Hello

 

I would like to get some clarification on the source tag in both syslog client and server.

I have different clients hosting apache / weblogic

 

My Syslog-ng Server has ip 192.x.x.x

 

Apache (client) has ip 192.x.x.1

 

Weblogic (client) has ip 192.x.x.2

 

In all the clients syslog configuration files, i have added

 

destination apacheaccesslog {

tcp("192.x.x.x " port(3331));

};

 

destination weblogiclog {

tcp("192.x.x.x " port(3332));

};

 

 

My issue is in the syslog-ng server configuration file, if i add

 

source apache_access {tcp(ip(192.x.x.x) port(3331));

};

 

Should the ip be the server ip or the client ip (in this example, i have put the syslog-ng server ip). Does the port number differentiate the different sources we are receiving the log files ???

 

 

 

 

 

 

logo-emailsignature.jpgKhaleelah Peerbocus – Systems Analyst

Mauritius Cargo Community Services

Business Registration No.: C08077158

VAT Registration No.: VAT20427044

1st Floor, Trade and Marketing Centre, Mer Rouge

Port-Louis, Mauritius

Tel: +230 206 2970 - Cell: +230 498 7897 Fax: +230 216 8858

Email: systems2@maccs.mu - Website: http://www.maccs.mu