[syslog-ng]Syslog forwarding

Fernando Cardoso fernando.cardoso@whatevernet.com
Wed, 30 Oct 2002 20:31:40 -0000

Hi all

I'm designing a solution where I need to forward syslog messages to 2
different servers (Cisco Works and a log correlation system). The message=
will be sent from Cisco routers and PIXes to a box running syslog-ng that
will forward the messages to the servers according to the facility and
levels defined on filters.

My question regards the origin of the messages as they will be seen by th=
end servers. Since both Cisco Works and the log correlation engine rely o=
the source IP to acknowledge and trigger alarms, will they see the syslog=
box IP or the original IP address of the routers and PIXes? In other word=
will syslog-ng spoof the source IP addresses when forwarding the messages=

Thanks in advance


