What is all this junk (msftedit and \par)? Did you copy this file off and edit it on a windows machine? Can you find an the original syslog-ng.conf that was shipped with the machine and edit that with 'vi' or something? Is syslog-ng even running? It probably barfed on this config.. grep for syslog-ng in your /var/log/messages and send the last few lines.<br>
<br>{\*\generator Msftedit 5.41.15.1515;}\viewkind4\uc1\pard\f0\fs20 #\par<br># /etc/syslog-ng/syslog-ng.conf\par<br>#\par<br># Automatically generated by SuSEconfig on Sat Aug 15 12:16:03 EDT 2009.\par<br>#\par<br># PLEASE DO NOT EDIT THIS FILE!\par<br>
#\par<br># you can modify /etc/syslog-ng/<a href="http://syslog-ng.conf.in">syslog-ng.conf.in</a> instead\par<br>#\par<br>#\par<br>#\par<br># File format description can be found in syslog-ng.conf(5)\par<br># and /usr/share/doc/packages/syslog-ng/syslog-ng.txt.\par<br>
#\par<br>\par<br>#\par<br># Global options.\par<br>#\par<br>options \{ long_hostnames(off); sync(0); perm(0640); stats(3600); \};\par<br>\par<br>#\par<br># 'src' is our main source definition. you can add\par<br># more sources driver definitions to it, or define\par<br>
# your own sources, i.e.:\par<br>#\par<br>#source my_src \{ .... \};\par<br>#\par<br>source src \{\par<br> #\par<br> # include internal syslog-ng messages\par<br> # note: the internal() soure is required!\par<br>
#\par<br> internal();\par<br><br><br><div class="gmail_quote">On Sat, Aug 15, 2009 at 12:19 PM, <span dir="ltr"><<a href="mailto:stephen.greenfield@wachovia.com">stephen.greenfield@wachovia.com</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">
<br><font face="sans-serif" size="2">I should have sent more detail originally.</font>
<br>
<br><font face="sans-serif" size="2"> system:
SLES10 PatchLevel 1</font>
<br>
<br><font face="sans-serif" size="2"> release:
syslog-ng-1.6.8-20.18</font>
<br>
<br><font face="sans-serif" size="2"> server
function: syslog
server, collecting syslog's from various clients</font>
<br>
<br><font face="sans-serif" size="2"> problem:
want
to open port 514 to collect syslog info over network</font>
<br>
<br><font face="sans-serif" size="2"> description:
without
changing the default syslog-ng.conf, the server</font>
<br><font face="sans-serif" size="2">
collects local syslog information, I uncomment
the udp</font>
<br><font face="sans-serif" size="2">
source entry and restart the daemon. The
syslog-ng</font>
<br><font face="sans-serif" size="2">
then shows listening on various ports, never
constant</font>
<br><font face="sans-serif" size="2">
and never port 514.</font>
<br>
<br>
<br>
<br><font face="sans-serif" size="2"># netstat -anp | grep LISTEN | grep
53</font>
<br><font face="sans-serif" size="2">unix 2 [ ACC
] STREAM LISTENING 5364
2161/acpid /var/run/acpid.socket</font>
<br><font face="sans-serif" size="2">unix 2 [ ACC
] STREAM LISTENING 5307
2134/resmgrd /var/run/.resmgr_socket</font>
<br>
<br>
<br>
<br><font size="2"><tt><a href="mailto:syslog-ng-bounces@lists.balabit.hu" target="_blank">syslog-ng-bounces@lists.balabit.hu</a> wrote on 08/15/2009
11:09:23 AM:<div class="im"><br>
<br>
> Post your config. Also, try 'netstat -anp | <br>
> grep LISTEN | grep 53' and post that (so there <br>
> is no services resolving issue).<br>
> <br>
> -Matt<br>
</div></tt></font><div><div></div><div class="h5">
<br><font size="2"><tt>> On Sat, Aug 15, 2009 at 10:27 AM, <stephen.<br>
> <a href="mailto:greenfield@wachovia.com" target="_blank">greenfield@wachovia.com</a>> wrote:</tt></font>
<br><font size="2"><tt>> <br>
> I configure syslog-ng to use udp port 514, on <br>
> the syslog server receiving log messages. When <br>
> I issue a `netstat -lp | grep syslog` it shows <br>
> different ports but never 514. Any ideas why? <br>
> <br>
> /steve</tt></font></div></div><br>______________________________________________________________________________<br>
Member info: <a href="https://lists.balabit.hu/mailman/listinfo/syslog-ng" target="_blank">https://lists.balabit.hu/mailman/listinfo/syslog-ng</a><br>
Documentation: <a href="http://www.balabit.com/support/documentation/?product=syslog-ng" target="_blank">http://www.balabit.com/support/documentation/?product=syslog-ng</a><br>
FAQ: <a href="http://www.campin.net/syslog-ng/faq.html" target="_blank">http://www.campin.net/syslog-ng/faq.html</a><br>
<br>
<br></blockquote></div><br><br clear="all"><br>-- <br>Some men see things as they are and ask why. I see things that never were and ask for initiative rolls.<br>