This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

Kiwi Syslog V9.3 and Web Access

Hi,

 

When will the Web Access component point to the SQL database (SQL Enterprise) rather than create a seperate SQL CE database. The problem is that you can only go back a certain number of days in the CE database which defeats the object, espcially when you are logging into a core SQL database for all the key events.

Is my option only to write SQL queries on the Syslog database itself in SQL. When will Web Access be able to point to the Main SQL database rather than it's own.

For Audit requirements I need to show I can review logs that go back 3 months for PCI, while they are in the database itself I have no means of accessing unless I write a script each time.

Also the Archive features in the current version only point to log files itself, can the archive facility not be enabled for the main SQL log database as this will be much more useful and allows us to keep 3 months online and archive the rest automatically. Again will need to write a query to perform this at the moment on the SQL server itself.

I would have thought Kiwi Syslog to have this type of flexibility.

Regards

Julian

  • When will the Web Access component point to the SQL database (SQL Enterprise) rather than create a seperate SQL CE database. The problem is that you can only go back a certain number of days in the CE database which defeats the object, espcially when you are logging into a core SQL database for all the key events.

    Web Access was always intended for real-time access to recent Syslog data (versus historical without time limits).  We're exploring the expansion of Web Access beyond SQL CE, but it's not something on our immediate roadmap.   If long-term historical SQL storage is a must, you'll have to leverage your own queries for reporting.

    For Audit requirements I need to show I can review logs that go back 3 months for PCI, while they are in the database itself I have no means of accessing unless I write a script each time.

    One workaround is to log to the file system and use auto-split logic to separate out the log file into folders based on device for last 3 months to make in more easily manageable (and archived after that point).  Then, you can use Kiwi Log Viewer to search through a 3 month log file for a specific device as necessary.   This is much more inline with the intended use-case for Kiwi Syslog.