- Community Home
- >
- Storage
- >
- Midrange and Enterprise Storage
- >
- HPE 3PAR StoreServ Storage
- >
- Re: SPLUNK as syslog 3PAR
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-12-2017 02:23 PM
тАО10-12-2017 02:23 PM
SPLUNK as syslog 3PAR
Hej,
Is there any way to send test traps from 3PAR after external syslog configuration.
- Tags:
- syslog
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО04-25-2018 04:04 AM
тАО04-25-2018 04:04 AM
Re: SPLUNK as syslog 3PAR
Hello,
You can send a test trap to all SNMP managers displayed with the showsnmpmgr command. Procedure Issue the checksnmp command. The CLI displays the IP addresses of the tested managers.
You have first to To register the SNMP manager with the agent, use the setsnmpmgr command followed by the IP address of the SNMP manager
You can find all details on the document Page 247-252 HPE 3PAR Command Line Interface Administrator Guide :
https://support.hpe.com/hpsc/doc/public/display?docId=c04204251
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО04-25-2018 04:27 AM
тАО04-25-2018 04:27 AM
Re: SPLUNK as syslog 3PAR
Hello,
You can use the "checksnmp" command to send an SNMP test trap.
EXAMPLES
cli% checksnmp
Trap sent to the following managers:
192.168.17.10:162
192.168.17.111:1000
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-09-2018 07:04 AM
тАО05-09-2018 07:04 AM
Re: SPLUNK as syslog 3PAR
Syslog is used to audit purposes, in my case, after setting and enabling syslog via setsys command, messages began to arrive in great amounts that no test message was necessary. you are intended to monitor events? consider use snmp traps.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-14-2018 07:33 AM
тАО08-14-2018 07:33 AM
Re: SPLUNK as syslog 3PAR
Do you know what port the 3par is sending the syslogs on?
I need to open the firewall for syslogging.
Also, are the syslogs coming from the SP or the 3par?
Thanks
Randy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-14-2018 01:56 PM
тАО08-14-2018 01:56 PM
Re: SPLUNK as syslog 3PAR
The syslog host is defined using the 3PAR StoreServ command line (setsys RemoteSyslogHost ...)
If the port is not configured one of the following default ports will be used; 514 for UDP, 601 for TCP, 6514 for TLS.
Note: While I am an HPE Employee, all of my comments (whether noted or not), are my own and are not any official representation of the company
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-14-2018 10:31 PM
тАО08-14-2018 10:31 PM
Re: SPLUNK as syslog 3PAR
If your SP is Version 5, you can set remote syslog there too ("Edit SP configuration"). The settings-dialoge will show the different ports it would use, depending on your flavour of udp or tcp, tls etc...
We use splunk too. My idea is to monitor remote connections from hpe, but so far I didn't find the right entries to monitor to catch all of them. There's some entries flagged "audit", but there are lot's of them that aren't of interest at all.