[syslog-ng]syslog-ng.conf

Nijs, Daniel NijsD@telergy.net
Tue, 10 Jul 2001 15:27:34 -0400


Hello,

I am relatively new to syslog-ng (only been running it for a month) and love
the software.  I would like to congratulate the author on doing such a great
job.  This is a powerful product, and with this comes complexity, and I have
a few questions I am not able to find an answer for.

I have a webserver logging to a centralized host, and I filter the logs
using specific criteria (i.e. document name).  Let's give this file a name
to make this question easier to understand.  I log this data to hits.log.
Now, I want to filter out a certain IP to a separate file (ip.log), and not
show the entries that were logged to ip.log in hits.log.  It seems that
syslog-ng keeps processing all rules, even after there was a match.  I was
hoping that there was an option to stop processing any further rules for
that matched data to solve this problem, but am unable to find any solution.
Does anyone have any suggestions on how to do this?  Thanks.

Best regards,

Dan