Changeset 429 for trunk/server/docs/manpages/eventlogadm.8
- Timestamp:
- Apr 9, 2010, 3:51:41 PM (15 years ago)
- Location:
- trunk/server
- Files:
-
- 2 edited
Legend:
- Unmodified
- Added
- Removed
-
trunk/server
-
Property svn:mergeinfo
set to
/vendor/3.5.2 merged eligible /vendor/current merged eligible
-
Property svn:mergeinfo
set to
-
trunk/server/docs/manpages/eventlogadm.8
r414 r429 1 '\" t2 1 .\" Title: eventlogadm 3 2 .\" Author: [see the "AUTHOR" section] 4 .\" Generator: DocBook XSL Stylesheets v1.7 5.2<http://docbook.sf.net/>5 .\" Date: 0 2/19/20103 .\" Generator: DocBook XSL Stylesheets v1.74.0 <http://docbook.sf.net/> 4 .\" Date: 03/30/2010 6 5 .\" Manual: System Administration tools 7 6 .\" Source: Samba 3.5 8 7 .\" Language: English 9 8 .\" 10 .TH "EVENTLOGADM" "8" "02/19/2010" "Samba 3\&.5" "System Administration tools" 9 .TH "EVENTLOGADM" "8" "03/30/2010" "Samba 3\&.5" "System Administration tools" 10 .\" ----------------------------------------------------------------- 11 .\" * (re)Define some macros 12 .\" ----------------------------------------------------------------- 13 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 14 .\" toupper - uppercase a string (locale-aware) 15 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 16 .de toupper 17 .tr aAbBcCdDeEfFgGhHiIjJkKlLmMnNoOpPqQrRsStTuUvVwWxXyYzZ 18 \\$* 19 .tr aabbccddeeffgghhiijjkkllmmnnooppqqrrssttuuvvwwxxyyzz 20 .. 21 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 22 .\" SH-xref - format a cross-reference to an SH section 23 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 24 .de SH-xref 25 .ie n \{\ 26 .\} 27 .toupper \\$* 28 .el \{\ 29 \\$* 30 .\} 31 .. 32 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 33 .\" SH - level-one heading that works better for non-TTY output 34 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 35 .de1 SH 36 .\" put an extra blank line of space above the head in non-TTY output 37 .if t \{\ 38 .sp 1 39 .\} 40 .sp \\n[PD]u 41 .nr an-level 1 42 .set-an-margin 43 .nr an-prevailing-indent \\n[IN] 44 .fi 45 .in \\n[an-margin]u 46 .ti 0 47 .HTML-TAG ".NH \\n[an-level]" 48 .it 1 an-trap 49 .nr an-no-space-flag 1 50 .nr an-break-flag 1 51 \." make the size of the head bigger 52 .ps +3 53 .ft B 54 .ne (2v + 1u) 55 .ie n \{\ 56 .\" if n (TTY output), use uppercase 57 .toupper \\$* 58 .\} 59 .el \{\ 60 .nr an-break-flag 0 61 .\" if not n (not TTY), use normal case (not uppercase) 62 \\$1 63 .in \\n[an-margin]u 64 .ti 0 65 .\" if not n (not TTY), put a border/line under subheading 66 .sp -.6 67 \l'\n(.lu' 68 .\} 69 .. 70 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 71 .\" SS - level-two heading that works better for non-TTY output 72 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 73 .de1 SS 74 .sp \\n[PD]u 75 .nr an-level 1 76 .set-an-margin 77 .nr an-prevailing-indent \\n[IN] 78 .fi 79 .in \\n[IN]u 80 .ti \\n[SN]u 81 .it 1 an-trap 82 .nr an-no-space-flag 1 83 .nr an-break-flag 1 84 .ps \\n[PS-SS]u 85 \." make the size of the head bigger 86 .ps +2 87 .ft B 88 .ne (2v + 1u) 89 .if \\n[.$] \&\\$* 90 .. 91 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 92 .\" BB/BE - put background/screen (filled box) around block of text 93 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 94 .de BB 95 .if t \{\ 96 .sp -.5 97 .br 98 .in +2n 99 .ll -2n 100 .gcolor red 101 .di BX 102 .\} 103 .. 104 .de EB 105 .if t \{\ 106 .if "\\$2"adjust-for-leading-newline" \{\ 107 .sp -1 108 .\} 109 .br 110 .di 111 .in 112 .ll 113 .gcolor 114 .nr BW \\n(.lu-\\n(.i 115 .nr BH \\n(dn+.5v 116 .ne \\n(BHu+.5v 117 .ie "\\$2"adjust-for-leading-newline" \{\ 118 \M[\\$1]\h'1n'\v'+.5v'\D'P \\n(BWu 0 0 \\n(BHu -\\n(BWu 0 0 -\\n(BHu'\M[] 119 .\} 120 .el \{\ 121 \M[\\$1]\h'1n'\v'-.5v'\D'P \\n(BWu 0 0 \\n(BHu -\\n(BWu 0 0 -\\n(BHu'\M[] 122 .\} 123 .in 0 124 .sp -.5v 125 .nf 126 .BX 127 .in 128 .sp .5v 129 .fi 130 .\} 131 .. 132 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 133 .\" BM/EM - put colored marker in margin next to block of text 134 .\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 135 .de BM 136 .if t \{\ 137 .br 138 .ll -2n 139 .gcolor red 140 .di BX 141 .\} 142 .. 143 .de EM 144 .if t \{\ 145 .br 146 .di 147 .ll 148 .gcolor 149 .nr BH \\n(dn 150 .ne \\n(BHu 151 \M[\\$1]\D'P -.75n 0 0 \\n(BHu -(\\n[.i]u - \\n(INu - .75n) 0 0 -\\n(BHu'\M[] 152 .in 0 153 .nf 154 .BX 155 .in 156 .fi 157 .\} 158 .. 11 159 .\" ----------------------------------------------------------------- 12 160 .\" * set default formatting … … 19 167 .\" * MAIN CONTENT STARTS HERE * 20 168 .\" ----------------------------------------------------------------- 21 .SH "N AME"169 .SH "Name" 22 170 eventlogadm \- push records into the Samba event log store 23 .SH "SYNOPSIS" 171 .SH "Synopsis" 172 .fam C 24 173 .HP \w'\ 'u 25 eventlogadm [\fB\-d\fR] [\fB\-h\fR] \fB\-o\fR\ addsource\ \fIEVENTLOG\fR\ \fISOURCENAME\fR\ \fIMSGFILE\fR 174 \FCeventlogadm\F[] [\fB\-d\fR] [\fB\-h\fR] \fB\-o\fR\ \FCaddsource\F[]\ \fIEVENTLOG\fR\ \fISOURCENAME\fR\ \fIMSGFILE\fR 175 .fam 176 .fam C 26 177 .HP \w'\ 'u 27 eventlogadm [\fB\-d\fR] [\fB\-h\fR] \fB\-o\fR\ write\ \fIEVENTLOG\fR 178 \FCeventlogadm\F[] [\fB\-d\fR] [\fB\-h\fR] \fB\-o\fR\ \FCwrite\F[]\ \fIEVENTLOG\fR 179 .fam 180 .fam C 28 181 .HP \w'\ 'u 29 eventlogadm [\fB\-d\fR] [\fB\-h\fR] \fB\-o\fR\ dump\ \fIEVENTLOG\fR\ \fIRECORD_NUMBER\fR 182 \FCeventlogadm\F[] [\fB\-d\fR] [\fB\-h\fR] \fB\-o\fR\ \FCdump\F[]\ \fIEVENTLOG\fR\ \fIRECORD_NUMBER\fR 183 .fam 30 184 .SH "DESCRIPTION" 31 185 .PP … … 34 188 suite\&. 35 189 .PP 36 eventlogadm 190 \FCeventlogadm\F[] 37 191 is a filter that accepts formatted event log records on standard input and writes them to the Samba event log store\&. Windows client can then manipulate these record using the usual administration tools\&. 38 192 .SH "OPTIONS" … … 41 195 .RS 4 42 196 The 43 \ -d197 \FC\-d\F[] 44 198 option causes 45 eventlogadm 199 \FCeventlogadm\F[] 46 200 to emit debugging information\&. 47 201 .RE 48 202 .PP 49 \fB\-o\fR addsource\fIEVENTLOG\fR \fISOURCENAME\fR \fIMSGFILE\fR203 \fB\-o\fR \FCaddsource\F[] \fIEVENTLOG\fR \fISOURCENAME\fR \fIMSGFILE\fR 50 204 .RS 4 51 205 The 52 \ -o addsource206 \FC\-o addsource\F[] 53 207 option creates a new event log source\&. 54 208 .RE 55 209 .PP 56 \fB\-o\fR write\fIEVENTLOG\fR210 \fB\-o\fR \FCwrite\F[] \fIEVENTLOG\fR 57 211 .RS 4 58 212 The 59 \ -o write213 \FC\-o write\F[] 60 214 reads event log records from standard input and writes them to the Samba event log store named by EVENTLOG\&. 61 215 .RE 62 216 .PP 63 \fB\-o\fR dump\fIEVENTLOG\fR \fIRECORD_NUMBER\fR217 \fB\-o\fR \FCdump\F[] \fIEVENTLOG\fR \fIRECORD_NUMBER\fR 64 218 .RS 4 65 219 The 66 \ -o dump220 \FC\-o dump\F[] 67 221 reads event log records from a EVENTLOG tdb and dumps them to standard output on screen\&. 68 222 .RE … … 75 229 .PP 76 230 For the write operation, 77 eventlogadm 231 \FCeventlogadm\F[] 78 232 expects to be able to read structured records from standard input\&. These records are a sequence of lines, with the record key and data separated by a colon character\&. Records are separated by at least one or more blank line\&. 79 233 .PP … … 89 243 .\} 90 244 91 LEN 245 \FCLEN\F[] 92 246 \- This field should be 0, since 93 eventlogadm 247 \FCeventlogadm\F[] 94 248 will calculate this value\&. 95 249 .RE … … 104 258 .\} 105 259 106 RS1 260 \FCRS1\F[] 107 261 \- This must be the value 1699505740\&. 108 262 .RE … … 117 271 .\} 118 272 119 RCN 273 \FCRCN\F[] 120 274 \- This field should be 0\&. 121 275 .RE … … 130 284 .\} 131 285 132 TMG 286 \FCTMG\F[] 133 287 \- The time the eventlog record was generated; format is the number of seconds since 00:00:00 January 1, 1970, UTC\&. 134 288 .RE … … 143 297 .\} 144 298 145 TMW 299 \FCTMW\F[] 146 300 \- The time the eventlog record was written; format is the number of seconds since 00:00:00 January 1, 1970, UTC\&. 147 301 .RE … … 156 310 .\} 157 311 158 EID 312 \FCEID\F[] 159 313 \- The eventlog ID\&. 160 314 .RE … … 169 323 .\} 170 324 171 ETP 325 \FCETP\F[] 172 326 \- The event type \-\- one of "INFO", "ERROR", "WARNING", "AUDIT SUCCESS" or "AUDIT FAILURE"\&. 173 327 .RE … … 182 336 .\} 183 337 184 ECT 338 \FCECT\F[] 185 339 \- The event category; this depends on the message file\&. It is primarily used as a means of filtering in the eventlog viewer\&. 186 340 .RE … … 195 349 .\} 196 350 197 RS2 351 \FCRS2\F[] 198 352 \- This field should be 0\&. 199 353 .RE … … 208 362 .\} 209 363 210 CRN 364 \FCCRN\F[] 211 365 \- This field should be 0\&. 212 366 .RE … … 221 375 .\} 222 376 223 USL 377 \FCUSL\F[] 224 378 \- This field should be 0\&. 225 379 .RE … … 234 388 .\} 235 389 236 SRC 390 \FCSRC\F[] 237 391 \- This field contains the source name associated with the event log\&. If a message file is used with an event log, there will be a registry entry for associating this source name with a message file DLL\&. 238 392 .RE … … 247 401 .\} 248 402 249 SRN 403 \FCSRN\F[] 250 404 \- The name of the machine on which the eventlog was generated\&. This is typically the host name\&. 251 405 .RE … … 260 414 .\} 261 415 262 STR 416 \FCSTR\F[] 263 417 \- The text associated with the eventlog\&. There may be more than one string in a record\&. 264 418 .RE … … 273 427 .\} 274 428 275 DAT 429 \FCDAT\F[] 276 430 \- This field should be left unset\&. 277 431 .SH "EXAMPLES" 278 432 .PP 279 433 An example of the record format accepted by 280 eventlogadm:434 \FCeventlogadm\F[]: 281 435 .sp 282 436 .if n \{\ 283 437 .RS 4 284 438 .\} 439 .fam C 440 .ps -1 285 441 .nf 442 .if t \{\ 443 .sp -1 444 .\} 445 .BB lightgray adjust-for-leading-newline 446 .sp -1 447 286 448 LEN: 0 287 449 RS1: 1699505740 … … 300 462 DAT: 301 463 302 .fi 464 .EB lightgray adjust-for-leading-newline 465 .if t \{\ 466 .sp 1 467 .\} 468 .fi 469 .fam 470 .ps +1 303 471 .if n \{\ 304 472 .RE … … 310 478 .RS 4 311 479 .\} 480 .fam C 481 .ps -1 312 482 .nf 483 .if t \{\ 484 .sp -1 485 .\} 486 .BB lightgray adjust-for-leading-newline 487 .sp -1 488 313 489 eventlogadm \-o addsource Application MyApplication | \e\e 314 490 %SystemRoot%/system32/MyApplication\&.dll 315 491 316 .fi 492 .EB lightgray adjust-for-leading-newline 493 .if t \{\ 494 .sp 1 495 .\} 496 .fi 497 .fam 498 .ps +1 317 499 .if n \{\ 318 500 .RE … … 324 506 .RS 4 325 507 .\} 508 .fam C 509 .ps -1 326 510 .nf 511 .if t \{\ 512 .sp -1 513 .\} 514 .BB lightgray adjust-for-leading-newline 515 .sp -1 516 327 517 tail \-f /var/log/messages | \e\e 328 518 my_program_to_parse_into_eventlog_records | \e\e 329 519 eventlogadm SystemLogEvents 330 520 331 .fi 521 .EB lightgray adjust-for-leading-newline 522 .if t \{\ 523 .sp 1 524 .\} 525 .fi 526 .fam 527 .ps +1 332 528 .if n \{\ 333 529 .RE
Note:
See TracChangeset
for help on using the changeset viewer.