Quantcast
Channel: THWACK: Message List - Kiwi Syslog
Viewing all articles
Browse latest Browse all 2141

Re: How Do I add a Mac Address Field or Column?

$
0
0

Jiri is correct that the software cannot track this and that it becomes irrelevent after the 1st hop, but that's not to say it cannot be done at all, if all of your machines that you want to track are on the same subnet and do not travel through a Router or Firewall.

 

If the machines you are looking to track are communicating to your copy of Syslog, then you have their IP address currently. It's Dynamic as you say, so that means nothing to you, but if you already know the mac addresses then it becomes simple (relatively speaking) to track which messages come from which machines regardless of IP address.

 

On every message you receive, run a script, check the IP address source of the message. Have the script run an ARP command from the command prompt and check the results to match a MAC address to the IP address just received. Then change the hostname or message text of the Syslog message to reflect the MAC address that matched.

 

While there is definitely some scripting involved and it might be a little complex for someone just getting started, you would now have MAC Address based Syslogging.


Viewing all articles
Browse latest Browse all 2141

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>