Thanks for your help, but im not sure to understant.
For the moment's i received syslog alert from other host's in the network, but syslog put the alert message in /var/log/message instead of /var/log/nameofserver.
I dont understand what i'm doing wrong.
>
> Do you want i paste here my syslog-ng.conf ? (i only change
> source net { udp(ip(127.0.0.1) port(514)); }; for source
> net { udp(ip(192.168.33.8) port(514)); };
Without looking up the source my first guess would be that the
problem is caused by having udp() in your configuration twice.
The 'src' and the 'net' sources both have udp(). It is possible
that the second bind was unsuccessful as syslog-ng already has
bound to 0.0.0.0:514 UDP port.Check your logs whether this is
the case, it should be logged. Optionally remove udp() from
the 'src' source if you're not logging from jails running on
the local machine.
Regards,
Sandor
--------------------------------------------------------
NOTICE: If received in error, please destroy and notify sender. Sender does not intend to waive confidentiality or privilege. Use of this email is prohibited when received in error.
_______________________________________________
syslog-ng maillist - syslog-ng@lists.balabit.hu
https://lists.balabit.hu/mailman/listinfo/syslog-ngFrequently asked questions at
http://www.campin.net/syslog-ng/faq.html
Francis Provencher
Ministère de la Sécurité publique du Québec
Direction des technologies de l'information
Division de la sécurité informatique
Tél: 1 418 646-3258
Courriel:
Francis.provencher@Msp.gouv.qc.ca CEH - Certified Ethical Hackers
SSCP - System Security Certified Practitionner
Sec+ - Security +