Changeset 368 for branches/samba-3.3.x/docs/manpages/eventlogadm.8
- Timestamp:
- Jan 15, 2010, 8:21:06 AM (16 years ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
branches/samba-3.3.x/docs/manpages/eventlogadm.8
r342 r368 1 '\" t 1 2 .\" Title: eventlogadm 2 3 .\" Author: [see the "AUTHOR" section] 3 .\" Generator: DocBook XSL Stylesheets v1.7 4.0<http://docbook.sf.net/>4 .\" Date: 10/12/20094 .\" Generator: DocBook XSL Stylesheets v1.75.2 <http://docbook.sf.net/> 5 .\" Date: 01/14/2010 5 6 .\" Manual: System Administration tools 6 7 .\" Source: Samba 3.3 7 8 .\" Language: English 8 9 .\" 9 .TH "EVENTLOGADM" "8" "10/12/2009" "Samba 3\&.3" "System Administration tools" 10 .\" ----------------------------------------------------------------- 11 .\" * (re)Define some macros 12 .\" ----------------------------------------------------------------- 13 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 14 .\" toupper - uppercase a string (locale-aware) 15 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 16 .de toupper 17 .tr aAbBcCdDeEfFgGhHiIjJkKlLmMnNoOpPqQrRsStTuUvVwWxXyYzZ 18 \\$* 19 .tr aabbccddeeffgghhiijjkkllmmnnooppqqrrssttuuvvwwxxyyzz 20 .. 21 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 22 .\" SH-xref - format a cross-reference to an SH section 23 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 24 .de SH-xref 25 .ie n \{\ 26 .\} 27 .toupper \\$* 28 .el \{\ 29 \\$* 30 .\} 31 .. 32 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 33 .\" SH - level-one heading that works better for non-TTY output 34 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 35 .de1 SH 36 .\" put an extra blank line of space above the head in non-TTY output 37 .if t \{\ 38 .sp 1 39 .\} 40 .sp \\n[PD]u 41 .nr an-level 1 42 .set-an-margin 43 .nr an-prevailing-indent \\n[IN] 44 .fi 45 .in \\n[an-margin]u 46 .ti 0 47 .HTML-TAG ".NH \\n[an-level]" 48 .it 1 an-trap 49 .nr an-no-space-flag 1 50 .nr an-break-flag 1 51 \." make the size of the head bigger 52 .ps +3 53 .ft B 54 .ne (2v + 1u) 55 .ie n \{\ 56 .\" if n (TTY output), use uppercase 57 .toupper \\$* 58 .\} 59 .el \{\ 60 .nr an-break-flag 0 61 .\" if not n (not TTY), use normal case (not uppercase) 62 \\$1 63 .in \\n[an-margin]u 64 .ti 0 65 .\" if not n (not TTY), put a border/line under subheading 66 .sp -.6 67 \l'\n(.lu' 68 .\} 69 .. 70 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 71 .\" SS - level-two heading that works better for non-TTY output 72 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 73 .de1 SS 74 .sp \\n[PD]u 75 .nr an-level 1 76 .set-an-margin 77 .nr an-prevailing-indent \\n[IN] 78 .fi 79 .in \\n[IN]u 80 .ti \\n[SN]u 81 .it 1 an-trap 82 .nr an-no-space-flag 1 83 .nr an-break-flag 1 84 .ps \\n[PS-SS]u 85 \." make the size of the head bigger 86 .ps +2 87 .ft B 88 .ne (2v + 1u) 89 .if \\n[.$] \&\\$* 90 .. 91 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 92 .\" BB/BE - put background/screen (filled box) around block of text 93 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 94 .de BB 95 .if t \{\ 96 .sp -.5 97 .br 98 .in +2n 99 .ll -2n 100 .gcolor red 101 .di BX 102 .\} 103 .. 104 .de EB 105 .if t \{\ 106 .if "\\$2"adjust-for-leading-newline" \{\ 107 .sp -1 108 .\} 109 .br 110 .di 111 .in 112 .ll 113 .gcolor 114 .nr BW \\n(.lu-\\n(.i 115 .nr BH \\n(dn+.5v 116 .ne \\n(BHu+.5v 117 .ie "\\$2"adjust-for-leading-newline" \{\ 118 \M[\\$1]\h'1n'\v'+.5v'\D'P \\n(BWu 0 0 \\n(BHu -\\n(BWu 0 0 -\\n(BHu'\M[] 119 .\} 120 .el \{\ 121 \M[\\$1]\h'1n'\v'-.5v'\D'P \\n(BWu 0 0 \\n(BHu -\\n(BWu 0 0 -\\n(BHu'\M[] 122 .\} 123 .in 0 124 .sp -.5v 125 .nf 126 .BX 127 .in 128 .sp .5v 129 .fi 130 .\} 131 .. 132 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 133 .\" BM/EM - put colored marker in margin next to block of text 134 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 135 .de BM 136 .if t \{\ 137 .br 138 .ll -2n 139 .gcolor red 140 .di BX 141 .\} 142 .. 143 .de EM 144 .if t \{\ 145 .br 146 .di 147 .ll 148 .gcolor 149 .nr BH \\n(dn 150 .ne \\n(BHu 151 \M[\\$1]\D'P -.75n 0 0 \\n(BHu -(\\n[.i]u - \\n(INu - .75n) 0 0 -\\n(BHu'\M[] 152 .in 0 153 .nf 154 .BX 155 .in 156 .fi 157 .\} 158 .. 10 .TH "EVENTLOGADM" "8" "01/14/2010" "Samba 3\&.3" "System Administration tools" 159 11 .\" ----------------------------------------------------------------- 160 12 .\" * set default formatting … … 167 19 .\" * MAIN CONTENT STARTS HERE * 168 20 .\" ----------------------------------------------------------------- 169 .SH "N ame"21 .SH "NAME" 170 22 eventlogadm \- push records into the Samba event log store 171 .SH "Synopsis" 172 .fam C 23 .SH "SYNOPSIS" 173 24 .HP \w'\ 'u 174 \FCeventlogadm\F[] [\fB\-d\fR] [\fB\-h\fR] \fB\-o\fR\ \FCaddsource\F[]\ \fIEVENTLOG\fR\ \fISOURCENAME\fR\ \fIMSGFILE\fR 175 .fam 176 .fam C 25 eventlogadm [\fB\-d\fR] [\fB\-h\fR] \fB\-o\fR\ addsource\ \fIEVENTLOG\fR\ \fISOURCENAME\fR\ \fIMSGFILE\fR 177 26 .HP \w'\ 'u 178 \FCeventlogadm\F[] [\fB\-d\fR] [\fB\-h\fR] \fB\-o\fR\ \FCwrite\F[]\ \fIEVENTLOG\fR 179 .fam 27 eventlogadm [\fB\-d\fR] [\fB\-h\fR] \fB\-o\fR\ write\ \fIEVENTLOG\fR 180 28 .SH "DESCRIPTION" 181 29 .PP … … 184 32 suite\&. 185 33 .PP 186 \FCeventlogadm\F[] 34 eventlogadm 187 35 is a filter that accepts formatted event log records on standard input and writes them to the Samba event log store\&. Windows client can then manipulate these record using the usual administration tools\&. 188 36 .SH "OPTIONS" … … 191 39 .RS 4 192 40 The 193 \ FC\-d\F[]41 \-d 194 42 option causes 195 \FCeventlogadm\F[] 43 eventlogadm 196 44 to emit debugging information\&. 197 45 .RE 198 46 .PP 199 \fB\-o\fR \FCaddsource\F[]\fIEVENTLOG\fR \fISOURCENAME\fR \fIMSGFILE\fR47 \fB\-o\fR addsource \fIEVENTLOG\fR \fISOURCENAME\fR \fIMSGFILE\fR 200 48 .RS 4 201 49 The 202 \ FC\-o addsource\F[]50 \-o addsource 203 51 option creates a new event log source\&. 204 52 .RE 205 53 .PP 206 \fB\-o\fR \FCwrite\F[]\fIEVENTLOG\fR54 \fB\-o\fR write \fIEVENTLOG\fR 207 55 .RS 4 208 56 The 209 \ FC\-o write\F[]57 \-o write 210 58 reads event log records from standard input and writes them to the Samba event log store named by EVENTLOG\&. 211 59 .RE … … 218 66 .PP 219 67 For the write operation, 220 \FCeventlogadm\F[] 68 eventlogadm 221 69 expects to be able to read structured records from standard input\&. These records are a sequence of lines, with the record key and data separated by a colon character\&. Records are separated by at least one or more blank line\&. 222 70 .PP … … 232 80 .\} 233 81 234 \FCLEN\F[] 82 LEN 235 83 \- This field should be 0, since 236 \FCeventlogadm\F[] 84 eventlogadm 237 85 will calculate this value\&. 238 86 .RE … … 247 95 .\} 248 96 249 \FCRS1\F[] 97 RS1 250 98 \- This must be the value 1699505740\&. 251 99 .RE … … 260 108 .\} 261 109 262 \FCRCN\F[] 110 RCN 263 111 \- This field should be 0\&. 264 112 .RE … … 273 121 .\} 274 122 275 \FCTMG\F[] 123 TMG 276 124 \- The time the eventlog record was generated; format is the number of seconds since 00:00:00 January 1, 1970, UTC\&. 277 125 .RE … … 286 134 .\} 287 135 288 \FCTMW\F[] 136 TMW 289 137 \- The time the eventlog record was written; format is the number of seconds since 00:00:00 January 1, 1970, UTC\&. 290 138 .RE … … 299 147 .\} 300 148 301 \FCEID\F[] 149 EID 302 150 \- The eventlog ID\&. 303 151 .RE … … 312 160 .\} 313 161 314 \FCETP\F[] 162 ETP 315 163 \- The event type \-\- one of "INFO", "ERROR", "WARNING", "AUDIT SUCCESS" or "AUDIT FAILURE"\&. 316 164 .RE … … 325 173 .\} 326 174 327 \FCECT\F[] 175 ECT 328 176 \- The event category; this depends on the message file\&. It is primarily used as a means of filtering in the eventlog viewer\&. 329 177 .RE … … 338 186 .\} 339 187 340 \FCRS2\F[] 188 RS2 341 189 \- This field should be 0\&. 342 190 .RE … … 351 199 .\} 352 200 353 \FCCRN\F[] 201 CRN 354 202 \- This field should be 0\&. 355 203 .RE … … 364 212 .\} 365 213 366 \FCUSL\F[] 214 USL 367 215 \- This field should be 0\&. 368 216 .RE … … 377 225 .\} 378 226 379 \FCSRC\F[] 227 SRC 380 228 \- This field contains the source name associated with the event log\&. If a message file is used with an event log, there will be a registry entry for associating this source name with a message file DLL\&. 381 229 .RE … … 390 238 .\} 391 239 392 \FCSRN\F[] 240 SRN 393 241 \- The name of the machine on which the eventlog was generated\&. This is typically the host name\&. 394 242 .RE … … 403 251 .\} 404 252 405 \FCSTR\F[] 253 STR 406 254 \- The text associated with the eventlog\&. There may be more than one string in a record\&. 407 255 .RE … … 416 264 .\} 417 265 418 \FCDAT\F[] 266 DAT 419 267 \- This field should be left unset\&. 420 268 .SH "EXAMPLES" 421 269 .PP 422 270 An example of the record format accepted by 423 \FCeventlogadm\F[]: 424 .sp 425 .if n \{\ 426 .RS 4 427 .\} 428 .fam C 429 .ps -1 271 eventlogadm: 272 .sp 273 .if n \{\ 274 .RS 4 275 .\} 430 276 .nf 431 .if t \{\432 .sp -1433 .\}434 .BB lightgray adjust-for-leading-newline435 .sp -1436 437 277 LEN: 0 438 278 RS1: 1699505740 … … 451 291 DAT: 452 292 453 .EB lightgray adjust-for-leading-newline454 .if t \{\455 .sp 1456 .\}457 293 .fi 458 .fam459 .ps +1460 294 .if n \{\ 461 295 .RE … … 467 301 .RS 4 468 302 .\} 469 .fam C470 .ps -1471 303 .nf 472 .if t \{\473 .sp -1474 .\}475 .BB lightgray adjust-for-leading-newline476 .sp -1477 478 304 eventlogadm \-o addsource Application MyApplication | \e\e 479 305 %SystemRoot%/system32/MyApplication\&.dll 480 306 481 .EB lightgray adjust-for-leading-newline482 .if t \{\483 .sp 1484 .\}485 307 .fi 486 .fam487 .ps +1488 308 .if n \{\ 489 309 .RE … … 495 315 .RS 4 496 316 .\} 497 .fam C498 .ps -1499 317 .nf 500 .if t \{\501 .sp -1502 .\}503 .BB lightgray adjust-for-leading-newline504 .sp -1505 506 318 tail \-f /var/log/messages | \e\e 507 319 my_program_to_parse_into_eventlog_records | \e\e 508 320 eventlogadm SystemLogEvents 509 321 510 .EB lightgray adjust-for-leading-newline511 .if t \{\512 .sp 1513 .\}514 322 .fi 515 .fam516 .ps +1517 323 .if n \{\ 518 324 .RE
Note:
See TracChangeset
for help on using the changeset viewer.