Thanks but what exactly I have to write in my syslog-ng.conf?<br />
I wrote this:<br />
<br />
destination d_garante {<br />
file("/var/log/garante");<br />
};<br />
<br />
parser pattern_db {<br />
db_parser( file("/var/lib/syslog-ng/patterndb.xml"));<br />
};<br />
<br />
log { <br />
source(s_local);<br />
source(s_network);<br />
parser(pattern_db); <br />
destination( d_garante);<br />
};<br />
<br />
is this right?<br />
<br />
<br />
----- Messaggio da mcholste@gmail.com ---------<br />
Data: Fri, 18 Nov 2011 09:15:33 -0600<br />
Da: Martin Holste <mcholste@gmail.com><br />
Rispondi-A: Syslog-ng users' and developers' mailing list <syslog-ng@lists.balabit.hu><br />
Oggetto: Re: [syslog-ng] patterndb<br />
A: Syslog-ng users' and developers' mailing list <syslog-ng@lists.balabit.hu><br />
<br />
<br />
> From <br />
> <a target="_blank" href="http://enterprise-log-search-and-archive.googlecode.com/svn/trunk/elsa/node/conf/patterndb.xml">http://enterprise-log-search-and-archive.googlecode.com/svn/trunk/elsa/node/conf/patterndb.xml</a>:<br />
><br />
> <patterndb version='3' pub_date='2009-11-04'><br />
> <ruleset name="ssh"><br />
> <pattern>sshd</pattern><br />
> <rules><br />
> <rule class="11" id="11"><br />
> <patterns><br />
> <!-- s0=usracct.authmethod, s1=usracct.username,<br />
> s2=usracct.device, i0=port, s3=usracct.service --><br />
> <pattern>Accepted @ESTRING:s0: @for @ESTRING:s1: @from<br />
> @ESTRING:s2: @port @ESTRING:i0: @@ANYSTRING:s3@</pattern><br />
> </patterns><br />
> </rule><br />
> <rule class="12" id="12"><br />
> <patterns><br />
> <!-- s0=usracct.authmethod, s1=usracct.username,<br />
> s2=usracct.device, i0=port, s3=usracct.service --><br />
> <pattern>Failed @ESTRING:s0: @for @ESTRING:s1: @from @ESTRING:s2:<br />
> @port @ESTRING:i0: @@ANYSTRING:s3@</pattern><br />
> <pattern>Failed @ESTRING:s0: @for invalid user @ESTRING:s1: @from<br />
> @ESTRING:s2: @port @ESTRING:i0: @@ANYSTRING:s3@</pattern><br />
> <pattern>Failed @ESTRING:s0: @for illegal user @ESTRING:s1: @from<br />
> @ESTRING:s2: @port @ESTRING:i0: @@ANYSTRING:s3@</pattern><br />
> </patterns><br />
> </rule><br />
> <rule class="13" id="13"><br />
> <patterns><br />
> <!-- s0=usracct.username --><br />
> <pattern>pam_unix(sshd:session): session closed for user<br />
> @ANYSTRING:s0:@</pattern><br />
> <pattern>session closed for user @ANYSTRING:s0:@</pattern><br />
> </patterns><br />
> </rule><br />
> </rules><br />
> </ruleset><br />
> </patterndb><br />
> On Fri, Nov 18, 2011 at 2:31 AM, Gianluca Tranelli<br />
> <g.tranelli@inarcassa.it> wrote:<br />
>> Good morning everybody, the time is very good here in Rome, but I don't want<br />
>> to talk abbout the weather but about patterndb that is driving me crazy.<br />
>> After reading all the administration guide v3.3, I found an example of using<br />
>> patterndb to log the duration of an ssh Linux and to log a new formatted<br />
>> message. I just copied the XML, ran update-patterndb but nothing happen. Do<br />
>> i miss something? Can someone post a complete working example on ssh?<br />
>> Patterndb is driving me crazy.<br />
>><br />
>> Thank you in advance.<br />
>><br />
>><br />
>> ______________________________________________________________________________<br />
>> Member info: <a target="_blank" href="https://lists.balabit.hu/mailman/listinfo/syslog-ng">https://lists.balabit.hu/mailman/listinfo/syslog-ng</a><br />
>> Documentation:<br />
>> <a target="_blank" href="http://www.balabit.com/support/documentation/?product=syslog-ng">http://www.balabit.com/support/documentation/?product=syslog-ng</a><br />
>> FAQ: <a target="_blank" href="http://www.balabit.com/wiki/syslog-ng-faq">http://www.balabit.com/wiki/syslog-ng-faq</a><br />
>><br />
>><br />
>><br />
> ______________________________________________________________________________<br />
> Member info: <a target="_blank" href="https://lists.balabit.hu/mailman/listinfo/syslog-ng">https://lists.balabit.hu/mailman/listinfo/syslog-ng</a><br />
> Documentation: <br />
> <a target="_blank" href="http://www.balabit.com/support/documentation/?product=syslog-ng">http://www.balabit.com/support/documentation/?product=syslog-ng</a><br />
> FAQ: <a target="_blank" href="http://www.balabit.com/wiki/syslog-ng-faq">http://www.balabit.com/wiki/syslog-ng-faq</a><br />
><br />
><br />
<br />
<br />
----- Fine messaggio da mcholste@gmail.com -----<br /><br />
<br />