[syslog-ng] How to deal with duplicate log entries
Chuck
chuck.carson at gmail.com
Wed Jul 21 21:00:11 CEST 2010
I have the following log statgements.. (Im basically trying to mirror what
solaris 10's default syslogl.conf does):
log { source (s_streams); filter (f_emerg);
destination (l_messages); };
log { source (s_streams); filter (f_err);
destination (l_messages); };
log { source (s_streams); filter (f_kern); filter (f_debug);
destination (l_messages); };
log { source (s_streams); filter (f_daemon); filter (f_notice);
destination (l_messages); };
log { source (s_streams); filter (f_mail); filter (f_crit);
destination (l_messages); };
log { source (s_streams); filter (f_mail); filter (f_debug);
destination (l_syslog); };
log { source (s_streams); filter (f_auth); filter (f_info);
destination (l_authlog); }; # sshd logging
However when sending to daemon.err I get duplicate messages...
Should I change line 2 to this:
log { source (s_streams); filter (f_err); filter (not f_daemon)
destination (l_messages); };
Or should I hard-code every facility like so:
log { source (s_streams); filter (f_err); filter (f_daemon)
destination (l_messages); };
log { source (s_streams); filter (f_err); filter (f_mail)
destination (l_messages); };
log { source (s_streams); filter (f_err); filter (f_auth)
destination (l_messages); };
...
and so on?
Thx,.CC
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.balabit.hu/pipermail/syslog-ng/attachments/20100721/f0223429/attachment.htm
More information about the syslog-ng
mailing list