[syslog-ng]syslog-ng do not work....
Schernau, Ed
syslog-ng@lists.balabit.hu
Tue, 27 Jan 2004 10:55:46 -0500
This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.
------_=_NextPart_001_01C3E4EE.06DB98B0
Content-Type: text/plain
FYI, use_time_recvd only works if you are logging with a template. Or has
this been fixed in the latest?
-----Original Message-----
From: Alessandro Fiorenzi [mailto:a.fiorenzi@infogroup.it]
Sent: Tuesday, January 27, 2004 10:53 AM
To: Syslog-ng
Subject: [syslog-ng]syslog-ng do not work....
Hi, I have set this configuration on central logserver
options {
long_hostnames(off);
sync(0);
log_fifo_size(1000);
dnscache(yes);
use_fqdn(yes);
use_time_recvd(true);
};
source src {
internal();
file("/proc/kmsg" log_prefix("kernel: "));
tcp(ip(192.168.52.100) port(514) max-connections(1000));
udp(ip(0.0.0.0) port(514));
};
but it does not work. The fist errore is on dnscache(yes);, if i remove this
I get the second on use_time_recvd(true);, remove this one I get errore on
file("/proc/kmsg" log_prefix("kernel: ")); .... why?
Thanks
Fiorenzi A.
------------------------------------------------------------------------
INFOGROUP S.P.A http://www.infogroup.it
-------------------------------------------------------------------------
DR. FIORENZI ALESSANDRO
Consulente Tribunale Firenze - sicurezza informatica -
Security Administrator
Socio <file:///home/fiore/signature/www.clusit.it> CLUSIT,
<file:///home/fiore/signature/www.alsi.it> ALSI
Tel : +39.055.43.65.742
CE : +39.335.64.144.77
@Email : a.fiorenzi@infogroup.it
PGP Key: http://www.infogroup.it/ds/fiorenzi.asc
-------------------------------------------------------------------------
"Faber est suae quisque fortunae"
-------------------------------------------------------------------------
*****This information may be confidential and/or privileged. Use of this
information by anyone other than the intended recipient is prohibited. If
you received this in error, please inform the sender and remove any record
of this message.*****
------_=_NextPart_001_01C3E4EE.06DB98B0
Content-Type: text/html
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3Dus-ascii">
<TITLE>Message</TITLE>
<META content=3D"MSHTML 6.00.2800.1264" name=3DGENERATOR></HEAD>
<BODY>
<DIV><SPAN class=3D436235515-27012004><FONT face=3DArial =
color=3D#0000ff size=3D2>FYI,=20
use_time_recvd only works if you are logging with a template. Or =
has this=20
been fixed in the latest?</FONT></SPAN></DIV>
<BLOCKQUOTE style=3D"MARGIN-RIGHT: 0px">
<DIV></DIV>
<DIV class=3DOutlookMessageHeader lang=3Den-us dir=3Dltr =
align=3Dleft><FONT=20
face=3DTahoma size=3D2>-----Original Message-----<BR><B>From:</B> =
Alessandro=20
Fiorenzi [mailto:a.fiorenzi@infogroup.it] <BR><B>Sent:</B> Tuesday, =
January=20
27, 2004 10:53 AM<BR><B>To:</B> Syslog-ng<BR><B>Subject:</B>=20
[syslog-ng]syslog-ng do not work....<BR><BR></FONT></DIV>Hi, I have =
set this=20
configuration on central logserver<BR><BR>options=20
{<BR> =20
long_hostnames(off); =20
<BR> =20
sync(0); =20
<BR> =20
log_fifo_size(1000);<BR> =20
dnscache(yes);<BR> =20
use_fqdn(yes);<BR> =20
use_time_recvd(true);<BR> =20
};<BR><BR>source src {<BR> =20
internal();<BR> =
file("/proc/kmsg"=20
log_prefix("kernel: =
"));<BR> =20
tcp(ip(192.168.52.100) port(514)=20
max-connections(1000));<BR> =
udp(ip(0.0.0.0) =
port(514));<BR> =20
};<BR><BR>but it does not work. The fist errore is on dnscache(yes);, =
if i=20
remove this I get the second on use_time_recvd(true);, remove this =
one I get=20
errore on file("/proc/kmsg" log_prefix("kernel: ")); ....=20
why?<BR><BR>Thanks<BR><BR>Fiorenzi A.<BR><BR><BR>
<TABLE cellSpacing=3D0 cellPadding=3D0 width=3D"100%">
<TBODY>
<TR>
<TD>
<TABLE cellSpacing=3D0 cellPadding=3D0 width=3D"100%">
<TBODY>
<TR>
<TD><FONT=20
=
size=3D3><B>------------------------------------------------------------=
------------=20
<ADDRESS>INFOGROUP S.P.A =20
=20
http://www.infogroup.it=20
=
</ADDRESS>--------------------------------------------------------------=
-----------<BR>DR.=20
FIORENZI ALESSANDRO </B></FONT><BR><BR>Consulente =
Tribunale=20
Firenze - sicurezza informatica -<BR>Security =
Administrator=20
<BR>Socio <A=20
=
href=3D"file:///home/fiore/signature/www.clusit.it"><U>CLUSIT</U></A>,=20
<A=20
=
href=3D"file:///home/fiore/signature/www.alsi.it"><U>ALSI</U></A><BR><BR=
><BR><BR><BR>
<ADDRESS>Tel : +39.055.43.65.742 <BR>CE : =
+39.335.64.144.77=20
<BR>@Email : a.fiorenzi@infogroup.it <BR>PGP Key:=20
http://www.infogroup.it/ds/fiorenzi.asc</ADDRESS><FONT=20
=
size=3D3><I>------------------------------------------------------------=
-------------<BR> &=
nbsp; =20
<B>"Faber est suae quisque fortunae"=20
=
</B><BR>----------------------------------------------------------------=
---------</I></FONT>=20
=
</TD></TR></TBODY></TABLE></TD></TR></TBODY></TABLE></BLOCKQUOTE></BODY>=
</HTML>
<P><I><FONT SIZE=3D2 FACE=3D"Arial">*****This information may be =
confidential and/or privileged. Use of this information by anyone other =
than the intended recipient is prohibited. If you received this in =
error, please inform the sender and remove any record of this =
message.*****</FONT></I></P>
------_=_NextPart_001_01C3E4EE.06DB98B0--