The syslog-ng Agent for Windows application can be installed on the domain controller and the members of a domain from the domain controller, and configured globally using group policies. The syslog-ng agent requires about 1 MB hard disk space.
To install the syslog-ng Agent application in a domain, see Procedure 5.1.2.1, “Installing the syslog-ng agent on the domain controller and the hosts of a domain”.
To configure the syslog-ng agents of the domain hosts, see Procedure 5.1.2.2, “Configuring the syslog-ng agents of the domain hosts”.
To configure the syslog-ng agents of the domain controllers, see Procedure 5.1.2.3, “Configuring the syslog-ng agents of the domain controllers”.
![]() |
Note |
|---|---|
Starting from version |
Procedure 5.1.2.1. Installing the syslog-ng agent on the domain controller and the hosts of a domain
![]() |
Note |
|---|---|
|
Starting from version 3.0.3, the syslog-ng Agent sends only messages that
are created after the agent has been installed. If you want to send old log
messages to the syslog-ng server, download the Orca MSI editor from http://www.technipages.com/download-orca-msi-editor.html, open
the .msi installer of the syslog-ng Agent, select
Property, and change the value of the
SENDOLDMESSAGES field to
Alternatively, you can also create an XML configuration file for the agent, and configure it to send the old messages. For details on using an XML-based configuration file for the installation, see Section 5.7, “Using an XML-based configuration file”. |
Download both the Microsoft Installer (.msi)
version and the executable (.exe) version of the
syslog-ng agent installer to the domain controller host. Make sure to
download the executable that includes the MMC snap-in module. Note that
separate .msi intallers are available for 32-bit and 64-bit operating
systems.
![]() |
Note |
|---|---|
|
Installing the syslog-ng agent requires administrator privileges, but configuring the related group policies on the domain controller requires domain administrator or higher (e.g., enterprise administrator) privileges. |
Install the syslog-ng Agent application to your domain controllers using
the .exe installer.
![]() |
Note |
|---|---|
|
The syslog-ng Agent for Windows requires the Microsoft .NET Framework version 2.0. This package is usually already installed on most hosts. It can be downloaded at: |
Select , right-click on the Organizational Unit of the domain whose hosts you want to install the syslog-ng agent on, and select .
Select , and edit the Group Policy object you want to add the syslog-ng agent configuration to. Alternatively, you can create a new group policy object as well.
Select , right-click on , and select .
Navigate to the syslog-ng Agent for Windows .msi
installer and select .
Select , then .
Select Computer Configuration > syslog-ng Agent Settings and configure the syslog-ng Agent. The members of the domain will use this configuration.
The syslog-ng Agent for Windows application will be automatically installed on the members of the domain when they are next rebooted. To perform the installation earlier, execute the gpupdate command on the members of the domain.
![]() |
Note |
|---|---|
If you do not want to install the syslog-ng Agent automatically from the domain controller, skip Steps 5-7, complete Step 8, then install the |
Procedure 5.1.2.2. Configuring the syslog-ng agents of the domain hosts
To configure an already installed syslog-ng agent from the domain controller, perform the following steps.
On the domain controller, select .
Right-click on the Organizational Unit, then select .
Configure the syslog-ng agent as needed for the domain hosts. The changes will take affect when the domain hosts update their settings from the domain controller. By default, this happens every 90 minutes, depending on your domain settings. To download the configuration earlier, execute the gpupdate command on the members of the domain.
![]() |
Note |
|---|---|
When the domain hosts update their settings, the syslog-ng agent will be automatically restarted to load the new settings, except when there is no difference between the old and the new settings. |
Procedure 5.1.2.3. Configuring the syslog-ng agents of the domain controllers
To configure the syslog-ng agent running on the domain controllers, perform the following steps.
On the domain controller, select .
Right-click on the Organizational Unit of the domain whose domain controllers you want to configure, then select . By default, the domain controllers are in the Domain Controllers organizational unit.
Select , and edit the Group Policy object you want to add the syslog-ng agent configuration to. Alternatively, you can create a new group policy object as well.
Select Computer Configuration > syslog-ng Agent Settings and configure the syslog-ng Agent. The domain controllers of the domain will use this configuration.
Configure the syslog-ng agent as needed for the domain controllers. If you have multiple domain controllers, the changes will take affect when the other domain controllers update their settings from this domain controller. By default, this happens every 5 minutes, depending on your domain settings. To download the configuration earlier, execute the gpupdate command on the domain controllers.
![]() |
Note |
|---|---|
When the domain controllers receive the new settings, the syslog-ng agent will be automatically restarted to load the new settings, except when there is no difference between the old and the new settings. |
© 2007-2010 BalaBit IT Security
Please send your comments or documentation bugs to: documentation@balabit.com