source: vendor/current/docs/manpages/eventlogadm.8@ 427

Last change on this file since 427 was 427, checked in by Silvan Scherrer, 16 years ago

Samba 3.5.x: update to 3.5.2

File size: 10.2 KB
RevLine 
[427]1.\" Title: eventlogadm
2.\" Author: [see the "AUTHOR" section]
3.\" Generator: DocBook XSL Stylesheets v1.74.0 <http://docbook.sf.net/>
4.\" Date: 03/30/2010
5.\" Manual: System Administration tools
6.\" Source: Samba 3.5
7.\" Language: English
8.\"
9.TH "EVENTLOGADM" "8" "03/30/2010" "Samba 3\&.5" "System Administration tools"
10.\" -----------------------------------------------------------------
11.\" * (re)Define some macros
12.\" -----------------------------------------------------------------
13.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
14.\" toupper - uppercase a string (locale-aware)
15.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
16.de toupper
17.tr aAbBcCdDeEfFgGhHiIjJkKlLmMnNoOpPqQrRsStTuUvVwWxXyYzZ
18\\$*
19.tr aabbccddeeffgghhiijjkkllmmnnooppqqrrssttuuvvwwxxyyzz
20..
21.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
22.\" SH-xref - format a cross-reference to an SH section
23.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
24.de SH-xref
25.ie n \{\
26.\}
27.toupper \\$*
28.el \{\
29\\$*
30.\}
31..
32.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
33.\" SH - level-one heading that works better for non-TTY output
34.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
35.de1 SH
36.\" put an extra blank line of space above the head in non-TTY output
37.if t \{\
38.sp 1
39.\}
40.sp \\n[PD]u
41.nr an-level 1
42.set-an-margin
43.nr an-prevailing-indent \\n[IN]
44.fi
45.in \\n[an-margin]u
46.ti 0
47.HTML-TAG ".NH \\n[an-level]"
48.it 1 an-trap
49.nr an-no-space-flag 1
50.nr an-break-flag 1
51\." make the size of the head bigger
52.ps +3
53.ft B
54.ne (2v + 1u)
55.ie n \{\
56.\" if n (TTY output), use uppercase
57.toupper \\$*
58.\}
59.el \{\
60.nr an-break-flag 0
61.\" if not n (not TTY), use normal case (not uppercase)
62\\$1
63.in \\n[an-margin]u
64.ti 0
65.\" if not n (not TTY), put a border/line under subheading
66.sp -.6
67\l'\n(.lu'
68.\}
69..
70.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
71.\" SS - level-two heading that works better for non-TTY output
72.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
73.de1 SS
74.sp \\n[PD]u
75.nr an-level 1
76.set-an-margin
77.nr an-prevailing-indent \\n[IN]
78.fi
79.in \\n[IN]u
80.ti \\n[SN]u
81.it 1 an-trap
82.nr an-no-space-flag 1
83.nr an-break-flag 1
84.ps \\n[PS-SS]u
85\." make the size of the head bigger
86.ps +2
87.ft B
88.ne (2v + 1u)
89.if \\n[.$] \&\\$*
90..
91.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
92.\" BB/BE - put background/screen (filled box) around block of text
93.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
94.de BB
95.if t \{\
96.sp -.5
97.br
98.in +2n
99.ll -2n
100.gcolor red
101.di BX
102.\}
103..
104.de EB
105.if t \{\
106.if "\\$2"adjust-for-leading-newline" \{\
107.sp -1
108.\}
109.br
110.di
111.in
112.ll
113.gcolor
114.nr BW \\n(.lu-\\n(.i
115.nr BH \\n(dn+.5v
116.ne \\n(BHu+.5v
117.ie "\\$2"adjust-for-leading-newline" \{\
118\M[\\$1]\h'1n'\v'+.5v'\D'P \\n(BWu 0 0 \\n(BHu -\\n(BWu 0 0 -\\n(BHu'\M[]
119.\}
120.el \{\
121\M[\\$1]\h'1n'\v'-.5v'\D'P \\n(BWu 0 0 \\n(BHu -\\n(BWu 0 0 -\\n(BHu'\M[]
122.\}
123.in 0
124.sp -.5v
125.nf
126.BX
127.in
128.sp .5v
129.fi
130.\}
131..
132.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
133.\" BM/EM - put colored marker in margin next to block of text
134.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
135.de BM
136.if t \{\
137.br
138.ll -2n
139.gcolor red
140.di BX
141.\}
142..
143.de EM
144.if t \{\
145.br
146.di
147.ll
148.gcolor
149.nr BH \\n(dn
150.ne \\n(BHu
151\M[\\$1]\D'P -.75n 0 0 \\n(BHu -(\\n[.i]u - \\n(INu - .75n) 0 0 -\\n(BHu'\M[]
152.in 0
153.nf
154.BX
155.in
156.fi
157.\}
158..
159.\" -----------------------------------------------------------------
160.\" * set default formatting
161.\" -----------------------------------------------------------------
162.\" disable hyphenation
163.nh
164.\" disable justification (adjust text to left margin only)
165.ad l
166.\" -----------------------------------------------------------------
167.\" * MAIN CONTENT STARTS HERE *
168.\" -----------------------------------------------------------------
169.SH "Name"
170eventlogadm \- push records into the Samba event log store
171.SH "Synopsis"
172.fam C
173.HP \w'\ 'u
174\FCeventlogadm\F[] [\fB\-d\fR] [\fB\-h\fR] \fB\-o\fR\ \FCaddsource\F[]\ \fIEVENTLOG\fR\ \fISOURCENAME\fR\ \fIMSGFILE\fR
175.fam
176.fam C
177.HP \w'\ 'u
178\FCeventlogadm\F[] [\fB\-d\fR] [\fB\-h\fR] \fB\-o\fR\ \FCwrite\F[]\ \fIEVENTLOG\fR
179.fam
180.fam C
181.HP \w'\ 'u
182\FCeventlogadm\F[] [\fB\-d\fR] [\fB\-h\fR] \fB\-o\fR\ \FCdump\F[]\ \fIEVENTLOG\fR\ \fIRECORD_NUMBER\fR
183.fam
184.SH "DESCRIPTION"
185.PP
186This tool is part of the
187\fBsamba\fR(1)
188suite\&.
189.PP
190\FCeventlogadm\F[]
191is a filter that accepts formatted event log records on standard input and writes them to the Samba event log store\&. Windows client can then manipulate these record using the usual administration tools\&.
192.SH "OPTIONS"
193.PP
194\fB\-d\fR
195.RS 4
196The
197\FC\-d\F[]
198option causes
199\FCeventlogadm\F[]
200to emit debugging information\&.
201.RE
202.PP
203\fB\-o\fR \FCaddsource\F[] \fIEVENTLOG\fR \fISOURCENAME\fR \fIMSGFILE\fR
204.RS 4
205The
206\FC\-o addsource\F[]
207option creates a new event log source\&.
208.RE
209.PP
210\fB\-o\fR \FCwrite\F[] \fIEVENTLOG\fR
211.RS 4
212The
213\FC\-o write\F[]
214reads event log records from standard input and writes them to the Samba event log store named by EVENTLOG\&.
215.RE
216.PP
217\fB\-o\fR \FCdump\F[] \fIEVENTLOG\fR \fIRECORD_NUMBER\fR
218.RS 4
219The
220\FC\-o dump\F[]
221reads event log records from a EVENTLOG tdb and dumps them to standard output on screen\&.
222.RE
223.PP
224\fB\-h\fR
225.RS 4
226Print usage information\&.
227.RE
228.SH "EVENTLOG RECORD FORMAT"
229.PP
230For the write operation,
231\FCeventlogadm\F[]
232expects to be able to read structured records from standard input\&. These records are a sequence of lines, with the record key and data separated by a colon character\&. Records are separated by at least one or more blank line\&.
233.PP
234The event log record field are:
235.sp
236.RS 4
237.ie n \{\
238\h'-04'\(bu\h'+03'\c
239.\}
240.el \{\
241.sp -1
242.IP \(bu 2.3
243.\}
244
245\FCLEN\F[]
246\- This field should be 0, since
247\FCeventlogadm\F[]
248will calculate this value\&.
249.RE
250.sp
251.RS 4
252.ie n \{\
253\h'-04'\(bu\h'+03'\c
254.\}
255.el \{\
256.sp -1
257.IP \(bu 2.3
258.\}
259
260\FCRS1\F[]
261\- This must be the value 1699505740\&.
262.RE
263.sp
264.RS 4
265.ie n \{\
266\h'-04'\(bu\h'+03'\c
267.\}
268.el \{\
269.sp -1
270.IP \(bu 2.3
271.\}
272
273\FCRCN\F[]
274\- This field should be 0\&.
275.RE
276.sp
277.RS 4
278.ie n \{\
279\h'-04'\(bu\h'+03'\c
280.\}
281.el \{\
282.sp -1
283.IP \(bu 2.3
284.\}
285
286\FCTMG\F[]
287\- The time the eventlog record was generated; format is the number of seconds since 00:00:00 January 1, 1970, UTC\&.
288.RE
289.sp
290.RS 4
291.ie n \{\
292\h'-04'\(bu\h'+03'\c
293.\}
294.el \{\
295.sp -1
296.IP \(bu 2.3
297.\}
298
299\FCTMW\F[]
300\- The time the eventlog record was written; format is the number of seconds since 00:00:00 January 1, 1970, UTC\&.
301.RE
302.sp
303.RS 4
304.ie n \{\
305\h'-04'\(bu\h'+03'\c
306.\}
307.el \{\
308.sp -1
309.IP \(bu 2.3
310.\}
311
312\FCEID\F[]
313\- The eventlog ID\&.
314.RE
315.sp
316.RS 4
317.ie n \{\
318\h'-04'\(bu\h'+03'\c
319.\}
320.el \{\
321.sp -1
322.IP \(bu 2.3
323.\}
324
325\FCETP\F[]
326\- The event type \-\- one of "INFO", "ERROR", "WARNING", "AUDIT SUCCESS" or "AUDIT FAILURE"\&.
327.RE
328.sp
329.RS 4
330.ie n \{\
331\h'-04'\(bu\h'+03'\c
332.\}
333.el \{\
334.sp -1
335.IP \(bu 2.3
336.\}
337
338\FCECT\F[]
339\- The event category; this depends on the message file\&. It is primarily used as a means of filtering in the eventlog viewer\&.
340.RE
341.sp
342.RS 4
343.ie n \{\
344\h'-04'\(bu\h'+03'\c
345.\}
346.el \{\
347.sp -1
348.IP \(bu 2.3
349.\}
350
351\FCRS2\F[]
352\- This field should be 0\&.
353.RE
354.sp
355.RS 4
356.ie n \{\
357\h'-04'\(bu\h'+03'\c
358.\}
359.el \{\
360.sp -1
361.IP \(bu 2.3
362.\}
363
364\FCCRN\F[]
365\- This field should be 0\&.
366.RE
367.sp
368.RS 4
369.ie n \{\
370\h'-04'\(bu\h'+03'\c
371.\}
372.el \{\
373.sp -1
374.IP \(bu 2.3
375.\}
376
377\FCUSL\F[]
378\- This field should be 0\&.
379.RE
380.sp
381.RS 4
382.ie n \{\
383\h'-04'\(bu\h'+03'\c
384.\}
385.el \{\
386.sp -1
387.IP \(bu 2.3
388.\}
389
390\FCSRC\F[]
391\- This field contains the source name associated with the event log\&. If a message file is used with an event log, there will be a registry entry for associating this source name with a message file DLL\&.
392.RE
393.sp
394.RS 4
395.ie n \{\