<div dir="ltr"><div><div><div><div><div><div>Hello Christian,<br><br></div>I just noticed that you seem to be using two network sources configured to use the same IP and port settings.<br></div>You should move the <span>src_MYAPP source to a different port, because the two are conflicting.<br></span></div><span>Furthermore, you could try removing the quotes from the </span><span>f_devenv_04net stanza. (Although I don&#39;t expect any significant changes in syslog-ng&#39;s behavior because of this.)<br><br></span></div><span>Which is the generic destination you were referring to earlier? Is it perhaps </span><span>d_MYAPP? (Or another one?)<br><br></span></div><span>Regards,<br></span></div><span>János<br></span><div><div><div><div><div><div><div><div><div class="gmail_extra"><br><div class="gmail_quote">2016-08-03 19:50 GMT+02:00 Christian Turner <span dir="ltr">&lt;<a target="_blank" href="mailto:cturner@highroads.com">cturner@highroads.com</a>&gt;</span>:<br><blockquote style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex" class="gmail_quote">





<div lang="EN-US">
<div>
<p class="gmail-MsoNormal"><a name="m_-7324745279193649848__MailEndCompose">@version: 3.2<u></u><u></u></a></p>
<p class="gmail-MsoNormal"><span>#Default configuration file for syslog-ng.<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>#<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span># For a description of syslog-ng configuration file directives, please read<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span># the syslog-ng Administrator&#39;s guide at:<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>#<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span># <a target="_blank" href="https://www.balabit.com/support/documentation">https://www.balabit.com/support/documentation</a><u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>#<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>@include &quot;scl.conf&quot;<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span><u></u> <u></u></span></p>
<p class="gmail-MsoNormal"><span>options {<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>        flush_lines (0);<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>        time_reopen (10);<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>        log_fifo_size (2048);<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>        chain_hostnames (off);<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>        use_dns (no);<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>        use_fqdn (no);<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>        create_dirs (yes);<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>        keep_hostname (no);<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>        stats_freq(86400);<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>};<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span><u></u> <u></u></span></p>
<p class="gmail-MsoNormal"><span>source s_sys {<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>        file (&quot;/proc/kmsg&quot; program_override(&quot;kernel: &quot;));<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>        unix-stream (&quot;/dev/log&quot;);<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>        internal();<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>};<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span><u></u> <u></u></span></p>
<p class="gmail-MsoNormal"><span>### MYAPP Dev  Logs ###<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span><u></u> <u></u></span></p>
<p class="gmail-MsoNormal"><span>## DEVENV ##<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>source src_devenv                        { udp(ip(0.0.0.0) port(514)); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span><u></u> <u></u></span></p>
<p class="gmail-MsoNormal"><span>filter f_devenv_01ui                     { netmask(<a target="_blank" href="http://10.22.206.0/24">10.22.206.0/24</a>); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>filter f_devenv_02gw                    { netmask(<a target="_blank" href="http://10.22.207.0/24">10.22.207.0/24</a>); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>filter f_devenv_03api                   { netmask(<a target="_blank" href="http://10.22.208.0/24">10.22.208.0/24</a>); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>filter f_devenv_04net                   { netmask( &quot;<a target="_blank" href="http://10.22.209.0/24">10.22.209.0/24</a>&quot; ); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>filter f_devenv_05bat                   { netmask(<a target="_blank" href="http://10.22.210.0/24">10.22.210.0/24</a>); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span><u></u> <u></u></span></p>
<p class="gmail-MsoNormal"><span>destination d_devenv_01ui         { file(&quot;/mnt/syslogng/MYAPPlogs/DEVENV/01ui-$HOST-$YEAR$MONTH$DAY.log&quot;); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>destination d_devenv_02gw       { file(&quot;/mnt/syslogng/MYAPPlogs/DEVENV/02gw-$HOST-$YEAR$MONTH$DAY.log&quot;); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>destination d_devenv_03api       { file(&quot;/mnt/syslogng/MYAPPlogs/DEVENV/03api-$HOST-$YEAR$MONTH$DAY.log&quot;); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>destination d_devenv_04net      { file(&quot;/mnt/syslogng/MYAPPlogs/DEVENV/04net-$HOST-$YEAR$MONTH$DAY.log&quot;); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>destination d_devenv_05bat      { file(&quot;/mnt/syslogng/MYAPPlogs/DEVENV/05bat-$HOST-$YEAR$MONTH$DAY.log&quot;); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span><u></u> <u></u></span></p>
<p class="gmail-MsoNormal"><span>log                                                    { source(src_devenv); filter(f_devenv_01ui); destination(d_devenv_01ui); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>log                                                    { source(src_devenv); filter(f_devenv_02gw); destination(d_devenv_02gw); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>log                                                    { source(src_devenv); filter(f_devenv_03api); destination(d_devenv_03api); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>log                                                    { source(src_devenv); filter(f_devenv_04net); destination(d_devenv_04net); flags(final); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>log                                                    { source(src_devenv); filter(f_devenv_05bat); destination(d_devenv_05bat); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span><u></u> <u></u></span></p>
<p class="gmail-MsoNormal"><span>## MYAPP ALL ##<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>source src_MYAPP { udp(ip(0.0.0.0) port(514)); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>destination d_MYAPP { file(&quot;/mnt/syslogng/MYAPPlogs/$HOST/$HOST-$YEAR$MONTH$DAY.log&quot;); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>log { source(src_MYAPP); destination(d_MYAPP); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span><u></u> <u></u></span></p>
<p class="gmail-MsoNormal"><span><u></u> <u></u></span></p>
<p class="gmail-MsoNormal"><span><u></u> <u></u></span></p>
<p class="gmail-MsoNormal"><span>#source external { tcp(); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>#source external { udp(); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span><u></u> <u></u></span></p>
<p class="gmail-MsoNormal"><span>#destination d_hosts { file(&quot;/home/syslog/$HOST/application.log&quot; owner(&quot;syslog&quot;) group(&quot;syslog&quot;) perm(0600)); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span><u></u> <u></u></span></p>
<p class="gmail-MsoNormal"><span>destination d_mesg { file(&quot;/var/log/messages&quot;); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>#destination d_cons { file(&quot;/dev/console&quot;); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>#destination d_auth { file(&quot;/var/log/secure&quot;); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>#destination d_mail { file(&quot;/var/log/maillog&quot; flush_lines(10)); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>#destination d_spol { file(&quot;/var/log/spooler&quot;); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>#destination d_boot { file(&quot;/var/log/boot.log&quot;); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>#destination d_cron { file(&quot;/var/log/cron&quot;); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>#destination d_kern { file(&quot;/var/log/kern&quot;); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>#destination d_mlal { usertty(&quot;*&quot;); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>#destination d_all { file(&quot;/var/log/splunk&quot;);  };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span><u></u> <u></u></span></p>
<p class="gmail-MsoNormal"><span>log { source(s_sys); destination(d_mesg); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span>#log { source(external); destination(d_hosts); };<u></u><u></u></span></p>
<p class="gmail-MsoNormal"><span><u></u> <u></u></span></p>
<p class="gmail-MsoNormal"><span><u></u> <u></u></span></p>
<span></span>
<div>
<div style="border-width:1pt medium medium;border-style:solid none none;border-color:rgb(225,225,225) -moz-use-text-color -moz-use-text-color;padding:3pt 0in 0in">
<p class="gmail-MsoNormal"><b>From:</b> Christian Turner <br>
<b>Sent:</b> Wednesday, August 3, 2016 11:53 AM<br>
<b>To:</b> &#39;<a target="_blank" href="mailto:syslog-ng@lists.balabit.hu">syslog-ng@lists.balabit.hu</a>&#39; &lt;<a target="_blank" href="mailto:syslog-ng@lists.balabit.hu">syslog-ng@lists.balabit.hu</a>&gt;<br>
<b>Subject:</b> RE: sylog-ng filters not working<u></u><u></u></p>
</div>
</div><span class="gmail-">
<p class="gmail-MsoNormal"><u></u> <u></u></p>
<p class="gmail-MsoNormal">Hi,<u></u><u></u></p>
<p class="gmail-MsoNormal"><u></u> <u></u></p>
<p class="gmail-MsoNormal">I have the following filter configured;<u></u><u></u></p>
<p class="gmail-MsoNormal"><u></u> <u></u></p>
<p class="gmail-MsoNormal">source src_devenv01                    { udp(ip(0.0.0.0) port(514)); };<u></u><u></u></p>
<p class="gmail-MsoNormal">filter f_devenv01_04net              { netmask(<a target="_blank" href="http://10.22.209.0/24">10.22.209.0/24</a>); };<u></u><u></u></p>
<p class="gmail-MsoNormal">destination d_devenv_04net      { file(&quot;/mnt/syslogng/p2alogs/DEVENV/04net-$HOST-$YEAR$MONTH$DAY.log&quot;); };<u></u><u></u></p>
<p class="gmail-MsoNormal">log                                                    { source(src_devenv01); filter(f_devenv_04net); destination(d_devenv_04net); flags(final); };<u></u><u></u></p>
<p class="gmail-MsoNormal"><u></u> <u></u></p>
<p class="gmail-MsoNormal">However, the filter does not work, and the logs from this source all go to the generic logging destination.<u></u><u></u></p>
<p class="gmail-MsoNormal"><u></u> <u></u></p>
<p class="gmail-MsoNormal">I perform an strace and I can see that the IP appears as expected, so I’m figuring I have a syntax error somewhere;<u></u><u></u></p>
<p class="gmail-MsoNormal"><u></u> <u></u></p>
<p class="gmail-MsoNormal">[pid 28481] recvfrom(11, &quot;&lt;182&gt;1 2016-08-03T10:27:50.645062-04:00 ::1 [[REDACTED]]..., 8192, 0, {sa_family=AF_INET, sin_port=htons(58785), sin_addr=inet_addr(&quot;<b>10.22.209.10</b>&quot;)}, [16]) = 265<u></u><u></u></p>
<p class="gmail-MsoNormal"><u></u> <u></u></p>
<p class="gmail-MsoNormal"><b><span style="color:black">Christian Turner</span></b><span style="color:black">
</span><span style="color:rgb(31,73,125)"><u></u><u></u></span></p>
<p class="gmail-MsoNormal"><u></u> <u></u></p>
</span></div>
</div>

<br>______________________________________________________________________________<br>
Member info: <a target="_blank" rel="noreferrer" href="https://lists.balabit.hu/mailman/listinfo/syslog-ng">https://lists.balabit.hu/mailman/listinfo/syslog-ng</a><br>
Documentation: <a target="_blank" rel="noreferrer" href="http://www.balabit.com/support/documentation/?product=syslog-ng">http://www.balabit.com/support/documentation/?product=syslog-ng</a><br>
FAQ: <a target="_blank" rel="noreferrer" href="http://www.balabit.com/wiki/syslog-ng-faq">http://www.balabit.com/wiki/syslog-ng-faq</a><br>
<br>
<br></blockquote></div><br><br clear="all"><br>-- <br><div class="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr">Janos SZIGETVARI<br><span>RHCE, License no. <a target="_blank" href="https://www.redhat.com/rhtapps/verify/?certId=150-053-692">150-053-692</a></span><br><br>E-mail: <a target="_blank" href="mailto:jszigetvari@gmail.com">jszigetvari@gmail.com</a><br>Phone: +36209440412 (Hungary)<br><br>__@__˚V˚<br>Make the switch to open (source) applications, protocols, formats now:<br>- windows -&gt; Linux, iexplore -&gt; Firefox, msoffice -&gt; LibreOffice<br>- msn -&gt; jabber protocol (Pidgin, Google Talk)<br>- mp3 -&gt; ogg, wmv -&gt; ogg, jpg -&gt; png, doc/xls/ppt -&gt; odt/ods/odp</div></div></div></div></div></div></div></div></div></div></div></div></div></div>
</div></div></div></div></div></div></div></div></div></div>