Security Compliance
Export log files using the CMC exportsyslog command or SFTP
The exportsyslog command exports the contents of the log files of the SEM from sources such as Syslog and SNMP. You can also use an SFTP tool such as WinSCP to gather the log files.
First published date
Last published date
Overview
When connecting a syslog device or troubleshooting the logs that you see from a connector it can be helpful to view what syslog traffic the SEM is receiving. This guide will explain methods of extracting this log information from the SEM for review.
Product section
Cause
Resolution
Method 1
- Access the CMC prompt:
- Virtual Console: Arrow down to Advanced Configuration, and then press Enter.
- SSH Client: Log in using your CMC credentials. See more in this article:Use an SSH client to connect to your SEM Appliance
- In the cmc> prompt, enter
appliance. The prompt changes to cmc::acm#indicating you are in the appliance configuration menu. - In the cmc::acm# prompt, enter
exportsyslog. - Select the log file or local facility by entering the corresponding number in the list and pressing Enter.
- Once you have selected the appropriate facilities, press q and then Enter to quit the selection prompt.
- Fill in the required information for a network share so that the SEM can export the requested data.
Note: If the syslog files you are exporting are very large in size and exceed the maximum capacity of the Temp partition, the export will fail. In that case, you can try exporting one log file at a time. If that one log file is still too large to export please try Method 2 or contact SolarWinds Support to assist with that.
Method 2
- Download an SFTP tool such as WinSCP
- Connect to the SEM on port 22 using the CMC account
- Navigate to /var/log
- Locate the log file for your facility, as well as any archived backups of that file
- Copy those files locally and zip them into a bundle