Juniper Logs

385 views
Skip to first unread message

Pablo Barriga

unread,
Sep 9, 2014, 12:36:14 PM9/9/14
to logaly...@googlegroups.com
Hello Group, I recently installed this great system, so far with Cisco devices is working great, I configured a Netscreen Firewall to send its logs to Logalyze, I see the logs are been collected on the system, but we I try to search for it, the result only show statistics of the logs received and none detail information.

I tried to create my own log definition for this logs, but the result remains the same "No items to show"

Greetings

logalyze_juniper.jpg

Balazs Vamos

unread,
Sep 10, 2014, 4:45:56 AM9/10/14
to logaly...@googlegroups.com
Hi Pablo,

This seems to be a good investigation story for me...
I have a feeling that there is some problem with the parsing here. As I can see the index contains the data but the raw log files do not. That's why it says that there are 142861 records there but nothing is shown.

Please check the following (it will be a kind of manual work):
- Go to $LOGALYZE_HOME/var/logstore and open the files there to check that there are data in them
- Open the application log in $LOGALYZE_HOME/logs and look for some exceptions.

We will see...

Balazs

Pablo Barriga

unread,
Sep 16, 2014, 11:35:34 AM9/16/14
to logaly...@googlegroups.com
Hello, thanks for the answer.

So far I see a lot of files on that folder, those files contains this type of events


<186>mxxx: NetScreen device_id=mxxx [Root]system-critical-00033: Src IP session limit! From 200.x.x.x:54695 to 200.x.x.x:53, proto UDP (zone Untrust int  ethernet0/2). Occurred 1 times. (2014-09-13 00:04:36)<186>mxxx: NetScreen device_id=mxxx  [Root]system-critical-00033: Src IP session limit! From 200.x.x.x

The application log doesn't show any parsing errors.

Greetings.
logsfiles.jpg
logs.txt
Reply all
Reply to author
Forward
0 new messages