<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic can we do something about the Zonedirector 12xx &amp;quot;remote syslog&amp;quot; in ZoneDirector</title>
    <link>https://community.ruckuswireless.com/t5/ZoneDirector/can-we-do-something-about-the-Zonedirector-12xx-quot-remote/m-p/21339#M4367</link>
    <description>Has anyone actually tried&amp;nbsp; intergrating&amp;nbsp; ruckus with something like&amp;nbsp; "WAZUH"&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;There are two ways to normally intergrate products:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;1. An agent... not possible&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;2. Via the syslog.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Sadly the syslog output from&amp;nbsp; the ZD &amp;amp; wifi points is a complete mess&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;here is an example of what the remote "wazuh" server recieves...&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Jul&amp;nbsp; 9 16:22:23 ZD-APMgr: IPC_thread rcv ping from TACMON &lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Jul&amp;nbsp; 9 16:22:35 stamgr: tac_del_arp:dev=br0 SIOCDARP failed, errno=6 &lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Jul&amp;nbsp; 9 16:22:35 syslog: eventd_to_syslog():AP[AP11@f0:b0:52:15:d8:f0] radio [11a/n/ac] detects User[yuanhui.zhang@d8:a3:15:ff:5c:83] in WLAN[some Office User] roams out to AP[AP10@f0:b0:52:15:7b:90] &lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Jul&amp;nbsp; 9 16:22:35 syslog: eventd_to_syslog():AP[AP10@f0:b0:52:15:7b:90] radio [11g/n] detects User[yuanhui.zhang@d8:a3:15:ff:5c:83] in WLAN[some&amp;nbsp; Office User] roams from AP[AP11@f0:b0:52:15:d8:f0] &lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Jul&amp;nbsp; 9 07:37:48 APMgr@AP08: lwapp_update_role_based_access_pcy_me: attached role based policy_id :0, policy6_id :0 to station me_type=201 84:a1:34:4c:f3:e7&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Basically this is complete garbage to parse, if you have multiple systems sending logs...&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;how to even begin to parse: 16:22:35 stamgr or 16:22:35 syslog:&amp;nbsp;&amp;nbsp; over multiple systems all sending UDP packets...&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;why can it not be better organised:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;EG:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt; ZD-APMgr: line no {date &amp;amp; time something industry standard},"some standard message format"&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;then do the same for the AP's&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;so separated lines can be linked together, when you have multiple feeds &amp;amp; multiple ZD's into the same log server, and the "line no" tells you if the UDP has lost something...&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;That way the&amp;nbsp; absolute start of the line can be "regex" to a trigger to save processing masses of log data&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;yep... it's the ZD.. we want it....&amp;nbsp; good luck with "16:22:35 stamgr or 16:22:35 syslog"&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
    <pubDate>Thu, 09 Jul 2020 08:33:35 GMT</pubDate>
    <dc:creator>itdept_head_me</dc:creator>
    <dc:date>2020-07-09T08:33:35Z</dc:date>
    <item>
      <title>can we do something about the Zonedirector 12xx "remote syslog"</title>
      <link>https://community.ruckuswireless.com/t5/ZoneDirector/can-we-do-something-about-the-Zonedirector-12xx-quot-remote/m-p/21339#M4367</link>
      <description>Has anyone actually tried&amp;nbsp; intergrating&amp;nbsp; ruckus with something like&amp;nbsp; "WAZUH"&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;There are two ways to normally intergrate products:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;1. An agent... not possible&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;2. Via the syslog.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Sadly the syslog output from&amp;nbsp; the ZD &amp;amp; wifi points is a complete mess&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;here is an example of what the remote "wazuh" server recieves...&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Jul&amp;nbsp; 9 16:22:23 ZD-APMgr: IPC_thread rcv ping from TACMON &lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Jul&amp;nbsp; 9 16:22:35 stamgr: tac_del_arp:dev=br0 SIOCDARP failed, errno=6 &lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Jul&amp;nbsp; 9 16:22:35 syslog: eventd_to_syslog():AP[AP11@f0:b0:52:15:d8:f0] radio [11a/n/ac] detects User[yuanhui.zhang@d8:a3:15:ff:5c:83] in WLAN[some Office User] roams out to AP[AP10@f0:b0:52:15:7b:90] &lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Jul&amp;nbsp; 9 16:22:35 syslog: eventd_to_syslog():AP[AP10@f0:b0:52:15:7b:90] radio [11g/n] detects User[yuanhui.zhang@d8:a3:15:ff:5c:83] in WLAN[some&amp;nbsp; Office User] roams from AP[AP11@f0:b0:52:15:d8:f0] &lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Jul&amp;nbsp; 9 07:37:48 APMgr@AP08: lwapp_update_role_based_access_pcy_me: attached role based policy_id :0, policy6_id :0 to station me_type=201 84:a1:34:4c:f3:e7&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Basically this is complete garbage to parse, if you have multiple systems sending logs...&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;how to even begin to parse: 16:22:35 stamgr or 16:22:35 syslog:&amp;nbsp;&amp;nbsp; over multiple systems all sending UDP packets...&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;why can it not be better organised:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;EG:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt; ZD-APMgr: line no {date &amp;amp; time something industry standard},"some standard message format"&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;then do the same for the AP's&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;so separated lines can be linked together, when you have multiple feeds &amp;amp; multiple ZD's into the same log server, and the "line no" tells you if the UDP has lost something...&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;That way the&amp;nbsp; absolute start of the line can be "regex" to a trigger to save processing masses of log data&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;yep... it's the ZD.. we want it....&amp;nbsp; good luck with "16:22:35 stamgr or 16:22:35 syslog"&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
      <pubDate>Thu, 09 Jul 2020 08:33:35 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ZoneDirector/can-we-do-something-about-the-Zonedirector-12xx-quot-remote/m-p/21339#M4367</guid>
      <dc:creator>itdept_head_me</dc:creator>
      <dc:date>2020-07-09T08:33:35Z</dc:date>
    </item>
  </channel>
</rss>

