6.6.1. Starting the Alliance subsystem

After configuring the global options and a TCP communications client, you must start the Alliance subsystem ALLSYL100 to start collecting logs. On the configuration menu take the option to Start Syslog Subsystem. The following panel is displayed:

Start sending logs to the syslog-ng server

Figure 6.6. Start sending logs to the syslog-ng server


Press Enter to start the subsystem. Depending on the configuration options you have selected, the following jobs will appear in the subsystem:

You can use options on the Configuration menu to view active jobs in the Alliance ALLSYL100 subsystem, and to end the subsystem. You can also end the subsystem ALLSYL100 manually using the End Subsystem (ENDSBS) command with the *IMMED option.

[Note] Note

The first time you start the Alliance subsystem the audit journal and operator message queue processes will begin collecting information starting from the earliest message. If there is a substantial amount of history in the journal or message queue it may take time for these messages to be sent to the syslog-ng server.


© 2007-2010 BalaBit IT Security
Please send your comments or documentation bugs to: documentation@balabit.com