Absent Member.
Absent Member.
726 views

Processing multiple files with the Microsoft DNS Trace Log SmartConnector?

I need to process Microsoft DNS Trace Log files. There exists a SmartConnector for this but does it support multiple files?

May I configured something like "*.log"? Does it support recursive directories?

(like the Multiple Folder Follower FlexConnector)

Ex:

/log/server1/dns.log

/log/server2/dns.log

etc...

How will you handle this case?

Regards,

Xavier

Labels (2)
0 Likes
4 Replies
Absent Member.
Absent Member.

I did something similar at a previous company, keep in mind that this was before ArcSight had a connector for this so I was making this up as I went along.

Using RedHat boxes with Samba client, I mapped a drive to the remote DNS servers that the MS admins created for me.  I would make sure the higher usage DNS servers were not all on the same VM.   I then setup a script that tails all of those logs across the enterprise and converted into CEF using perl.   That was 2009 and over 60 DNS servers.

Today I would do the same with the ArcSight MS Dns Trace or a Flex connector.  Set up the shares pull/tail the logs into a couple of local log files and have multiple connectors reading those logs.

This saves you in two places.  One you don't have to install connectors on your DNS servers.  Two you can have better control of the connectors when they are not on corporate infrastructure.  With this method, even on our busiest DNS servers, the admins of those boxes did not notice any performance impact. 

Hope this helps, I don't have any of the code but its a start.  ArcSight Support would probably not support this in anyway but its my hack and it worked for the three plus years I was there.

0 Likes
Absent Member.
Absent Member.

Hello Eric,

We are brainstorming in the same way but now that a SmartConnector exists, we would like to use it of course... Thank you for your feedback!

0 Likes

Hi,

There's a new connector now for Multiple Log files, but i'm facing an issue with it. I get "Folder [xyz] does not exist"

Any ideas?

Mustapha
0 Likes
Absent Member.
Absent Member.

Mustapha,

Have you gone through these troubleshooting steps in the SmartConnector documentation?

Hopefully one of these steps solves the issue.

untitled.bmp

0 Likes
The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.