[syslog-ng] IPv6 rewrite rule PVCE

strife at riseup.net strife at riseup.net
Thu Feb 14 13:50:00 CET 2013


> Hi,
>
> I think it would be awesome if we added this functionality to syslog-ng as
> a
> reusable config block (a.k.a SCL).

Indeed!

> As I discussed it with Bazsi IRL, it could replace the IPs with a hash by
> default

If you don't strip at least parts of the IPs, this is useless. At least
for IPv4, it would be easy to just recreate the hashes for all possible IP
combinations and match the hash ("rainbow table").

I see that one might prefer to strip the last one or two octets instead of
getting rid of the complete IP.

-- 
strife



More information about the syslog-ng mailing list