Forward syslog messages unchanged
I found a thread from about 5 years ago where someone wanted to forward messages untouched to another system, but there never was a follow up to say if it was possible. I need to do that, but the messages are still getting to the remote system with my ip address as the source. I have the keep_hostnames(yes) global option set, and I'm still having the problem. Is there any other option I may not know about to do this? Do I need to set up another syslog-ng enabled server and have that system read from there instead of me forwarding the events right to that machine's port? Thanks, Paul ************************************ This email may contain privileged and/or confidential information that is intended solely for the use of the addressee. If you are not the intended recipient or entity, you are strictly prohibited from disclosing, copying, distributing or using any of the information contained in the transmission. If you received this communication in error, please contact the sender immediately and destroy the material in its entirety, whether electronic or hard copy. This communication may contain nonpublic personal information about consumers subject to the restrictions of the Gramm-Leach-Bliley Act and the Sarbanes-Oxley Act. You may not directly or indirectly reuse or disclose such information for any purpose other than to provide the services for which you are receiving the information. There are risks associated with the use of electronic transmission. The sender of this information does not control the method of transmittal or service providers and assumes no duty or obligation for the security, receipt, or third party interception of this transmission. ************************************
On Wed, 2009-10-07 at 11:51 -0400, PAUL WILLIAMSON wrote:
I found a thread from about 5 years ago where someone wanted to forward messages untouched to another system, but there never was a follow up to say if it was possible.
I need to do that, but the messages are still getting to the remote system with my ip address as the source. I have the keep_hostnames(yes) global option set, and I'm still having the problem. Is there any other option I may not know about to do this?
The option you need is called spoof_source (boolean). It works only with UDP targets however. See the agmin guide: http://www.balabit.hu/dl/html/syslog-ng-v3.0-guide-admin-en.html/ch08s02.htm... Regards, Peter -- Höltzl Péter CISA, IT biztonsági tanácsadó holtzl.peter@balabit.hu +36 20 366 9667 BalaBit IT Security 1115 Budapest XI. Bártfai u. 54. Tel +36 1 371 0540 Fax +36 1 208 0875 Az üzenet és annak bármely csatolt anyaga bizalmas, jogi védelem alatt áll, a nyilvános közléstől védett. Az üzenetet kizárólag a címzett, illetve az általa meghatalmazottak használhatják fel. Ha Ön nem az üzenet címzettje, úgy kérjük, hogy telefonon, vagy e-mail-ben értesítse erről az üzenet küldőjét és törölje az üzenetet, valamint annak összes csatolt mellékletét a rendszeréből. Ha Ön nem az üzenet címzettje, abban az esetben tilos az üzenetet vagy annak bármely csatolt mellékletét lemásolnia, elmentenie, az üzenet tartalmát bárkivel közölnie vagy azzal visszaélnie.
participants (2)
-
Höltzl Péter
-
PAUL WILLIAMSON