diff options
Diffstat (limited to 'docs/manpages/eventlogadm.8')
-rw-r--r-- | docs/manpages/eventlogadm.8 | 268 |
1 files changed, 36 insertions, 232 deletions
diff --git a/docs/manpages/eventlogadm.8 b/docs/manpages/eventlogadm.8 index 59d3ec9bb7..045aba3b7c 100644 --- a/docs/manpages/eventlogadm.8 +++ b/docs/manpages/eventlogadm.8 @@ -1,161 +1,13 @@ +'\" t .\" Title: eventlogadm .\" Author: [see the "AUTHOR" section] -.\" Generator: DocBook XSL Stylesheets v1.74.0 <http://docbook.sf.net/> -.\" Date: 06/18/2010 +.\" Generator: DocBook XSL Stylesheets v1.75.2 <http://docbook.sf.net/> +.\" Date: 03/06/2011 .\" Manual: System Administration tools .\" Source: Samba 3.5 .\" Language: English .\" -.TH "EVENTLOGADM" "8" "06/18/2010" "Samba 3\&.5" "System Administration tools" -.\" ----------------------------------------------------------------- -.\" * (re)Define some macros -.\" ----------------------------------------------------------------- -.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -.\" toupper - uppercase a string (locale-aware) -.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -.de toupper -.tr aAbBcCdDeEfFgGhHiIjJkKlLmMnNoOpPqQrRsStTuUvVwWxXyYzZ -\\$* -.tr aabbccddeeffgghhiijjkkllmmnnooppqqrrssttuuvvwwxxyyzz -.. -.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -.\" SH-xref - format a cross-reference to an SH section -.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -.de SH-xref -.ie n \{\ -.\} -.toupper \\$* -.el \{\ -\\$* -.\} -.. -.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -.\" SH - level-one heading that works better for non-TTY output -.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -.de1 SH -.\" put an extra blank line of space above the head in non-TTY output -.if t \{\ -.sp 1 -.\} -.sp \\n[PD]u -.nr an-level 1 -.set-an-margin -.nr an-prevailing-indent \\n[IN] -.fi -.in \\n[an-margin]u -.ti 0 -.HTML-TAG ".NH \\n[an-level]" -.it 1 an-trap -.nr an-no-space-flag 1 -.nr an-break-flag 1 -\." make the size of the head bigger -.ps +3 -.ft B -.ne (2v + 1u) -.ie n \{\ -.\" if n (TTY output), use uppercase -.toupper \\$* -.\} -.el \{\ -.nr an-break-flag 0 -.\" if not n (not TTY), use normal case (not uppercase) -\\$1 -.in \\n[an-margin]u -.ti 0 -.\" if not n (not TTY), put a border/line under subheading -.sp -.6 -\l'\n(.lu' -.\} -.. -.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -.\" SS - level-two heading that works better for non-TTY output -.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -.de1 SS -.sp \\n[PD]u -.nr an-level 1 -.set-an-margin -.nr an-prevailing-indent \\n[IN] -.fi -.in \\n[IN]u -.ti \\n[SN]u -.it 1 an-trap -.nr an-no-space-flag 1 -.nr an-break-flag 1 -.ps \\n[PS-SS]u -\." make the size of the head bigger -.ps +2 -.ft B -.ne (2v + 1u) -.if \\n[.$] \&\\$* -.. -.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -.\" BB/BE - put background/screen (filled box) around block of text -.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -.de BB -.if t \{\ -.sp -.5 -.br -.in +2n -.ll -2n -.gcolor red -.di BX -.\} -.. -.de EB -.if t \{\ -.if "\\$2"adjust-for-leading-newline" \{\ -.sp -1 -.\} -.br -.di -.in -.ll -.gcolor -.nr BW \\n(.lu-\\n(.i -.nr BH \\n(dn+.5v -.ne \\n(BHu+.5v -.ie "\\$2"adjust-for-leading-newline" \{\ -\M[\\$1]\h'1n'\v'+.5v'\D'P \\n(BWu 0 0 \\n(BHu -\\n(BWu 0 0 -\\n(BHu'\M[] -.\} -.el \{\ -\M[\\$1]\h'1n'\v'-.5v'\D'P \\n(BWu 0 0 \\n(BHu -\\n(BWu 0 0 -\\n(BHu'\M[] -.\} -.in 0 -.sp -.5v -.nf -.BX -.in -.sp .5v -.fi -.\} -.. -.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -.\" BM/EM - put colored marker in margin next to block of text -.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -.de BM -.if t \{\ -.br -.ll -2n -.gcolor red -.di BX -.\} -.. -.de EM -.if t \{\ -.br -.di -.ll -.gcolor -.nr BH \\n(dn -.ne \\n(BHu -\M[\\$1]\D'P -.75n 0 0 \\n(BHu -(\\n[.i]u - \\n(INu - .75n) 0 0 -\\n(BHu'\M[] -.in 0 -.nf -.BX -.in -.fi -.\} -.. +.TH "EVENTLOGADM" "8" "03/06/2011" "Samba 3\&.5" "System Administration tools" .\" ----------------------------------------------------------------- .\" * set default formatting .\" ----------------------------------------------------------------- @@ -166,58 +18,52 @@ .\" ----------------------------------------------------------------- .\" * MAIN CONTENT STARTS HERE * .\" ----------------------------------------------------------------- -.SH "Name" +.SH "NAME" eventlogadm \- push records into the Samba event log store -.SH "Synopsis" -.fam C +.SH "SYNOPSIS" .HP \w'\ 'u -\FCeventlogadm\F[] [\fB\-d\fR] [\fB\-h\fR] \fB\-o\fR\ \FCaddsource\F[]\ \fIEVENTLOG\fR\ \fISOURCENAME\fR\ \fIMSGFILE\fR -.fam -.fam C +eventlogadm [\fB\-d\fR] [\fB\-h\fR] \fB\-o\fR\ addsource\ \fIEVENTLOG\fR\ \fISOURCENAME\fR\ \fIMSGFILE\fR .HP \w'\ 'u -\FCeventlogadm\F[] [\fB\-d\fR] [\fB\-h\fR] \fB\-o\fR\ \FCwrite\F[]\ \fIEVENTLOG\fR -.fam -.fam C +eventlogadm [\fB\-d\fR] [\fB\-h\fR] \fB\-o\fR\ write\ \fIEVENTLOG\fR .HP \w'\ 'u -\FCeventlogadm\F[] [\fB\-d\fR] [\fB\-h\fR] \fB\-o\fR\ \FCdump\F[]\ \fIEVENTLOG\fR\ \fIRECORD_NUMBER\fR -.fam +eventlogadm [\fB\-d\fR] [\fB\-h\fR] \fB\-o\fR\ dump\ \fIEVENTLOG\fR\ \fIRECORD_NUMBER\fR .SH "DESCRIPTION" .PP This tool is part of the \fBsamba\fR(1) suite\&. .PP -\FCeventlogadm\F[] +eventlogadm is a filter that accepts formatted event log records on standard input and writes them to the Samba event log store\&. Windows client can then manipulate these record using the usual administration tools\&. .SH "OPTIONS" .PP \fB\-d\fR .RS 4 The -\FC\-d\F[] +\-d option causes -\FCeventlogadm\F[] +eventlogadm to emit debugging information\&. .RE .PP -\fB\-o\fR \FCaddsource\F[] \fIEVENTLOG\fR \fISOURCENAME\fR \fIMSGFILE\fR +\fB\-o\fR addsource \fIEVENTLOG\fR \fISOURCENAME\fR \fIMSGFILE\fR .RS 4 The -\FC\-o addsource\F[] +\-o addsource option creates a new event log source\&. .RE .PP -\fB\-o\fR \FCwrite\F[] \fIEVENTLOG\fR +\fB\-o\fR write \fIEVENTLOG\fR .RS 4 The -\FC\-o write\F[] +\-o write reads event log records from standard input and writes them to the Samba event log store named by EVENTLOG\&. .RE .PP -\fB\-o\fR \FCdump\F[] \fIEVENTLOG\fR \fIRECORD_NUMBER\fR +\fB\-o\fR dump \fIEVENTLOG\fR \fIRECORD_NUMBER\fR .RS 4 The -\FC\-o dump\F[] +\-o dump reads event log records from a EVENTLOG tdb and dumps them to standard output on screen\&. .RE .PP @@ -228,7 +74,7 @@ Print usage information\&. .SH "EVENTLOG RECORD FORMAT" .PP For the write operation, -\FCeventlogadm\F[] +eventlogadm expects to be able to read structured records from standard input\&. These records are a sequence of lines, with the record key and data separated by a colon character\&. Records are separated by at least one or more blank line\&. .PP The event log record field are: @@ -242,9 +88,9 @@ The event log record field are: .IP \(bu 2.3 .\} -\FCLEN\F[] +LEN \- This field should be 0, since -\FCeventlogadm\F[] +eventlogadm will calculate this value\&. .RE .sp @@ -257,7 +103,7 @@ will calculate this value\&. .IP \(bu 2.3 .\} -\FCRS1\F[] +RS1 \- This must be the value 1699505740\&. .RE .sp @@ -270,7 +116,7 @@ will calculate this value\&. .IP \(bu 2.3 .\} -\FCRCN\F[] +RCN \- This field should be 0\&. .RE .sp @@ -283,7 +129,7 @@ will calculate this value\&. .IP \(bu 2.3 .\} -\FCTMG\F[] +TMG \- The time the eventlog record was generated; format is the number of seconds since 00:00:00 January 1, 1970, UTC\&. .RE .sp @@ -296,7 +142,7 @@ will calculate this value\&. .IP \(bu 2.3 .\} -\FCTMW\F[] +TMW \- The time the eventlog record was written; format is the number of seconds since 00:00:00 January 1, 1970, UTC\&. .RE .sp @@ -309,7 +155,7 @@ will calculate this value\&. .IP \(bu 2.3 .\} -\FCEID\F[] +EID \- The eventlog ID\&. .RE .sp @@ -322,7 +168,7 @@ will calculate this value\&. .IP \(bu 2.3 .\} -\FCETP\F[] +ETP \- The event type \-\- one of "INFO", "ERROR", "WARNING", "AUDIT SUCCESS" or "AUDIT FAILURE"\&. .RE .sp @@ -335,7 +181,7 @@ will calculate this value\&. .IP \(bu 2.3 .\} -\FCECT\F[] +ECT \- The event category; this depends on the message file\&. It is primarily used as a means of filtering in the eventlog viewer\&. .RE .sp @@ -348,7 +194,7 @@ will calculate this value\&. .IP \(bu 2.3 .\} -\FCRS2\F[] +RS2 \- This field should be 0\&. .RE .sp @@ -361,7 +207,7 @@ will calculate this value\&. .IP \(bu 2.3 .\} -\FCCRN\F[] +CRN \- This field should be 0\&. .RE .sp @@ -374,7 +220,7 @@ will calculate this value\&. .IP \(bu 2.3 .\} -\FCUSL\F[] +USL \- This field should be 0\&. .RE .sp @@ -387,7 +233,7 @@ will calculate this value\&. .IP \(bu 2.3 .\} -\FCSRC\F[] +SRC \- This field contains the source name associated with the event log\&. If a message file is used with an event log, there will be a registry entry for associating this source name with a message file DLL\&. .RE .sp @@ -400,7 +246,7 @@ will calculate this value\&. .IP \(bu 2.3 .\} -\FCSRN\F[] +SRN \- The name of the machine on which the eventlog was generated\&. This is typically the host name\&. .RE .sp @@ -413,7 +259,7 @@ will calculate this value\&. .IP \(bu 2.3 .\} -\FCSTR\F[] +STR \- The text associated with the eventlog\&. There may be more than one string in a record\&. .RE .sp @@ -426,25 +272,17 @@ will calculate this value\&. .IP \(bu 2.3 .\} -\FCDAT\F[] +DAT \- This field should be left unset\&. .SH "EXAMPLES" .PP An example of the record format accepted by -\FCeventlogadm\F[]: +eventlogadm: .sp .if n \{\ .RS 4 .\} -.fam C -.ps -1 .nf -.if t \{\ -.sp -1 -.\} -.BB lightgray adjust-for-leading-newline -.sp -1 - LEN: 0 RS1: 1699505740 RCN: 0 @@ -461,13 +299,7 @@ An example of the record format accepted by STR: (root) CMD ( rm \-f /var/spool/cron/lastrun/cron\&.hourly) DAT: -.EB lightgray adjust-for-leading-newline -.if t \{\ -.sp 1 -.\} .fi -.fam -.ps +1 .if n \{\ .RE .\} @@ -477,25 +309,11 @@ Set up an eventlog source, specifying a message file DLL: .if n \{\ .RS 4 .\} -.fam C -.ps -1 .nf -.if t \{\ -.sp -1 -.\} -.BB lightgray adjust-for-leading-newline -.sp -1 - eventlogadm \-o addsource Application MyApplication | \e\e %SystemRoot%/system32/MyApplication\&.dll -.EB lightgray adjust-for-leading-newline -.if t \{\ -.sp 1 -.\} .fi -.fam -.ps +1 .if n \{\ .RE .\} @@ -505,26 +323,12 @@ Filter messages from the system log into an event log: .if n \{\ .RS 4 .\} -.fam C -.ps -1 .nf -.if t \{\ -.sp -1 -.\} -.BB lightgray adjust-for-leading-newline -.sp -1 - tail \-f /var/log/messages | \e\e my_program_to_parse_into_eventlog_records | \e\e eventlogadm SystemLogEvents -.EB lightgray adjust-for-leading-newline -.if t \{\ -.sp 1 -.\} .fi -.fam -.ps +1 .if n \{\ .RE .\} |