Changeset 134 for branches/samba-3.0/docs/manpages/eventlogadm.8
- Timestamp:
- May 23, 2008, 6:56:41 AM (17 years ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
branches/samba-3.0/docs/manpages/eventlogadm.8
r44 r134 1 .\"Generated by db2man.xsl. Don't modify this, modify the source. 2 .de Sh \" Subsection 3 .br 4 .if t .Sp 5 .ne 5 6 .PP 7 \fB\\$1\fR 8 .PP 9 .. 10 .de Sp \" Vertical space (when we can't use .PP) 11 .if t .sp .5v 12 .if n .sp 13 .. 14 .de Ip \" List item 15 .br 16 .ie \\n(.$>=3 .ne \\$3 17 .el .ne 3 18 .IP "\\$1" \\$2 19 .. 20 .TH "EVENTLOGADM" 8 "" "" "" 1 .\" Title: eventlogadm 2 .\" Author: 3 .\" Generator: DocBook XSL Stylesheets v1.73.2 <http://docbook.sf.net/> 4 .\" Date: 05/21/2008 5 .\" Manual: System Administration tools 6 .\" Source: Samba 3.0 7 .\" 8 .TH "EVENTLOGADM" "8" "05/21/2008" "Samba 3\.0" "System Administration tools" 9 .\" disable hyphenation 10 .nh 11 .\" disable justification (adjust text to left margin only) 12 .ad l 21 13 .SH "NAME" 22 14 eventlogadm - push records into the Samba event log store 23 15 .SH "SYNOPSIS" 24 16 .HP 1 25 eventlogadm [\fB -d\fR] [\fB-h\fR] \fB-o\fR addsource \fIEVENTLOG\fR \fISOURCENAME\fR\fIMSGFILE\fR17 eventlogadm [\fB\-d\fR] [\fB\-h\fR] \fB\-o\fR\ addsource\ \fIEVENTLOG\fR\ \fISOURCENAME\fR\ \fIMSGFILE\fR 26 18 .HP 1 27 eventlogadm [\fB -d\fR] [\fB-h\fR] \fB-o\fR write\fIEVENTLOG\fR19 eventlogadm [\fB\-d\fR] [\fB\-h\fR] \fB\-o\fR\ write\ \fIEVENTLOG\fR 28 20 .SH "DESCRIPTION" 29 21 .PP 30 22 This tool is part of the 31 23 \fBsamba\fR(1) 32 suite .24 suite\. 33 25 .PP 34 26 eventlogadm 35 is a filter that accepts formatted event log records on standard input and writes them to the Samba event log store . Windows client can then manipulate these record using the usual administration tools.27 is a filter that accepts formatted event log records on standard input and writes them to the Samba event log store\. Windows client can then manipulate these record using the usual administration tools\. 36 28 .SH "OPTIONS" 37 29 .PP 38 \fB -d\fR39 .RS 3n30 \fB\-d\fR 31 .RS 4 40 32 The 41 -d33 \-d 42 34 option causes 43 35 eventlogadm 44 to emit debugging information .45 .RE 46 .PP 47 \fB -o\fR addsource \fIEVENTLOG\fR \fISOURCENAME\fR \fIMSGFILE\fR48 .RS 3n36 to emit debugging information\. 37 .RE 38 .PP 39 \fB\-o\fR addsource \fIEVENTLOG\fR \fISOURCENAME\fR \fIMSGFILE\fR 40 .RS 4 49 41 The 50 -o addsource51 option creates a new event log source .52 .RE 53 .PP 54 \fB -o\fR write \fIEVENTLOG\fR55 .RS 3n42 \-o addsource 43 option creates a new event log source\. 44 .RE 45 .PP 46 \fB\-o\fR write \fIEVENTLOG\fR 47 .RS 4 56 48 The 57 -o write58 reads event log records from standard input and writes them to theSamba event log store named by EVENTLOG .59 .RE 60 .PP 61 \fB -h\fR62 .RS 3n63 Print usage information .49 \-o write 50 reads event log records from standard input and writes them to theSamba event log store named by EVENTLOG\. 51 .RE 52 .PP 53 \fB\-h\fR 54 .RS 4 55 Print usage information\. 64 56 .RE 65 57 .SH "EVENTLOG RECORD FORMAT" … … 67 59 For the write operation, 68 60 eventlogadm 69 expects to be able to read structured records from standard input . These records are a sequence of lines, with the record key and data separated by a colon character. Records are separated by at least one or more blank line.61 expects to be able to read structured records from standard input\. These records are a sequence of lines, with the record key and data separated by a colon character\. Records are separated by at least one or more blank line\. 70 62 .PP 71 63 The event log record field are: 72 .TP 3n 73 \(bu 64 .sp 65 .RS 4 66 .ie n \{\ 67 \h'-04'\(bu\h'+03'\c 68 .\} 69 .el \{\ 70 .sp -1 71 .IP \(bu 2.3 72 .\} 74 73 75 74 LEN 76 - This field should be 0, since75 \- This field should be 0, since 77 76 eventlogadm 78 will calculate this value. 79 .TP 3n 80 \(bu 77 will calculate this value\. 78 .RE 79 .sp 80 .RS 4 81 .ie n \{\ 82 \h'-04'\(bu\h'+03'\c 83 .\} 84 .el \{\ 85 .sp -1 86 .IP \(bu 2.3 87 .\} 81 88 82 89 RS1 83 - This must be the value 1699505740. 84 .TP 3n 85 \(bu 90 \- This must be the value 1699505740\. 91 .RE 92 .sp 93 .RS 4 94 .ie n \{\ 95 \h'-04'\(bu\h'+03'\c 96 .\} 97 .el \{\ 98 .sp -1 99 .IP \(bu 2.3 100 .\} 86 101 87 102 RCN 88 - This field should be 0. 89 .TP 3n 90 \(bu 103 \- This field should be 0\. 104 .RE 105 .sp 106 .RS 4 107 .ie n \{\ 108 \h'-04'\(bu\h'+03'\c 109 .\} 110 .el \{\ 111 .sp -1 112 .IP \(bu 2.3 113 .\} 91 114 92 115 TMG 93 - The time the eventlog record was generated; format is the number of seconds since 00:00:00 January 1, 1970, UTC. 94 .TP 3n 95 \(bu 116 \- The time the eventlog record was generated; format is the number of seconds since 00:00:00 January 1, 1970, UTC\. 117 .RE 118 .sp 119 .RS 4 120 .ie n \{\ 121 \h'-04'\(bu\h'+03'\c 122 .\} 123 .el \{\ 124 .sp -1 125 .IP \(bu 2.3 126 .\} 96 127 97 128 TMW 98 - The time the eventlog record was written; format is the number of seconds since 00:00:00 January 1, 1970, UTC. 99 .TP 3n 100 \(bu 129 \- The time the eventlog record was written; format is the number of seconds since 00:00:00 January 1, 1970, UTC\. 130 .RE 131 .sp 132 .RS 4 133 .ie n \{\ 134 \h'-04'\(bu\h'+03'\c 135 .\} 136 .el \{\ 137 .sp -1 138 .IP \(bu 2.3 139 .\} 101 140 102 141 EID 103 - The eventlog ID. 104 .TP 3n 105 \(bu 142 \- The eventlog ID\. 143 .RE 144 .sp 145 .RS 4 146 .ie n \{\ 147 \h'-04'\(bu\h'+03'\c 148 .\} 149 .el \{\ 150 .sp -1 151 .IP \(bu 2.3 152 .\} 106 153 107 154 ETP 108 - The event type -- one of "INFO", "ERROR", "WARNING", "AUDIT SUCCESS" or "AUDIT FAILURE". 109 .TP 3n 110 \(bu 155 \- The event type \-\- one of "INFO", "ERROR", "WARNING", "AUDIT SUCCESS" or "AUDIT FAILURE"\. 156 .RE 157 .sp 158 .RS 4 159 .ie n \{\ 160 \h'-04'\(bu\h'+03'\c 161 .\} 162 .el \{\ 163 .sp -1 164 .IP \(bu 2.3 165 .\} 111 166 112 167 ECT 113 - The event category; this depends on the message file. It is primarily used as a means of filtering in the eventlog viewer. 114 .TP 3n 115 \(bu 168 \- The event category; this depends on the message file\. It is primarily used as a means of filtering in the eventlog viewer\. 169 .RE 170 .sp 171 .RS 4 172 .ie n \{\ 173 \h'-04'\(bu\h'+03'\c 174 .\} 175 .el \{\ 176 .sp -1 177 .IP \(bu 2.3 178 .\} 116 179 117 180 RS2 118 - This field should be 0. 119 .TP 3n 120 \(bu 181 \- This field should be 0\. 182 .RE 183 .sp 184 .RS 4 185 .ie n \{\ 186 \h'-04'\(bu\h'+03'\c 187 .\} 188 .el \{\ 189 .sp -1 190 .IP \(bu 2.3 191 .\} 121 192 122 193 CRN 123 - This field should be 0. 124 .TP 3n 125 \(bu 194 \- This field should be 0\. 195 .RE 196 .sp 197 .RS 4 198 .ie n \{\ 199 \h'-04'\(bu\h'+03'\c 200 .\} 201 .el \{\ 202 .sp -1 203 .IP \(bu 2.3 204 .\} 126 205 127 206 USL 128 - This field should be 0. 129 .TP 3n 130 \(bu 207 \- This field should be 0\. 208 .RE 209 .sp 210 .RS 4 211 .ie n \{\ 212 \h'-04'\(bu\h'+03'\c 213 .\} 214 .el \{\ 215 .sp -1 216 .IP \(bu 2.3 217 .\} 131 218 132 219 SRC 133 - This field contains the source name associated with the event log. If a message file is used with an event log, there will be a registry entry for associating this source name with a message file DLL. 134 .TP 3n 135 \(bu 220 \- This field contains the source name associated with the event log\. If a message file is used with an event log, there will be a registry entry for associating this source name with a message file DLL\. 221 .RE 222 .sp 223 .RS 4 224 .ie n \{\ 225 \h'-04'\(bu\h'+03'\c 226 .\} 227 .el \{\ 228 .sp -1 229 .IP \(bu 2.3 230 .\} 136 231 137 232 SRN 138 - he name of the machine on which the eventlog was generated. This is typically the host name. 139 .TP 3n 140 \(bu 233 \- he name of the machine on which the eventlog was generated\. This is typically the host name\. 234 .RE 235 .sp 236 .RS 4 237 .ie n \{\ 238 \h'-04'\(bu\h'+03'\c 239 .\} 240 .el \{\ 241 .sp -1 242 .IP \(bu 2.3 243 .\} 141 244 142 245 STR 143 - The text associated with the eventlog. There may be more than one string in a record. 144 .TP 3n 145 \(bu 246 \- The text associated with the eventlog\. There may be more than one string in a record\. 247 .RE 248 .sp 249 .RS 4 250 .ie n \{\ 251 \h'-04'\(bu\h'+03'\c 252 .\} 253 .el \{\ 254 .sp -1 255 .IP \(bu 2.3 256 .\} 146 257 147 258 DAT 148 - This field should be left unset.259 \- This field should be left unset\. 149 260 .SH "EXAMPLES" 150 261 .PP 151 262 An example of the record format accepted by 152 263 eventlogadm: 153 264 .sp 265 .RS 4 154 266 .nf 155 156 267 LEN: 0 157 268 RS1: 1699505740 … … 159 270 TMG: 1128631322 160 271 TMW: 1128631322 161 EID: 1000 272 EID: 1000 162 273 ETP: INFO 163 ECT: 0 274 ECT: 0 164 275 RS2: 0 165 276 CRN: 0 … … 167 278 SRC: cron 168 279 SRN: dmlinux 169 STR: (root) CMD ( rm -f /var/spool/cron/lastrun/cron.hourly)170 DAT: 280 STR: (root) CMD ( rm \-f /var/spool/cron/lastrun/cron\.hourly) 281 DAT: 171 282 172 283 .fi 284 .RE 173 285 .PP 174 286 Set up an eventlog source, specifying a message file DLL: 175 287 .sp 288 .RS 4 176 289 .nf 177 178 eventlogadm -o addsource Application MyApplication | \\ 179 %SystemRoot%/system32/MyApplication.dll 290 eventlogadm \-o addsource Application MyApplication | \e\e 291 %SystemRoot%/system32/MyApplication\.dll 180 292 181 293 .fi 294 .RE 182 295 .PP 183 296 Filter messages from the system log into an event log: 184 297 .sp 298 .RS 4 185 299 .nf 186 187 tail -f /var/log/messages | \\ 188 my_program_to_parse_into_eventlog_records | \\ 300 tail \-f /var/log/messages | \e\e 301 my_program_to_parse_into_eventlog_records | \e\e 189 302 eventlogadm SystemLogEvents 190 303 191 304 .fi 305 .RE 192 306 .SH "VERSION" 193 307 .PP 194 This man page is correct for version 3 .0.25 of the Samba suite.308 This man page is correct for version 3\.0\.25 of the Samba suite\. 195 309 .SH "AUTHOR" 196 310 .PP 197 The original Samba software and related utilities were created by Andrew Tridgell. Samba is now developed by the Samba Team as an Open Source project similar to the way the Linux kernel is developed. 198 311 The original Samba software and related utilities were created by Andrew Tridgell\. Samba is now developed by the Samba Team as an Open Source project similar to the way the Linux kernel is developed\.
Note:
See TracChangeset
for help on using the changeset viewer.