Security Compliance

Export log files using the CMC exportsyslog command or SFTP

The exportsyslog command exports the contents of the log files of the SEM from sources such as Syslog and SNMP. You can also use an SFTP tool such as WinSCP to gather the log files.

First published date

10/9/2018 5:27 PM

Last published date

5/31/2022 5:04 AM

Overview

This article applies to Security Event Manager (formerly Log & Event Manager).

When connecting a syslog device or troubleshooting the logs that you see from a connector it can be helpful to view what syslog traffic the SEM is receiving. This guide will explain methods of extracting this log information from the SEM for review.

Product section

Security Event Manager

Cause

N/A

Resolution

Method 1

  1. Access the CMC prompt:
  2. In the cmc> prompt, enter appliance. The prompt changes to cmc::acm# indicating you are in the appliance configuration menu.
  3. In the cmc::acm# prompt, enter exportsyslog.
  4. Select the log file or local facility by entering the corresponding number in the list and pressing Enter.
  5. Once you have selected the appropriate facilities, press q and then Enter to quit the selection prompt.
  6. Fill in the required information for a network share so that the SEM can export the requested data.

 

Note: If the syslog files you are exporting are very large in size and exceed the maximum capacity of the Temp partition, the export will fail. In that case, you can try exporting one log file at a time. If that one log file is still too large to export please try Method 2 or contact SolarWinds Support to assist with that.


Method 2

  1. Download an SFTP tool such as WinSCP
  2. Connect to the SEM on port 22 using the CMC account
  3. Navigate to /var/log
  4. Locate the log file for your facility, as well as any archived backups of that file
  5. Copy those files locally and zip them into a bundle