Hello,
thank you ! that was my issue.
I do have issue to find a proper filter for apache2. vhost mixed up as filtering on the FQDN is not enough.
Some apache2 logs doesn't contain the FQDN.
Any idea ?
Regards,
Hugo
The apache one should come first, otherwise your logs will go through
the ones before it (if any of the filters match, of course), resulting
in duplicate logs.
Put the apache one first, and flags(final) will not let matching logs
through to the others.
--
|8]
______________________________________________________________________________
Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng
Documentation: http://www.balabit.com/support/documentation/?product=syslog-ng
FAQ: http://www.balabit.com/wiki/syslog-ng-faq