source: vendor/3.5.7/docs/manpages/eventlogadm.8

Last change on this file was 478, checked in by Silvan Scherrer, 15 years ago

Samba 3.5: vendor update to 3.5.4

File size: 10.2 KB
Line 
1.\" Title: eventlogadm
2.\" Author: [see the "AUTHOR" section]
3.\" Generator: DocBook XSL Stylesheets v1.74.0 <http://docbook.sf.net/>
4.\" Date: 06/18/2010
5.\" Manual: System Administration tools
6.\" Source: Samba 3.5
7.\" Language: English
8.\"
9.TH "EVENTLOGADM" "8" "06/18/2010" "Samba 3\&.5" "System Administration tools"
10.\" -----------------------------------------------------------------
11.\" * (re)Define some macros
12.\" -----------------------------------------------------------------
13.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
14.\" toupper - uppercase a string (locale-aware)
15.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
16.de toupper
17.tr aAbBcCdDeEfFgGhHiIjJkKlLmMnNoOpPqQrRsStTuUvVwWxXyYzZ
18\\$*
19.tr aabbccddeeffgghhiijjkkllmmnnooppqqrrssttuuvvwwxxyyzz
20..
21.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
22.\" SH-xref - format a cross-reference to an SH section
23.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
24.de SH-xref
25.ie n \{\
26.\}
27.toupper \\$*
28.el \{\
29\\$*
30.\}
31..
32.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
33.\" SH - level-one heading that works better for non-TTY output
34.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
35.de1 SH
36.\" put an extra blank line of space above the head in non-TTY output
37.if t \{\
38.sp 1
39.\}
40.sp \\n[PD]u
41.nr an-level 1
42.set-an-margin
43.nr an-prevailing-indent \\n[IN]
44.fi
45.in \\n[an-margin]u
46.ti 0
47.HTML-TAG ".NH \\n[an-level]"
48.it 1 an-trap
49.nr an-no-space-flag 1
50.nr an-break-flag 1
51\." make the size of the head bigger
52.ps +3
53.ft B
54.ne (2v + 1u)
55.ie n \{\
56.\" if n (TTY output), use uppercase
57.toupper \\$*
58.\}
59.el \{\
60.nr an-break-flag 0
61.\" if not n (not TTY), use normal case (not uppercase)
62\\$1
63.in \\n[an-margin]u
64.ti 0
65.\" if not n (not TTY), put a border/line under subheading
66.sp -.6
67\l'\n(.lu'
68.\}
69..
70.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
71.\" SS - level-two heading that works better for non-TTY output
72.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
73.de1 SS
74.sp \\n[PD]u
75.nr an-level 1
76.set-an-margin
77.nr an-prevailing-indent \\n[IN]
78.fi
79.in \\n[IN]u
80.ti \\n[SN]u
81.it 1 an-trap
82.nr an-no-space-flag 1
83.nr an-break-flag 1
84.ps \\n[PS-SS]u
85\." make the size of the head bigger
86.ps +2
87.ft B
88.ne (2v + 1u)
89.if \\n[.$] \&\\$*
90..
91.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
92.\" BB/BE - put background/screen (filled box) around block of text
93.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
94.de BB
95.if t \{\
96.sp -.5
97.br
98.in +2n
99.ll -2n
100.gcolor red
101.di BX
102.\}
103..
104.de EB
105.if t \{\
106.if "\\$2"adjust-for-leading-newline" \{\
107.sp -1
108.\}
109.br
110.di
111.in
112.ll
113.gcolor
114.nr BW \\n(.lu-\\n(.i
115.nr BH \\n(dn+.5v
116.ne \\n(BHu+.5v
117.ie "\\$2"adjust-for-leading-newline" \{\
118\M[\\$1]\h'1n'\v'+.5v'\D'P \\n(BWu 0 0 \\n(BHu -\\n(BWu 0 0 -\\n(BHu'\M[]
119.\}
120.el \{\
121\M[\\$1]\h'1n'\v'-.5v'\D'P \\n(BWu 0 0 \\n(BHu -\\n(BWu 0 0 -\\n(BHu'\M[]
122.\}
123.in 0
124.sp -.5v
125.nf
126.BX
127.in
128.sp .5v
129.fi
130.\}
131..
132.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
133.\" BM/EM - put colored marker in margin next to block of text
134.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
135.de BM
136.if t \{\
137.br
138.ll -2n
139.gcolor red
140.di BX
141.\}
142..
143.de EM
144.if t \{\
145.br
146.di
147.ll
148.gcolor
149.nr BH \\n(dn
150.ne \\n(BHu
151\M[\\$1]\D'P -.75n 0 0 \\n(BHu -(\\n[.i]u - \\n(INu - .75n) 0 0 -\\n(BHu'\M[]
152.in 0
153.nf
154.BX
155.in
156.fi
157.\}
158..
159.\" -----------------------------------------------------------------
160.\" * set default formatting
161.\" -----------------------------------------------------------------
162.\" disable hyphenation
163.nh
164.\" disable justification (adjust text to left margin only)
165.ad l
166.\" -----------------------------------------------------------------
167.\" * MAIN CONTENT STARTS HERE *
168.\" -----------------------------------------------------------------
169.SH "Name"
170eventlogadm \- push records into the Samba event log store
171.SH "Synopsis"
172.fam C
173.HP \w'\ 'u
174\FCeventlogadm\F[] [\fB\-d\fR] [\fB\-h\fR] \fB\-o\fR\ \FCaddsource\F[]\ \fIEVENTLOG\fR\ \fISOURCENAME\fR\ \fIMSGFILE\fR
175.fam
176.fam C
177.HP \w'\ 'u
178\FCeventlogadm\F[] [\fB\-d\fR] [\fB\-h\fR] \fB\-o\fR\ \FCwrite\F[]\ \fIEVENTLOG\fR
179.fam
180.fam C
181.HP \w'\ 'u
182\FCeventlogadm\F[] [\fB\-d\fR] [\fB\-h\fR] \fB\-o\fR\ \FCdump\F[]\ \fIEVENTLOG\fR\ \fIRECORD_NUMBER\fR
183.fam
184.SH "DESCRIPTION"
185.PP
186This tool is part of the
187\fBsamba\fR(1)
188suite\&.
189.PP
190\FCeventlogadm\F[]
191is a filter that accepts formatted event log records on standard input and writes them to the Samba event log store\&. Windows client can then manipulate these record using the usual administration tools\&.
192.SH "OPTIONS"
193.PP
194\fB\-d\fR
195.RS 4
196The
197\FC\-d\F[]
198option causes
199\FCeventlogadm\F[]
200to emit debugging information\&.
201.RE
202.PP
203\fB\-o\fR \FCaddsource\F[] \fIEVENTLOG\fR \fISOURCENAME\fR \fIMSGFILE\fR
204.RS 4
205The
206\FC\-o addsource\F[]
207option creates a new event log source\&.
208.RE
209.PP
210\fB\-o\fR \FCwrite\F[] \fIEVENTLOG\fR
211.RS 4
212The
213\FC\-o write\F[]
214reads event log records from standard input and writes them to the Samba event log store named by EVENTLOG\&.
215.RE
216.PP
217\fB\-o\fR \FCdump\F[] \fIEVENTLOG\fR \fIRECORD_NUMBER\fR
218.RS 4
219The
220\FC\-o dump\F[]
221reads event log records from a EVENTLOG tdb and dumps them to standard output on screen\&.
222.RE
223.PP
224\fB\-h\fR
225.RS 4
226Print usage information\&.
227.RE
228.SH "EVENTLOG RECORD FORMAT"
229.PP
230For the write operation,
231\FCeventlogadm\F[]
232expects to be able to read structured records from standard input\&. These records are a sequence of lines, with the record key and data separated by a colon character\&. Records are separated by at least one or more blank line\&.
233.PP
234The event log record field are:
235.sp
236.RS 4
237.ie n \{\
238\h'-04'\(bu\h'+03'\c
239.\}
240.el \{\
241.sp -1
242.IP \(bu 2.3
243.\}
244
245\FCLEN\F[]
246\- This field should be 0, since
247\FCeventlogadm\F[]
248will calculate this value\&.
249.RE
250.sp
251.RS 4
252.ie n \{\
253\h'-04'\(bu\h'+03'\c
254.\}
255.el \{\
256.sp -1
257.IP \(bu 2.3
258.\}
259
260\FCRS1\F[]
261\- This must be the value 1699505740\&.
262.RE
263.sp
264.RS 4
265.ie n \{\
266\h'-04'\(bu\h'+03'\c
267.\}
268.el \{\
269.sp -1
270.IP \(bu 2.3
271.\}
272
273\FCRCN\F[]
274\- This field should be 0\&.
275.RE
276.sp
277.RS 4
278.ie n \{\
279\h'-04'\(bu\h'+03'\c
280.\}
281.el \{\
282.sp -1
283.IP \(bu 2.3
284.\}
285
286\FCTMG\F[]
287\- The time the eventlog record was generated; format is the number of seconds since 00:00:00 January 1, 1970, UTC\&.
288.RE
289.sp
290.RS 4
291.ie n \{\
292\h'-04'\(bu\h'+03'\c
293.\}
294.el \{\
295.sp -1
296.IP \(bu 2.3
297.\}
298
299\FCTMW\F[]
300\- The time the eventlog record was written; format is the number of seconds since 00:00:00 January 1, 1970, UTC\&.
301.RE
302.sp
303.RS 4
304.ie n \{\
305\h'-04'\(bu\h'+03'\c
306.\}
307.el \{\
308.sp -1
309.IP \(bu 2.3
310.\}
311
312\FCEID\F[]
313\- The eventlog ID\&.
314.RE
315.sp
316.RS 4
317.ie n \{\
318\h'-04'\(bu\h'+03'\c
319.\}
320.el \{\
321.sp -1
322.IP \(bu 2.3
323.\}
324
325\FCETP\F[]
326\- The event type \-\- one of "INFO", "ERROR", "WARNING", "AUDIT SUCCESS" or "AUDIT FAILURE"\&.
327.RE
328.sp
329.RS 4
330.ie n \{\
331\h'-04'\(bu\h'+03'\c
332.\}
333.el \{\
334.sp -1
335.IP \(bu 2.3
336.\}
337
338\FCECT\F[]
339\- The event category; this depends on the message file\&. It is primarily used as a means of filtering in the eventlog viewer\&.
340.RE
341.sp
342.RS 4
343.ie n \{\
344\h'-04'\(bu\h'+03'\c
345.\}
346.el \{\
347.sp -1
348.IP \(bu 2.3
349.\}
350
351\FCRS2\F[]
352\- This field should be 0\&.
353.RE
354.sp
355.RS 4
356.ie n \{\
357\h'-04'\(bu\h'+03'\c
358.\}
359.el \{\
360.sp -1
361.IP \(bu 2.3
362.\}
363
364\FCCRN\F[]
365\- This field should be 0\&.
366.RE
367.sp
368.RS 4
369.ie n \{\
370\h'-04'\(bu\h'+03'\c
371.\}
372.el \{\
373.sp -1
374.IP \(bu 2.3
375.\}
376
377\FCUSL\F[]
378\- This field should be 0\&.
379.RE
380.sp
381.RS 4
382.ie n \{\
383\h'-04'\(bu\h'+03'\c
384.\}
385.el \{\
386.sp -1
387.IP \(bu 2.3
388.\}
389
390\FCSRC\F[]
391\- This field contains the source name associated with the event log\&. If a message file is used with an event log, there will be a registry entry for associating this source name with a message file DLL\&.
392.RE
393.sp
394.RS 4
395.ie n \{\
396\h'-04'\(bu\h'+03'\c
397.\}
398.el \{\
399.sp -1
400.IP \(bu 2.3
401.\}
402
403\FCSRN\F[]
404\- The name of the machine on which the eventlog was generated\&. This is typically the host name\&.
405.RE
406.sp
407.RS 4
408.ie n \{\
409\h'-04'\(bu\h'+03'\c
410.\}
411.el \{\
412.sp -1
413.IP \(bu 2.3
414.\}
415
416\FCSTR\F[]
417\- The text associated with the eventlog\&. There may be more than one string in a record\&.
418.RE
419.sp
420.RS 4
421.ie n \{\
422\h'-04'\(bu\h'+03'\c
423.\}
424.el \{\
425.sp -1
426.IP \(bu 2.3
427.\}
428
429\FCDAT\F[]
430\- This field should be left unset\&.
431.SH "EXAMPLES"
432.PP
433An example of the record format accepted by
434\FCeventlogadm\F[]:
435.sp
436.if n \{\
437.RS 4
438.\}
439.fam C
440.ps -1
441.nf
442.if t \{\
443.sp -1
444.\}
445.BB lightgray adjust-for-leading-newline
446.sp -1
447
448 LEN: 0
449 RS1: 1699505740
450 RCN: 0
451 TMG: 1128631322
452 TMW: 1128631322
453 EID: 1000
454 ETP: INFO
455 ECT: 0
456 RS2: 0
457 CRN: 0
458 USL: 0
459 SRC: cron
460 SRN: dmlinux
461 STR: (root) CMD ( rm \-f /var/spool/cron/lastrun/cron\&.hourly)
462 DAT:
463
464.EB lightgray adjust-for-leading-newline
465.if t \{\
466.sp 1
467.\}
468.fi
469.fam
470.ps +1
471.if n \{\
472.RE
473.\}
474.PP
475Set up an eventlog source, specifying a message file DLL:
476.sp
477.if n \{\
478.RS 4
479.\}
480.fam C
481.ps -1
482.nf
483.if t \{\
484.sp -1
485.\}
486.BB lightgray adjust-for-leading-newline
487.sp -1
488
489 eventlogadm \-o addsource Application MyApplication | \e\e
490 %SystemRoot%/system32/MyApplication\&.dll
491
492.EB lightgray adjust-for-leading-newline
493.if t \{\
494.sp 1
495.\}
496.fi
497.fam
498.ps +1
499.if n \{\
500.RE
501.\}
502.PP
503Filter messages from the system log into an event log:
504.sp
505.if n \{\
506.RS 4
507.\}
508.fam C
509.ps -1
510.nf
511.if t \{\
512.sp -1
513.\}
514.BB lightgray adjust-for-leading-newline
515.sp -1
516
517 tail \-f /var/log/messages | \e\e
518 my_program_to_parse_into_eventlog_records | \e\e
519 eventlogadm SystemLogEvents
520
521.EB lightgray adjust-for-leading-newline
522.if t \{\
523.sp 1
524.\}
525.fi
526.fam
527.ps +1
528.if n \{\
529.RE
530.\}
531.SH "VERSION"
532.PP
533This man page is correct for version 3\&.0\&.25 of the Samba suite\&.
534.SH "AUTHOR"
535.PP
536The original Samba software and related utilities were created by Andrew Tridgell\&. Samba is now developed by the Samba Team as an Open Source project similar to the way the Linux kernel is developed\&.
Note: See TracBrowser for help on using the repository browser.