[syslog-ng] host name treatment

Russell Fulton r.fulton at auckland.ac.nz
Fri Aug 25 02:39:28 CEST 2006


Hi Harry,

Harry Hoffman wrote:
> Hey Russell,
> 
> This can usually be corrected by forcing the use of tcp as opposed to udp.
> 
> It doesn't work for all instances, I still haven't figured out why :-(
> 
I think I have solved the immediate issue by changing HOST to HOST_FROM
in the file name template.

BTW first alpha on SELMS is about ready to fly. I'm running it in
parallel with sl3 at the moment.  If you sign up with rubyforge I'll add
you to the list of developers for the project.  The current version
basically duplicates sl3 with a few added bells and whistles (you can
create counters based or text from REs so you can count the number of
log in attempts for all hosts...)

I've written but not tested all the stuff for real time scanning --
that's next months exercise...

BTW is that Phd finished yet?  ;)  If you wait much longer you will be
able to have Alex's room when you visit -- he is dead set on leaving
home next year :)

Russell


More information about the syslog-ng mailing list