This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

Solarwinds NPM/SAM forward snmp and syslog to Kiwi server ?

Solarwinds NPM/SAM  forward snmp and syslog to Kiwi server, cant this be done ?

currently all syslog and trap collections are going to NPM/SaM for fitering and alerting. 

There is a legal requirement to keep the log data for  3years.   right now the syslog and trapping is generating 12 gb perweek.

I would like to send the syslog and trap to a kiwi server and use the archiving schedule.

I know I can just send the data to kiwi but man power prevents me from getting configuration items done.

can this be done ?

  • Ah, this is  topic near and dear to my heart. Can I suggest that you actually do it the other way:

    Set up a load balancer doing UDB round-robin to a pool of Kiwi Syslog servers (they can be virtual machines)

    Set up rules on the kiwi systems to

    1. write all messages to a database (a built-in action)
    2. filter out the garbage you don't need
    3. transparently forward (again, a built-in action) the meaningful messages (cold start, spanning tree, BGP neighbor down, etc) to your NPM server

    I talk about this in this video: https://www.youtube.com/watch?v=8u61Faf6maI

  • Whilst Leon's way is way more cool, couldn't you just add "Forward the Syslog Message" and put it at the top of the Alerts/Filter Rules section?

    pastedImage_0.png