source: branches/samba-3.3.x/docs/manpages/eventlogadm.8@ 368

Last change on this file since 368 was 368, checked in by Herwig Bauernfeind, 16 years ago

Update Samba 3.3 to 3.3.10 (docs)

File size: 5.9 KB
Line 
1'\" t
2.\" Title: eventlogadm
3.\" Author: [see the "AUTHOR" section]
4.\" Generator: DocBook XSL Stylesheets v1.75.2 <http://docbook.sf.net/>
5.\" Date: 01/14/2010
6.\" Manual: System Administration tools
7.\" Source: Samba 3.3
8.\" Language: English
9.\"
10.TH "EVENTLOGADM" "8" "01/14/2010" "Samba 3\&.3" "System Administration tools"
11.\" -----------------------------------------------------------------
12.\" * set default formatting
13.\" -----------------------------------------------------------------
14.\" disable hyphenation
15.nh
16.\" disable justification (adjust text to left margin only)
17.ad l
18.\" -----------------------------------------------------------------
19.\" * MAIN CONTENT STARTS HERE *
20.\" -----------------------------------------------------------------
21.SH "NAME"
22eventlogadm \- push records into the Samba event log store
23.SH "SYNOPSIS"
24.HP \w'\ 'u
25eventlogadm [\fB\-d\fR] [\fB\-h\fR] \fB\-o\fR\ addsource\ \fIEVENTLOG\fR\ \fISOURCENAME\fR\ \fIMSGFILE\fR
26.HP \w'\ 'u
27eventlogadm [\fB\-d\fR] [\fB\-h\fR] \fB\-o\fR\ write\ \fIEVENTLOG\fR
28.SH "DESCRIPTION"
29.PP
30This tool is part of the
31\fBsamba\fR(1)
32suite\&.
33.PP
34eventlogadm
35is a filter that accepts formatted event log records on standard input and writes them to the Samba event log store\&. Windows client can then manipulate these record using the usual administration tools\&.
36.SH "OPTIONS"
37.PP
38\fB\-d\fR
39.RS 4
40The
41\-d
42option causes
43eventlogadm
44to emit debugging information\&.
45.RE
46.PP
47\fB\-o\fR addsource \fIEVENTLOG\fR \fISOURCENAME\fR \fIMSGFILE\fR
48.RS 4
49The
50\-o addsource
51option creates a new event log source\&.
52.RE
53.PP
54\fB\-o\fR write \fIEVENTLOG\fR
55.RS 4
56The
57\-o write
58reads event log records from standard input and writes them to the Samba event log store named by EVENTLOG\&.
59.RE
60.PP
61\fB\-h\fR
62.RS 4
63Print usage information\&.
64.RE
65.SH "EVENTLOG RECORD FORMAT"
66.PP
67For the write operation,
68eventlogadm
69expects to be able to read structured records from standard input\&. These records are a sequence of lines, with the record key and data separated by a colon character\&. Records are separated by at least one or more blank line\&.
70.PP
71The event log record field are:
72.sp
73.RS 4
74.ie n \{\
75\h'-04'\(bu\h'+03'\c
76.\}
77.el \{\
78.sp -1
79.IP \(bu 2.3
80.\}
81
82LEN
83\- This field should be 0, since
84eventlogadm
85will calculate this value\&.
86.RE
87.sp
88.RS 4
89.ie n \{\
90\h'-04'\(bu\h'+03'\c
91.\}
92.el \{\
93.sp -1
94.IP \(bu 2.3
95.\}
96
97RS1
98\- This must be the value 1699505740\&.
99.RE
100.sp
101.RS 4
102.ie n \{\
103\h'-04'\(bu\h'+03'\c
104.\}
105.el \{\
106.sp -1
107.IP \(bu 2.3
108.\}
109
110RCN
111\- This field should be 0\&.
112.RE
113.sp
114.RS 4
115.ie n \{\
116\h'-04'\(bu\h'+03'\c
117.\}
118.el \{\
119.sp -1
120.IP \(bu 2.3
121.\}
122
123TMG
124\- The time the eventlog record was generated; format is the number of seconds since 00:00:00 January 1, 1970, UTC\&.
125.RE
126.sp
127.RS 4
128.ie n \{\
129\h'-04'\(bu\h'+03'\c
130.\}
131.el \{\
132.sp -1
133.IP \(bu 2.3
134.\}
135
136TMW
137\- The time the eventlog record was written; format is the number of seconds since 00:00:00 January 1, 1970, UTC\&.
138.RE
139.sp
140.RS 4
141.ie n \{\
142\h'-04'\(bu\h'+03'\c
143.\}
144.el \{\
145.sp -1
146.IP \(bu 2.3
147.\}
148
149EID
150\- The eventlog ID\&.
151.RE
152.sp
153.RS 4
154.ie n \{\
155\h'-04'\(bu\h'+03'\c
156.\}
157.el \{\
158.sp -1
159.IP \(bu 2.3
160.\}
161
162ETP
163\- The event type \-\- one of "INFO", "ERROR", "WARNING", "AUDIT SUCCESS" or "AUDIT FAILURE"\&.
164.RE
165.sp
166.RS 4
167.ie n \{\
168\h'-04'\(bu\h'+03'\c
169.\}
170.el \{\
171.sp -1
172.IP \(bu 2.3
173.\}
174
175ECT
176\- The event category; this depends on the message file\&. It is primarily used as a means of filtering in the eventlog viewer\&.
177.RE
178.sp
179.RS 4
180.ie n \{\
181\h'-04'\(bu\h'+03'\c
182.\}
183.el \{\
184.sp -1
185.IP \(bu 2.3
186.\}
187
188RS2
189\- This field should be 0\&.
190.RE
191.sp
192.RS 4
193.ie n \{\
194\h'-04'\(bu\h'+03'\c
195.\}
196.el \{\
197.sp -1
198.IP \(bu 2.3