<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0cm;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Times New Roman",serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:#954F72;
text-decoration:underline;}
p
{mso-style-priority:99;
margin:0cm;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Times New Roman",serif;}
p.msonormal0, li.msonormal0, div.msonormal0
{mso-style-name:msonormal;
margin:0cm;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Times New Roman",serif;}
p.xmsonormal, li.xmsonormal, div.xmsonormal
{mso-style-name:x_msonormal;
margin:0cm;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
p.xmsochpdefault, li.xmsochpdefault, div.xmsochpdefault
{mso-style-name:x_msochpdefault;
margin:0cm;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Calibri",sans-serif;}
span.xmsohyperlink
{mso-style-name:x_msohyperlink;
color:#0563C1;
text-decoration:underline;}
span.xmsohyperlinkfollowed
{mso-style-name:x_msohyperlinkfollowed;
color:#954F72;
text-decoration:underline;}
span.xemailstyle17
{mso-style-name:x_emailstyle17;
font-family:"Calibri",sans-serif;
color:windowtext;}
span.EmailStyle24
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:#1F497D;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:612.0pt 792.0pt;
margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-GB" link="#0563C1" vlink="#954F72">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D;mso-fareast-language:EN-US">Hiya,<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D;mso-fareast-language:EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D;mso-fareast-language:EN-US">Thanks for this – most useful.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D;mso-fareast-language:EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D;mso-fareast-language:EN-US">Is it possible to lookup the IP Addresses from a list (we are likely to be talking in the range of hundreds of addresses)<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D;mso-fareast-language:EN-US"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D;mso-fareast-language:EN-US">Thanks<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D;mso-fareast-language:EN-US">Pete.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1F497D;mso-fareast-language:EN-US"><o:p> </o:p></span></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm 0cm 0cm">
<p class="MsoNormal"><b><span lang="EN-US" style="font-size:11.0pt;font-family:"Calibri",sans-serif">From:</span></b><span lang="EN-US" style="font-size:11.0pt;font-family:"Calibri",sans-serif"> syslog-ng <syslog-ng-bounces@lists.balabit.hu>
<b>On Behalf Of </b>Attila Szakacs (aszakacs)<br>
<b>Sent:</b> 12 January 2021 14:11<br>
<b>To:</b> Syslog-ng users' and developers' mailing list <syslog-ng@lists.balabit.hu><br>
<b>Subject:</b> Re: [syslog-ng] Filtering Destination by Source<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<p class="MsoNormal" style="background:white"><span style="font-family:"Calibri",sans-serif;color:black">Hi Peter,<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-family:"Calibri",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-family:"Calibri",sans-serif;color:black">If the decision can be made with the source IP or hostname, it is pretty easy to do.<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-family:"Calibri",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-family:"Calibri",sans-serif;color:black">You can create multiple filters, each corresponding to one known source IP: netmask(), or hostname: host().<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-family:"Calibri",sans-serif;color:black">Then you can create embedded log statements. Don't forget to add flags(final), or it will flow through that branch.<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-family:"Calibri",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-family:"Calibri",sans-serif;color:black">An example configuration:<o:p></o:p></span></p>
</div>
<div>
<div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4">@version: 3.30<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p> </o:p></span></p>
</div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"># One network source, which collects logs from various hosts<o:p></o:p></span></p>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4">source s_network {<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> network(port(12345))</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">;</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4">}</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">;</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p> </o:p></span></p>
</div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"># One known host, with the IP 127.0.0.1<o:p></o:p></span></p>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4">filter f_host1 {<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> netmask(</span><span style="font-size:10.5pt;font-family:"Courier New";color:#CE9178">"127.0.0.1"</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4">)</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">;</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4">}</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">;</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p> </o:p></span></p>
</div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"># Another known host with the IP 127.0.0.2<o:p></o:p></span></p>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4">filter f_host2 {<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> netmask(</span><span style="font-size:10.5pt;font-family:"Courier New";color:#CE9178">"127.0.0.2"</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4">)</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">;</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4">}</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">;</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p> </o:p></span></p>
</div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"># The destination, where host1's logs will be forwarded to<o:p></o:p></span></p>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4">destination d_network1 {<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> network(</span><span style="font-size:10.5pt;font-family:"Courier New";color:#CE9178">"localhost"</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> port(23456))</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">;</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4">}</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">;</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4;background:#1E1E1E"><o:p> </o:p></span></p>
</div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4;background:#1E1E1E"># The destination, where host2's logs will be forwarded to</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4">destination d_network2 {<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> network(</span><span style="font-size:10.5pt;font-family:"Courier New";color:#CE9178">"localhost"</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> port(23457))</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">;</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4">}</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">;</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p> </o:p></span></p>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4">log {<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> source(s_network)</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">;</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p> </o:p></span></p>
</div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> # First branch, for host1 -> destination1<o:p></o:p></span></p>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> log {<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> filter(f_host1)</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">;</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> destination(d_network1)</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">;</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> flags(final)</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">; # Don't forget to
stop processing</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> }</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">;</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p> </o:p></span></p>
</div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> # Second branch, for host2 -> destination2<o:p></o:p></span></p>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> log {<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> filter(f_host2)</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">;</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> destination(d_network2)</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">;</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> flags(final)</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">; <span style="background:#1E1E1E">#
Don't forget to stop processing</span></span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> }</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">;</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4">}</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">;</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal" style="background:white"><span style="font-family:"Calibri",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-family:"Calibri",sans-serif;color:black">You can use inline filters too, if it is more convenient. With this, you do not need to define f_host1 and f_host2:<o:p></o:p></span></p>
</div>
<div>
<div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4">log {<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> source(s_network)</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">;</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p> </o:p></span></p>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4">
</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955"># First branch, for 127.0.0.1 -> destination1</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> log {<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> filter { netmask(</span><span style="font-size:10.5pt;font-family:"Courier New";color:#CE9178">"127.0.0.1"</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4">)</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">;
};</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> destination(d_network1)</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">;</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> flags(final)</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">; # Don't forget to
stop processing</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> }</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">;</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p> </o:p></span></p>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4">
</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955"># Second branch, for 127.0.0.2 -> destination2</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> log {<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> filter { netmask(</span><span style="font-size:10.5pt;font-family:"Courier New";color:#CE9178">"127.0.0.2"</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4">)</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">;
};</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> destination(d_network2)</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">;</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> flags(final)</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">; # Don't forget to
stop processing</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"> }</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">;</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:14.25pt;background:#1E1E1E"><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4">}</span><span style="font-size:10.5pt;font-family:"Courier New";color:#6A9955">;</span><span style="font-size:10.5pt;font-family:"Courier New";color:#D4D4D4"><o:p></o:p></span></p>
</div>
</div>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-family:"Calibri",sans-serif;color:black"><o:p> </o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-family:"Calibri",sans-serif;color:black">Cheers,<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white"><span style="font-family:"Calibri",sans-serif;color:black">Attila<o:p></o:p></span></p>
</div>
<div class="MsoNormal" align="center" style="text-align:center">
<hr size="2" width="98%" align="center">
</div>
<div id="divRplyFwdMsg">
<p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:black">From:</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:black"> syslog-ng <<a href="mailto:syslog-ng-bounces@lists.balabit.hu">syslog-ng-bounces@lists.balabit.hu</a>>
on behalf of Peter Griggs <<a href="mailto:peter@petergriggs.co.uk">peter@petergriggs.co.uk</a>><br>
<b>Sent:</b> Tuesday, January 12, 2021 2:31 PM<br>
<b>To:</b> Syslog-ng users' and developers' mailing list <<a href="mailto:syslog-ng@lists.balabit.hu">syslog-ng@lists.balabit.hu</a>><br>
<b>Subject:</b> [syslog-ng] Filtering Destination by Source</span> <o:p></o:p></p>
<div>
<p class="MsoNormal"> <o:p></o:p></p>
</div>
</div>
<div>
<div style="border:solid #9C6500 1.0pt;padding:2.0pt 2.0pt 2.0pt 2.0pt">
<p class="MsoNormal" style="line-height:12.0pt;background:#FFEB9C"><b><span style="font-size:10.0pt;font-family:"Calibri",sans-serif;color:#9C6500">CAUTION:</span></b><span style="font-size:10.0pt;font-family:"Calibri",sans-serif;color:black"> This email originated
from outside of the organization. Do not follow guidance, click links, or open attachments unless you recognize the sender and know the content is safe.<o:p></o:p></span></p>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<div>
<p class="xmsonormal">Hello,<o:p></o:p></p>
<p class="xmsonormal"> <o:p></o:p></p>
<p class="xmsonormal">We have a lot of network logs all being pointed to a central syslog however this is a mix of vendors (Cisco / Juniper / Checkpoint) etc. is there a way of splitting the destination file by vendor type / or source IP address? We ingest
this data into Splunk so want to get the source typing right however I am unable to get the sources to point to various listeners and I would prefer.<o:p></o:p></p>
<p class="xmsonormal"> <o:p></o:p></p>
<p class="xmsonormal">Thanks<o:p></o:p></p>
<p class="xmsonormal">Peter.<o:p></o:p></p>
</div>
</div>
</div>
</div>
</body>
</html>