<div dir="ltr">Hi,<div><br></div><div>thanks so much! works well! </div></div><div class="gmail_extra"><br clear="all"><div><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr">--<div>Jorge Pereira</div></div></div></div>
<br><div class="gmail_quote">On Thu, Aug 18, 2016 at 1:06 PM, Scheidler, Balázs <span dir="ltr">&lt;<a href="mailto:balazs.scheidler@balabit.com" target="_blank">balazs.scheidler@balabit.com</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div><div><div><br></div>the @confgen line only registers a source driver named s_nginx_modsec_log that you&#39;ll have to use in order to expand this in your configuration file.<br><br></div>@confgen is assumed to be used at the top level, whereas the driver being declared as a normal source statement.<br><br><div><br></div><div><span class=""><div>@module confgen context(source) name(s_nginx_modsec_log) exec(&quot;/etc/syslog-ng/scripts/c<wbr>onfgen-modsec-skeleton.sh&quot;)<br><br></div></span>log {<br></div><div>    source { s_nginx_modsec_log(); };<br></div>    destination(d_collector);<div>};</div><br></div>Your source name uses the conventions of a source drive (the s_ prefix), so you probably assumed that it is declaring a source, but it isn&#39;t. It defines a source driver.<br><div><div><div><br></div></div></div></div><div class="gmail_extra"><br clear="all"><div><div data-smartmail="gmail_signature"><div dir="ltr">-- <br>Bazsi<br></div></div></div>
<br><div class="gmail_quote"><div><div class="h5">On Wed, Aug 17, 2016 at 9:42 PM, Jorge Pereira <span dir="ltr">&lt;<a href="mailto:jpereiran@gmail.com" target="_blank">jpereiran@gmail.com</a>&gt;</span> wrote:<br></div></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div><div class="h5"><div dir="ltr">Hi guys,<div><br></div><div>somebody could help?</div></div><div class="gmail_extra"><br clear="all"><div><div data-smartmail="gmail_signature"><div dir="ltr">--<div>Jorge Pereira</div></div></div></div><div><div>
<br><div class="gmail_quote">On Fri, Aug 12, 2016 at 3:15 AM, Jorge Pereira <span dir="ltr">&lt;<a href="mailto:jpereiran@gmail.com" target="_blank">jpereiran@gmail.com</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div>Hi guys!</div><div><br></div><div>Following the sample described in <a href="https://www.balabit.com/documents/syslog-ng-ose-latest-guides/en/syslog-ng-ose-guide-admin/html/generating-configuration-blocks.html" target="_blank">https://www.balabit.com/doc<wbr>uments/syslog-ng-ose-latest-gu<wbr>ides/en/syslog-ng-ose-guide-ad<wbr>min/html/generating-configurat<wbr>ion-blocks.html</a></div><div><br></div><div>1) I have my &#39;confgen&#39; script that prints the below <b>file()</b> entries. (p.s: these files has content.)</div><div><br></div><div><div># /etc/syslog-ng/scripts/confgen<wbr>-modsec-skeleton.sh</div><div>file(&quot;/opt/nginx/logs/waf/<a href="http://www.cocada.com" target="_blank">www.<wbr>cocada.com</a>&quot; program_override(&quot;ng_modsec&quot;) flags(no-parse));</div><div>file(&quot;/opt/nginx/logs/waf/<a href="http://www.caipirinha.com" target="_blank">www.<wbr>caipirinha.com</a>&quot; program_override(&quot;ng_modsec&quot;) flags(no-parse));</div><div># </div></div><div><br></div><div>2) My config set:</div><div><br></div><div># cat /etc/syslog-ng/conf.d/nginx_mo<wbr>dsec.conf <br></div><div><div>options {<br></div><div>    threaded(yes);</div><div>    flush_lines(0);</div><div>    use-dns(no);</div><div>    normalize-hostnames(yes);</div><div>    keep-hostname(yes);</div><div>};</div><div><br></div><div>destination d_collector {<br></div><div>    tcp(&quot;192.168.1.248&quot; port(514)  keep-alive(on)  );</div><div>};</div><div><br></div><div>log {</div><div>@module confgen context(source) name(s_nginx_modsec_log) exec(&quot;/etc/syslog-ng/scripts/c<wbr>onfgen-modsec-skeleton.sh&quot;)</div><div>    destination(d_collector);</div><div>};</div><div><br></div><div># </div></div><div><br></div><div>Conclusion: The syslog-ng doesn&#39;t call the script at any time.</div><div><br></div><div># strace -fff /usr/sbin/syslog-ng -dvte 2&gt;&amp;1 | grep &quot;confgen-modsec&quot;<br></div><div><br></div><div>p.s: I have &#39;confgen&#39; support.</div><div><br></div><div><div># syslog-ng --version | grep confgen</div><div>Available-Modules: syslogformat,kvformat,afamqp,s<wbr>djournal,system-source,afuser,<wbr>json-plugin,dbparser,affile,af<wbr>socket,linux-kmsg-format,afmon<wbr>godb,mod-python,<b>confgen</b>,csvpar<wbr>ser,pseudofile,afsql,afprog,<wbr>afstomp,cryptofuncs,graphite,<wbr>basicfuncs</div></div><div>#</div><div><br></div><div>I appreciate any help.</div><div><br></div><div>Best,</div><div>Jorge Pereira</div></div>
</blockquote></div><br></div></div></div>
<br></div></div>______________________________<wbr>______________________________<wbr>__________________<br>
Member info: <a href="https://lists.balabit.hu/mailman/listinfo/syslog-ng" rel="noreferrer" target="_blank">https://lists.balabit.hu/mailm<wbr>an/listinfo/syslog-ng</a><br>
Documentation: <a href="http://www.balabit.com/support/documentation/?product=syslog-ng" rel="noreferrer" target="_blank">http://www.balabit.com/support<wbr>/documentation/?product=<wbr>syslog-ng</a><br>
FAQ: <a href="http://www.balabit.com/wiki/syslog-ng-faq" rel="noreferrer" target="_blank">http://www.balabit.com/wiki/sy<wbr>slog-ng-faq</a><br>
<br>
<br></blockquote></div><br></div>
<br>______________________________<wbr>______________________________<wbr>__________________<br>
Member info: <a href="https://lists.balabit.hu/mailman/listinfo/syslog-ng" rel="noreferrer" target="_blank">https://lists.balabit.hu/<wbr>mailman/listinfo/syslog-ng</a><br>
Documentation: <a href="http://www.balabit.com/support/documentation/?product=syslog-ng" rel="noreferrer" target="_blank">http://www.balabit.com/<wbr>support/documentation/?<wbr>product=syslog-ng</a><br>
FAQ: <a href="http://www.balabit.com/wiki/syslog-ng-faq" rel="noreferrer" target="_blank">http://www.balabit.com/wiki/<wbr>syslog-ng-faq</a><br>
<br>
<br></blockquote></div><br></div>