[syslog-ng] How to deal with duplicate log entries

Chuck chuck.carson at gmail.com
Wed Jul 21 21:00:11 CEST 2010


I have the following log statgements.. (Im basically trying to mirror what
solaris 10's default syslogl.conf does):

log { source (s_streams);       filter (f_emerg);
destination (l_messages); };
log { source (s_streams);       filter (f_err);
destination (l_messages); };
log { source (s_streams);       filter (f_kern); filter (f_debug);
destination (l_messages); };
log { source (s_streams);       filter (f_daemon); filter (f_notice);
destination (l_messages); };
log { source (s_streams);       filter (f_mail); filter (f_crit);
destination (l_messages); };
log { source (s_streams);       filter (f_mail); filter (f_debug);
destination (l_syslog);   };
log { source (s_streams);       filter (f_auth); filter (f_info);
destination (l_authlog);  };    # sshd logging

However when sending to daemon.err I get duplicate messages...

Should I change line 2 to this:
log { source (s_streams);       filter (f_err);   filter (not f_daemon)
                     destination (l_messages); };

Or should I hard-code every facility like so:
log { source (s_streams);       filter (f_err);   filter (f_daemon)
                     destination (l_messages); };
log { source (s_streams);       filter (f_err);   filter (f_mail)
                     destination (l_messages); };
log { source (s_streams);       filter (f_err);   filter (f_auth)
                     destination (l_messages); };
...
and so on?

Thx,.CC
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.balabit.hu/pipermail/syslog-ng/attachments/20100721/f0223429/attachment.htm 


More information about the syslog-ng mailing list