Sawmill

DOWNLOAD
SAWMILL 8.5.6
free trial!!
Home Products Downloads Purchase Support About About
Sawmill Sawmill

SAWMILLFORUM

Sawmill Discussion Forum

Subject: "Considering Product - Have Questions"     Previous Topic | Next Topic
Printer-friendly copy    
Conferences Pre-Sales Topic #830
Reading Topic #830
Dwallace74
Member since Mar-29-12
1 posts
Mar-29-12, 09:16 AM (PDT)
Click to EMail Dwallace74 Click to send private message to Dwallace74 Click to view user profileClick to add this user to your buddy list  
"Considering Product - Have Questions"
 
   We are currently using Kiwi Syslog Server to collect our logs. Your product was mentioned on their support page. I've been reviewing the documentation about your product and have some questions:

1) We use a SIEM for monitoring and alerting, but we are not actively reviewing all of the collected log data that goes to the Kiwi server. Can reporting be scheduled to review logs based on the type of log or program? I'd like to start looking for anomalies, plus be able to schedule and generate reports on a weekly, monthly and quarterly basis.
2) I think I understand how the "profile" works for reporting purposes. If I want Sawmill to review and report on the various SQL logs collected on the Kiwi server, would that be considered one profile or would a profile be required for each SQL server?

Thank you!


  Alert | IP Printer-friendly page | Edit | Reply | Reply With Quote | Top
dgilmoreadmin
Member since Nov-18-04
3743 posts
Mar-29-12, 11:31 AM (PDT)
Click to EMail dgilmore Click to send private message to dgilmore Click to view user profileClick to add this user to your buddy list Click to send message via AOL IM  
1. "RE: Considering Product - Have Questions"
In response to message #0
 
Hi-

Sawmill has a built in scheduler that can send out periodic reports, daily, weekly, monthly, quarterly, and these reports can be filtered in many ways, by event types, or any field that's logged, or any combination of conditions.

If kiwi has logs for multiple SQL servers it's likely you can analyze the log file within one profile, however, in some cases it might be of interest from an organizational or unit point of view to have a profile for each of the SQL servers. As long as the resulting format from the SQL server is the same in the kiwi log, you could have one profile for all SQL servers.

David
Sawmill Product Support Team
support@flowerfire.com


  Alert | IP Printer-friendly page | Edit | Reply | Reply With Quote | Top

Conferences | Topics | Previous Topic | Next Topic
© 2012 Flowerfire | Copyright | Privacy Policy | License Agreement | Terms of Use | Contact | Feedback | About
Sawmill Software
Sawmill Software
Back to Sawmill Home