hello. I am having a slight problem with syslog-ng. It is running fine on all of our servers, however we did set up a logging host to keep an archive of other servers logs. It is using udp as the protocol to send the logger messages to the loghost. When the messages comes through to the loghost and is filtered to the appropriate destination, it always appears twice. For example the following is common to 99% of all the logs on the loghost: Feb 16 13:13:47 sun08 su: 'su root' succeeded for mjs on /dev/pts/24 Feb 16 13:13:47 sun08 su: 'su root' succeeded for mjs on /dev/pts/24 Feb 16 14:27:19 sun08 login: pam_authenticate: error Authentication failed Feb 16 14:27:19 sun08 login: pam_authenticate: error Authentication failed Feb 19 08:06:33 sun08 su: pam_authenticate: error Authentication failed Feb 19 08:06:33 sun08 su: pam_authenticate: error Authentication failed Feb 19 08:06:33 sun08 su: 'su root' failed for tvd on /dev/pts/12 Feb 19 08:06:33 sun08 su: 'su root' failed for tvd on /dev/pts/12 This is not happening on the local servers. Anyone have any suggestions? Thanks in advance for your help. Matt Studley American Mathematical Society Systems Administrator
participants (1)
-
Matt Studley