I have tons of message that dosen't have Src/dst information.
Inside Cacti there is no interpretation of the message, it's just a display, it will be hard if not impossible to define all type of message and display the column depending of the contend.
Yes I mean the number of message par page to be increase if possible,
and yes agree with you for source and destination maybe it will be imposible to have separated
For the number of message you can change the default view inside: Console ->Configuration -> Settings -> Syslog
It's the Filed name 'Max. report Records'
That is the max number of message you view by default, I think it's what you want.
And If you whan to change it just when you view your messages, select Messages on the first part of the screen:
yes, I found it now thanks , one more question
is there any way to show me the host name without the IP
Hmm, mine is displaying the hostname. But since it's what I have on the database, I think this part is done by rsyslog daemon, not by cacti itself.
Can you tel me what's is your template you have on Rsyslog.conf about the cacti_syslog ?
/etc/rsyslog.d/cacti.conf
$ModLoad imudp $UDPServerRun 514 $ModLoad ommysql
$template cacti_syslog,"INSERT INTO syslog_incoming(facility_id, priority_id, program, logtime, host, message) \ values (%syslogfacility%, %syslogpriority%, '%programname%', '%timegenerated:::date-mysql%', '%HOSTNAME%', TRIM('%msg%'))"$
/etc/rsyslog.conf
module(load="imuxsock" # provides support for local system logging (e.g. via logger command) SysSock.Use="off") # Turn off message reception via local log socket;
module(load="imjournal" # provides access to the systemd journal UsePid="system" # PID nummber is retrieved as the ID of the process the journal entry originates from StateFile="imjournal.state") # File to store the position in the journal
global(workDirectory="/var/lib/rsyslog")
module(load="builtin:omfile" Template="RSYSLOG_TraditionalFileFormat")
include(file="/etc/rsyslog.d/*.conf" mode="optional")
*.info;mail.none;authpriv.none;cron.none;local0.none /var/log/messages
authpriv.* /var/log/secure
mail.* -/var/log/maillog
cron.* /var/log/cron
.emerg :omusrmsg:
uucp,news.crit /var/log/spooler
local7.* /var/log/boot.log
It's a setting in Syslog to resolve IP to hostname. Syslog also maintains a cache.
how can I fix it then when you close the issue while didn't explain clearly
@TheWitness
Syslog only has an origin IP. There is no destination IP. If you have a message with source and destination amongst millions of different message classes, you would have to write a disector for it.
If that's the case, if I were you, I would sanction a developer to write a plugin that interprets and displays your messages from that syslog data as for now, in the current design, it does not belong in syslog directly.
It's a great idea, but my preference would be to do it that way. Splunk by the way does this exceptionally well.
No I think the latest question is related to the syslog view, where it see the IP address of the source of the message, not the hostname. Not the iip source/dest inside the messages (I think that is clear for him now that cacti can't interpret messages).
There were multiple topics actually. So, dns resolution is broken?
well yes Guys, Thanks , but is possible to see the hostname instead of ip address ? I have tried also to add devices on cacti itself in order to be shown as hostname but still get only IPs on syslog plugin
Is your feature request related to a problem? Please describe. it not related to a problem
Describe the solution you'd like it will be a good idea to have two column for source IP and destination IP and the possibility to increase the list view for ex. 100 or more to see all the syslog in one page
Additional context![image](https://github.com/Cacti/plugin_syslog/assets/96175987/498481e1-7133-4c35-af92-db41992e1743)