Swapna | 4 Dec 21:16 2008
Picon

Need help to send logs to a different server

Hi,

We have syslog-ng configuration  as follows:

   -  There are 50 clients  communicating to one log server

   -  The  log server is kept in secured place where nobody have access

   -  All the logs  of 50 clients  are coming to the log server  and
      the logs are kept  as follow

          /var/log/syslog-ng/<client host>/extended.log

   
We want  all the log of each client  to relay into a seperate server live.
Means the  current log  file of each  host will go to the new server  
simultaneously  as  it is going to the central log server.   

We can configure a  second  log server  like the existing one.  But our
requirement  is,  that all the logs will be received from the central log  server not from the client  hosts.

Any help is  really appreciated.

Thanks

      
______________________________________________________________________________
Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng
Documentation: http://www.balabit.com/support/documentation/?product=syslog-ng
FAQ: http://www.campin.net/syslog-ng/faq.html
(Continue reading)

liuruihong | 5 Dec 09:23 2008

答复: Need help to send logs to a different server

in the client,you can define many remote log server simultaneously.syslog
and syslog-ng all support this function.
You can find in the manual:)

谢谢!

刘蕊红 |sys|6758

-----邮件原件-----
发件人: syslog-ng-bounces <at> lists.balabit.hu
[mailto:syslog-ng-bounces <at> lists.balabit.hu] 代表 Swapna
发送时间: 2008年12月5日 4:17
收件人: syslog-ng <at> lists.balabit.hu
主题: [syslog-ng] Need help to send logs to a different server

Hi,

We have syslog-ng configuration  as follows:

   -  There are 50 clients  communicating to one log server

   -  The  log server is kept in secured place where nobody have access

   -  All the logs  of 50 clients  are coming to the log server  and
      the logs are kept  as follow

          /var/log/syslog-ng/<client host>/extended.log

   
We want  all the log of each client  to relay into a seperate server live.
(Continue reading)

bugzilla | 5 Dec 12:53 2008

[Bug 24] New: .pid file not set correctly (STOP not working)

https://bugzilla.balabit.com/show_bug.cgi?id=24

           Summary: .pid file not set correctly (STOP not working)
           Product: syslog-ng
           Version: unspecified
          Platform: Other
        OS/Version: Linux
            Status: NEW
          Severity: normal
          Priority: unspecified
         Component: syslog-ng
        AssignedTo: bazsi <at> balabit.hu
        ReportedBy: man <at> inspektsecurity.com
Type of the Report: ---
   Estimated Hours: 0.0

Hi.

in installed syslog-ng 3.0.1 PE (syslog-ng-premium-edition-3.0.1-linux-i386.run).
The installation is on a CentOS 5 system (RedHat spin-off).

Although the program itself works fine, the RC scripts STOP command does not work.

I traced the problem down to the .pid file not being set correctly.
According to the RC script the .pid file shoud be in:
PIDFILE=$SYSLOGNG_PREFIX/var/run/syslog-ng.pid

resulting in the below when running STOP/RESTART
------------
[root <at> test-server:~] /etc/init.d/syslog-ng restart
(Continue reading)

bugzilla | 6 Dec 18:09 2008

[Bug 24] .pid file not set correctly (STOP not working)

https://bugzilla.balabit.com/show_bug.cgi?id=24

--- Comment #1 from Balazs Scheidler <bazsi <at> balabit.hu>  2008-12-06 18:09:09 ---
Thanks for the report. I'm forwarding this to our internal bugzilla.

--

-- 
Configure bugmail: https://bugzilla.balabit.com/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are watching all bug changes.
______________________________________________________________________________
Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng
Documentation: http://www.balabit.com/support/documentation/?product=syslog-ng
FAQ: http://www.campin.net/syslog-ng/faq.html

Lavannya | 7 Dec 16:03 2008
Picon

Re: 答复: Need help to send logs to a different server

Yes ,  from the client  we can ,  but I think if you read my mail properly, I clearly written that my requirement is
NOT, to get the logs from the client.  I want  to set one server , which will get  all the information from the
central log master. Yes , I know it can be done through ssh/rsync. But I wanted to know , if there is any option
in syslog-ng .

Thanks

--- On Fri, 12/5/08, liuruihong <liuruihong <at> baidu.com> wrote:

> From: liuruihong <liuruihong <at> baidu.com>
> Subject: 答复: [syslog-ng] Need help to send logs to a different server
> To: swap_project <at> yahoo.com, "'Syslog-ng users' and developers' mailing list'" <syslog-ng <at> lists.balabit.hu>
> Date: Friday, December 5, 2008, 3:23 AM
> in the client,you can define many remote log server
> simultaneously.syslog
> and syslog-ng all support this function.
> You can find in the manual:)
> 
> 
> 谢谢!
> 
> 刘蕊红 |sys|6758
> 
> -----邮件原件-----
> 发件人: syslog-ng-bounces <at> lists.balabit.hu
> [mailto:syslog-ng-bounces <at> lists.balabit.hu] 代表 Swapna
> 发送时间: 2008年12月5日 4:17
> 收件人: syslog-ng <at> lists.balabit.hu
> 主题: [syslog-ng] Need help to send logs to a different
> server
(Continue reading)

Marc Andersen | 8 Dec 14:04 2008

Re: 答复: Need help to send logs to a different server

If the central syslog server is running syslog-ng you can just add another destination (live log server) to the already existing local files.

log{
source (udp/tcp incoming);
destination(new live log server);
};

cheers
/Marc


On 07/12/08 16.03, "Lavannya" <swap_project <at> yahoo.com> wrote:

Yes ,  from the client  we can ,  but I think if you read my mail properly, I clearly written that my requirement is NOT, to get the logs from the client.  I want  to set one server , which will get  all the information from the central log master. Yes , I know it can be done through ssh/rsync. But I wanted to know , if there is any option in syslog-ng .

Thanks



--- On Fri, 12/5/08, liuruihong <liuruihong <at> baidu.com> wrote:

> From: liuruihong <liuruihong <at> baidu.com>
> Subject: 答复: [syslog-ng] Need help to send logs to a different server
> To: swap_project <at> yahoo.com, "'Syslog-ng users' and developers' mailing list'" <syslog-ng <at> lists.balabit.hu>
> Date: Friday, December 5, 2008, 3:23 AM
> in the client,you can define many remote log server
> simultaneously.syslog
> and syslog-ng all support this function.
> You can find in the manual:)
>
>
> 谢谢!
>
> 刘蕊红 |sys|6758
>
> -----邮件原件-----
> 发件人: syslog-ng-bounces <at> lists.balabit.hu
> [mailto:syslog-ng-bounces <at> lists.balabit.hu] 代表 Swapna
> 发送时间: 2008年12月5日 4:17
> 收件人: syslog-ng <at> lists.balabit.hu
> 主题: [syslog-ng] Need help to send logs to a different
> server
>
> Hi,
>
>
> We have syslog-ng configuration  as follows:
>
>    -  There are 50 clients  communicating to one log server
>
>    -  The  log server is kept in secured place where nobody
> have access
>
>    -  All the logs  of 50 clients  are coming to the log
> server  and
>       the logs are kept  as follow
>
>           /var/log/syslog-ng/<client
> host>/extended.log
>
>
> We want  all the log of each client  to relay into a
> seperate server live.
> Means the  current log  file of each  host will go to the
> new server
> simultaneously  as  it is going to the central log server.
>
>
> We can configure a  second  log server  like the existing
> one.  But our
> requirement  is,  that all the logs will be received from
> the central log
> server not from the client  hosts.
>
> Any help is  really appreciated.
>
> Thanks
>
>
>
>
> ____________________________________________________________________________
> __
> Member info:
> https://lists.balabit.hu/mailman/listinfo/syslog-ng
> Documentation:
> http://www.balabit.com/support/documentation/?product=syslog-ng
> FAQ: http://www.campin.net/syslog-ng/faq.html



______________________________________________________________________________
Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng
Documentation: http://www.balabit.com/support/documentation/?product=syslog-ng
FAQ: http://www.campin.net/syslog-ng/faq.html


______________________________________________________________________________
Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng
Documentation: http://www.balabit.com/support/documentation/?product=syslog-ng
FAQ: http://www.campin.net/syslog-ng/faq.html

Lavannya | 8 Dec 19:18 2008
Picon

Re: 答复: Need help to send logs to a different server

Hi Mark,

Thanks for your reply.  I am getting error whatever configuration you had said.  May be  I need to change our
existing configuration again.  Here is the central  log server  configuration I am sending as attachment.
Our central  log server  is already configured  with  tcp(ip(0.0.0.0) ip and when  I am adding the new  server  to
collect the log it is giving error.

  - I want to add another  server (this is needed for some application )
    to my central log server which  will
    get all the logs  from the central log  server.  

Pl. feel free to correct  the log file and send it to me.

Thanks again

--- On Mon, 12/8/08, Marc Andersen <man <at> inspektsecurity.com> wrote:

> From: Marc Andersen <man <at> inspektsecurity.com>
> Subject: Re: [syslog-ng] 答复:  Need help to send logs to a different server
> To: "Syslog-ng users' and developers' mailing list" <syslog-ng <at> lists.balabit.hu>
> Date: Monday, December 8, 2008, 8:04 AM
> If the central syslog server is running syslog-ng you can
> just add another destination (live log server) to the
> already existing local files.
> 
> log{
> source (udp/tcp incoming);
> destination(new live log server);
> };
> 
> cheers
> /Marc
> 
> 
> On 07/12/08 16.03, "Lavannya"
> <swap_project <at> yahoo.com> wrote:
> 
> Yes ,  from the client  we can ,  but I think if you read
> my mail properly, I clearly written that my requirement is
> NOT, to get the logs from the client.  I want  to set one
> server , which will get  all the information from the
> central log master. Yes , I know it can be done through
> ssh/rsync. But I wanted to know , if there is any option in
> syslog-ng .
> 
> Thanks
> 
> 
> 
> --- On Fri, 12/5/08, liuruihong
> <liuruihong <at> baidu.com> wrote:
> 
> > From: liuruihong <liuruihong <at> baidu.com>
> > Subject: 答复: [syslog-ng] Need help to send logs to
> a different server
> > To: swap_project <at> yahoo.com, "'Syslog-ng
> users' and developers' mailing list'"
> <syslog-ng <at> lists.balabit.hu>
> > Date: Friday, December 5, 2008, 3:23 AM
> > in the client,you can define many remote log server
> > simultaneously.syslog
> > and syslog-ng all support this function.
> > You can find in the manual:)
> >
> >
> > 谢谢!
> >
> > 刘蕊红 |sys|6758
> >
> > -----邮件原件-----
> > 发件人: syslog-ng-bounces <at> lists.balabit.hu
> > [mailto:syslog-ng-bounces <at> lists.balabit.hu] 代表
> Swapna
> > 发送时间: 2008年12月5日 4:17
> > 收件人: syslog-ng <at> lists.balabit.hu
> > 主题: [syslog-ng] Need help to send logs to a
> different
> > server
> >
> > Hi,
> >
> >
> > We have syslog-ng configuration  as follows:
> >
> >    -  There are 50 clients  communicating to one log
> server
> >
> >    -  The  log server is kept in secured place where
> nobody
> > have access
> >
> >    -  All the logs  of 50 clients  are coming to the
> log
> > server  and
> >       the logs are kept  as follow
> >
> >           /var/log/syslog-ng/<client
> > host>/extended.log
> >
> >
> > We want  all the log of each client  to relay into a
> > seperate server live.
> > Means the  current log  file of each  host will go to
> the
> > new server
> > simultaneously  as  it is going to the central log
> server.
> >
> >
> > We can configure a  second  log server  like the
> existing
> > one.  But our
> > requirement  is,  that all the logs will be received
> from
> > the central log
> > server not from the client  hosts.
> >
> > Any help is  really appreciated.
> >
> > Thanks
> >
> >
> >
> >
> >
> ____________________________________________________________________________
> > __
> > Member info:
> > https://lists.balabit.hu/mailman/listinfo/syslog-ng
> > Documentation:
> >
> http://www.balabit.com/support/documentation/?product=syslog-ng
> > FAQ: http://www.campin.net/syslog-ng/faq.html
> 
> 
> 
> ______________________________________________________________________________
> Member info:
> https://lists.balabit.hu/mailman/listinfo/syslog-ng
> Documentation:
> http://www.balabit.com/support/documentation/?product=syslog-ng
> FAQ: http://www.campin.net/syslog-ng/faq.html
> 
> 
> ______________________________________________________________________________
> Member info:
> https://lists.balabit.hu/mailman/listinfo/syslog-ng
> Documentation:
> http://www.balabit.com/support/documentation/?product=syslog-ng
> FAQ: http://www.campin.net/syslog-ng/faq.html

      
# Begin /etc/syslog-ng/syslog-ng.conf

 


options { 	sync (0);
		time_reopen (10);
		log_fifo_size (1000);
		long_hostnames(off); 
		use_dns (yes);
		use_fqdn (no);
		create_dirs (yes);
		keep_hostname (yes);
};

source src {	unix-stream("/dev/log");
		internal();
		pipe("/proc/kmsg");
    };


source remotetcp { tcp(ip(0.0.0.0) port(514) max-connections(600)); };
source remoteudp { udp(); };



# Remote Logging
##########################


destination everything { file("/var/log/remotes/$HOST/$HOST-all-system.logs"); };
filter f_everything { level(debug..emerg); };
log { source(remotetcp); filter(f_everything); destination(everything); };
log { source(remoteudp); filter(f_everything); destination(everything); };

destination authpriv { file("/var/log/remotes/$HOST/$HOST-authpriv.log"); };
filter f_authpriv { facility(authpriv); };
log { source(remotetcp); filter(f_authpriv); destination(authpriv); };
log { source(remoteudp); filter(f_authpriv); destination(authpriv); };

destination auth     { file("/var/log/remotes/$HOST/$HOST-auth.log"); };
filter f_auth { facility(auth); };
log { source(remotetcp); filter(f_auth); destination(auth); };
log { source(remoteudp); filter(f_auth); destination(auth); };




# Local Destinations
#####################
destination syslog { file("/var/log/syslog.log"); };
destination messages { file("/var/log/messages.log"); };
destination auth { file("/var/log/auth.log"); };
destination authpriv { file("/var/log/authpriv.log"); };
destination cron { file("/var/log/cron.log"); };
destination kernel { file("/var/log/kernel.log"); };
destination daemon { file("/var/log/daemon.log"); };
destination lpr { file("/var/log/lpr.log"); };
destination mail { file("/var/log/mail.log"); };
destination debug { file("/var/log/debug.log"); };
#
destination console { usertty("root"); };
destination console_all { file("/dev/tty12"); };


# Local Filters
###############
filter f_syslog { not facility(authpriv, auth, mail); };
filter f_messages { level(info..warn) and not facility(auth, authpriv, mail, news); };
filter f_auth { facility(auth); };
filter f_authpriv { facility(auth, authpriv); };
filter f_cron { facility(cron); };
filter f_daemon { facility(daemon); };
filter f_kernel { facility(kern); };
filter f_lpr { facility(lpr); };
filter f_mail { facility(mail); };
filter f_debug { not facility(auth, authpriv, news, mail); };
# 
#
filter f_emergency { level(emerg); };
filter f_info { level(info); };
filter f_notice { level(notice); };
filter f_warn { level(warn); };
filter f_crit { level(crit); };
filter f_err { level(err); };


# Local Log 
############
log { source(src); filter(f_syslog); destination(syslog); };
log { source(src); filter(f_messages); destination(messages); };
log { source(src); filter(f_auth); destination(auth); };
log { source(src); filter(f_authpriv); destination(authpriv); };
log { source(src); filter(f_cron); destination(cron); };
log { source(src); filter(f_kernel); destination(kernel); };
log { source(src); filter(f_daemon); destination(daemon); };
log { source(src); filter(f_lpr); destination(lpr); };
log { source(src); filter(f_mail); destination(mail); };
log { source(src); filter(f_debug); destination(debug); };
#
#
log { source(src); filter(f_emergency); destination(console); };
log { source(src); destination(console_all); };

 
______________________________________________________________________________
Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng
Documentation: http://www.balabit.com/support/documentation/?product=syslog-ng
FAQ: http://www.campin.net/syslog-ng/faq.html

Marc Andersen | 9 Dec 09:13 2008

Re: 答复: Need help to send logs to a different server

Yeah. What I wrote was pseudo-code.
What is in the attached  conf file should work (barring typos and the ever persistent challenge of parenthesis and semicolons)

cheers
/Marc


On 08/12/08 19.18, "Lavannya" <swap_project <at> yahoo.com> wrote:

Hi Mark,

Thanks for your reply.  I am getting error whatever configuration you had said.  May be  I need to change our existing configuration again.  Here is the central  log server  configuration I am sending as attachment. Our central  log server  is already configured  with  tcp(ip(0.0.0.0) ip and when  I am adding the new  server  to collect the log it is giving error.

  - I want to add another  server (this is needed for some application )
    to my central log server which  will
    get all the logs  from the central log  server.

Pl. feel free to correct  the log file and send it to me.

Thanks again





--- On Mon, 12/8/08, Marc Andersen <man <at> inspektsecurity.com> wrote:

> From: Marc Andersen <man <at> inspektsecurity.com>
> Subject: Re: [syslog-ng] 答复:  Need help to send logs to a different server
> To: "Syslog-ng users' and developers' mailing list" <syslog-ng <at> lists.balabit.hu>
> Date: Monday, December 8, 2008, 8:04 AM
> If the central syslog server is running syslog-ng you can
> just add another destination (live log server) to the
> already existing local files.
>
> log{
> source (udp/tcp incoming);
> destination(new live log server);
> };
>
> cheers
> /Marc
>
>
> On 07/12/08 16.03, "Lavannya"
> <swap_project <at> yahoo.com> wrote:
>
> Yes ,  from the client  we can ,  but I think if you read
> my mail properly, I clearly written that my requirement is
> NOT, to get the logs from the client.  I want  to set one
> server , which will get  all the information from the
> central log master. Yes , I know it can be done through
> ssh/rsync. But I wanted to know , if there is any option in
> syslog-ng .
>
> Thanks
>
>
>
> --- On Fri, 12/5/08, liuruihong
> <liuruihong <at> baidu.com> wrote:
>
> > From: liuruihong <liuruihong <at> baidu.com>
> > Subject: 答复: [syslog-ng] Need help to send logs to
> a different server
> > To: swap_project <at> yahoo.com, "'Syslog-ng
> users' and developers' mailing list'"
> <syslog-ng <at> lists.balabit.hu>
> > Date: Friday, December 5, 2008, 3:23 AM
> > in the client,you can define many remote log server
> > simultaneously.syslog
> > and syslog-ng all support this function.
> > You can find in the manual:)
> >
> >
> > 谢谢!
> >
> > 刘蕊红 |sys|6758
> >
> > -----邮件原件-----
> > 发件人: syslog-ng-bounces <at> lists.balabit.hu
> > [mailto:syslog-ng-bounces <at> lists.balabit.hu] 代表
> Swapna
> > 发送时间: 2008年12月5日 4:17
> > 收件人: syslog-ng <at> lists.balabit.hu
> > 主题: [syslog-ng] Need help to send logs to a
> different
> > server
> >
> > Hi,
> >
> >
> > We have syslog-ng configuration  as follows:
> >
> >    -  There are 50 clients  communicating to one log
> server
> >
> >    -  The  log server is kept in secured place where
> nobody
> > have access
> >
> >    -  All the logs  of 50 clients  are coming to the
> log
> > server  and
> >       the logs are kept  as follow
> >
> >           /var/log/syslog-ng/<client
> > host>/extended.log
> >
> >
> > We want  all the log of each client  to relay into a
> > seperate server live.
> > Means the  current log  file of each  host will go to
> the
> > new server
> > simultaneously  as  it is going to the central log
> server.
> >
> >
> > We can configure a  second  log server  like the
> existing
> > one.  But our
> > requirement  is,  that all the logs will be received
> from
> > the central log
> > server not from the client  hosts.
> >
> > Any help is  really appreciated.
> >
> > Thanks
> >
> >
> >
> >
> >
> ____________________________________________________________________________
> > __
> > Member info:
> > https://lists.balabit.hu/mailman/listinfo/syslog-ng
> > Documentation:
> >
> http://www.balabit.com/support/documentation/?product=syslog-ng
> > FAQ: http://www.campin.net/syslog-ng/faq.html
>
>
>
> ______________________________________________________________________________
> Member info:
> https://lists.balabit.hu/mailman/listinfo/syslog-ng
> Documentation:
> http://www.balabit.com/support/documentation/?product=syslog-ng
> FAQ: http://www.campin.net/syslog-ng/faq.html
>
>
> ______________________________________________________________________________
> Member info:
> https://lists.balabit.hu/mailman/listinfo/syslog-ng
> Documentation:
> http://www.balabit.com/support/documentation/?product=syslog-ng
> FAQ: http://www.campin.net/syslog-ng/faq.html



Attachment (syslogng.txt): application/octet-stream, 4928 bytes
______________________________________________________________________________
Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng
Documentation: http://www.balabit.com/support/documentation/?product=syslog-ng
FAQ: http://www.campin.net/syslog-ng/faq.html

Geller, Sandor (IT | 9 Dec 09:22 2008

Re: 答复: Need help to send logs to a different server

Hi,

The f_everthing filter matches on all logs so it is redundant,
you could omit it (using filters is optional in the log sections).

To forward the logs to a second server the easiest would be to
add the host to the everything destination like this:

destination everything {
        file("/var/log/remotes/$HOST/$HOST-all-system.logs"); };
        tcp(1.2.3.4 port(5));
};

Obviously replace the IP address and the port with valid values,
and when the second server doesn't support tcp then you should
use udp.

BTW you should add the log_prefix option to your kernel source
to mimic syslogd's behaviour:

        file("/proc/kmsg" log_prefix("kernel: "));

hth,

Sandor

> -----Original Message-----
> From: syslog-ng-bounces <at> lists.balabit.hu
> [mailto:syslog-ng-bounces <at> lists.balabit.hu] On Behalf Of Lavannya
> Sent: Monday, December 08, 2008 7:18 PM
> To: Syslog-ng users' and developers' mailing list
> Subject: Re: [syslog-ng] 答复: Need help to send logs to a
> different server
>
> Hi Mark,
>
> Thanks for your reply.  I am getting error whatever
> configuration you had said.  May be  I need to change our
> existing configuration again.  Here is the central  log
> server  configuration I am sending as attachment. Our central
>  log server  is already configured  with  tcp(ip(0.0.0.0) ip
> and when  I am adding the new  server  to collect the log it
> is giving error.
>
>   - I want to add another  server (this is needed for some
> application )
>     to my central log server which  will
>     get all the logs  from the central log  server.
>
> Pl. feel free to correct  the log file and send it to me.
>
> Thanks again
>
>
>
>
>
> --- On Mon, 12/8/08, Marc Andersen <man <at> inspektsecurity.com> wrote:
>
> > From: Marc Andersen <man <at> inspektsecurity.com>
> > Subject: Re: [syslog-ng] 答复:  Need help to send logs to a
> different server
> > To: "Syslog-ng users' and developers' mailing list"
> <syslog-ng <at> lists.balabit.hu>
> > Date: Monday, December 8, 2008, 8:04 AM
> > If the central syslog server is running syslog-ng you can
> > just add another destination (live log server) to the
> > already existing local files.
> >
> > log{
> > source (udp/tcp incoming);
> > destination(new live log server);
> > };
> >
> > cheers
> > /Marc
> >
> >
> > On 07/12/08 16.03, "Lavannya"
> > <swap_project <at> yahoo.com> wrote:
> >
> > Yes ,  from the client  we can ,  but I think if you read
> > my mail properly, I clearly written that my requirement is
> > NOT, to get the logs from the client.  I want  to set one
> > server , which will get  all the information from the
> > central log master. Yes , I know it can be done through
> > ssh/rsync. But I wanted to know , if there is any option in
> > syslog-ng .
> >
> > Thanks
> >
> >
> >
> > --- On Fri, 12/5/08, liuruihong
> > <liuruihong <at> baidu.com> wrote:
> >
> > > From: liuruihong <liuruihong <at> baidu.com>
> > > Subject: 答复: [syslog-ng] Need help to send logs to
> > a different server
> > > To: swap_project <at> yahoo.com, "'Syslog-ng
> > users' and developers' mailing list'"
> > <syslog-ng <at> lists.balabit.hu>
> > > Date: Friday, December 5, 2008, 3:23 AM
> > > in the client,you can define many remote log server
> > > simultaneously.syslog
> > > and syslog-ng all support this function.
> > > You can find in the manual:)
> > >
> > >
> > > 谢谢!
> > >
> > > 刘蕊红 |sys|6758
> > >
> > > -----邮件原件-----
> > > 发件人: syslog-ng-bounces <at> lists.balabit.hu
> > > [mailto:syslog-ng-bounces <at> lists.balabit.hu] 代表
> > Swapna
> > > 发送时间: 2008年12月5日 4:17
> > > 收件人: syslog-ng <at> lists.balabit.hu
> > > 主题: [syslog-ng] Need help to send logs to a
> > different
> > > server
> > >
> > > Hi,
> > >
> > >
> > > We have syslog-ng configuration  as follows:
> > >
> > >    -  There are 50 clients  communicating to one log
> > server
> > >
> > >    -  The  log server is kept in secured place where
> > nobody
> > > have access
> > >
> > >    -  All the logs  of 50 clients  are coming to the
> > log
> > > server  and
> > >       the logs are kept  as follow
> > >
> > >           /var/log/syslog-ng/<client
> > > host>/extended.log
> > >
> > >
> > > We want  all the log of each client  to relay into a
> > > seperate server live.
> > > Means the  current log  file of each  host will go to
> > the
> > > new server
> > > simultaneously  as  it is going to the central log
> > server.
> > >
> > >
> > > We can configure a  second  log server  like the
> > existing
> > > one.  But our
> > > requirement  is,  that all the logs will be received
> > from
> > > the central log
> > > server not from the client  hosts.
> > >
> > > Any help is  really appreciated.
> > >
> > > Thanks
> > >
> > >
> > >
> > >
> > >
> >
> ______________________________________________________________
> ______________
> > > __
> > > Member info:
> > > https://lists.balabit.hu/mailman/listinfo/syslog-ng
> > > Documentation:
> > >
> > http://www.balabit.com/support/documentation/?product=syslog-ng
> > > FAQ: http://www.campin.net/syslog-ng/faq.html
> >
> >
> >
> >
> ______________________________________________________________
> ________________
> > Member info:
> > https://lists.balabit.hu/mailman/listinfo/syslog-ng
> > Documentation:
> > http://www.balabit.com/support/documentation/?product=syslog-ng
> > FAQ: http://www.campin.net/syslog-ng/faq.html
> >
> >
> >
> ______________________________________________________________
> ________________
> > Member info:
> > https://lists.balabit.hu/mailman/listinfo/syslog-ng
> > Documentation:
> > http://www.balabit.com/support/documentation/?product=syslog-ng
> > FAQ: http://www.campin.net/syslog-ng/faq.html
>
>
>
--------------------------------------------------------

NOTICE: If received in error, please destroy and notify sender. Sender does not intend to waive
confidentiality or privilege. Use of this email is prohibited when received in error.
______________________________________________________________________________
Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng
Documentation: http://www.balabit.com/support/documentation/?product=syslog-ng
FAQ: http://www.campin.net/syslog-ng/faq.html

Lavannya | 9 Dec 18:04 2008
Picon

Re: 答复: Need help to send logs to a different server

Thanks to both of you.

I have configured  our  existing log master  , following  both of your  advice  seperately.  But  the server  where I
am trying to forward the logs
is  not  listening the port  I am mentioning.  

I tested  as follows:

       1.   I took  a server where  syslog-ng  is not at all installe.
            checked,  but did not find  any log which is being forwarded
            by the central log master

       2..  Took one server  which  is  already  a client  , and 
            syslog-ng  is installed  already  as  it is a client server.
            In that server also  did not find any logs which  is being
            forwarded by the central log master.

In both the servers  where I tested,  iptables  is turned off. Moreover found, that  the central log  master  is
broken too.

Pl. guide me more where ,i am missing  for this configuration.

Thanks again

--- On Tue, 12/9/08, Geller, Sandor (IT) <Sandor.Geller <at> morganstanley.com> wrote:

> From: Geller, Sandor (IT) <Sandor.Geller <at> morganstanley.com>
> Subject: Re: [syslog-ng] 答复:  Need help to send logs to a different server
> To: "Syslog-ng users' and developers' mailing list" <syslog-ng <at> lists.balabit.hu>
> Date: Tuesday, December 9, 2008, 3:22 AM
> Hi,
> 
> The f_everthing filter matches on all logs so it is
> redundant,
> you could omit it (using filters is optional in the log
> sections).
> 
> To forward the logs to a second server the easiest would be
> to
> add the host to the everything destination like this:
> 
> destination everything {
>        
> file("/var/log/remotes/$HOST/$HOST-all-system.logs");
> };
>         tcp(1.2.3.4 port(5));
> };
> 
> Obviously replace the IP address and the port with valid
> values,
> and when the second server doesn't support tcp then you
> should
> use udp.
> 
> BTW you should add the log_prefix option to your kernel
> source
> to mimic syslogd's behaviour:
> 
>         file("/proc/kmsg"
> log_prefix("kernel: "));
> 
> hth,
> 
> Sandor
> 
> > -----Original Message-----
> > From: syslog-ng-bounces <at> lists.balabit.hu
> > [mailto:syslog-ng-bounces <at> lists.balabit.hu] On Behalf
> Of Lavannya
> > Sent: Monday, December 08, 2008 7:18 PM
> > To: Syslog-ng users' and developers' mailing
> list
> > Subject: Re: [syslog-ng] 答复: Need help to send
> logs to a
> > different server
> >
> > Hi Mark,
> >
> > Thanks for your reply.  I am getting error whatever
> > configuration you had said.  May be  I need to change
> our
> > existing configuration again.  Here is the central 
> log
> > server  configuration I am sending as attachment. Our
> central
> >  log server  is already configured  with 
> tcp(ip(0.0.0.0) ip
> > and when  I am adding the new  server  to collect the
> log it
> > is giving error.
> >
> >   - I want to add another  server (this is needed for
> some
> > application )
> >     to my central log server which  will
> >     get all the logs  from the central log  server.
> >
> > Pl. feel free to correct  the log file and send it to
> me.
> >
> > Thanks again
> >
> >
> >
> >
> >
> > --- On Mon, 12/8/08, Marc Andersen
> <man <at> inspektsecurity.com> wrote:
> >
> > > From: Marc Andersen
> <man <at> inspektsecurity.com>
> > > Subject: Re: [syslog-ng] 答复:  Need help to
> send logs to a
> > different server
> > > To: "Syslog-ng users' and
> developers' mailing list"
> > <syslog-ng <at> lists.balabit.hu>
> > > Date: Monday, December 8, 2008, 8:04 AM
> > > If the central syslog server is running syslog-ng
> you can
> > > just add another destination (live log server) to
> the
> > > already existing local files.
> > >
> > > log{
> > > source (udp/tcp incoming);
> > > destination(new live log server);
> > > };
> > >
> > > cheers
> > > /Marc
> > >
> > >
> > > On 07/12/08 16.03, "Lavannya"
> > > <swap_project <at> yahoo.com> wrote:
> > >
> > > Yes ,  from the client  we can ,  but I think if
> you read
> > > my mail properly, I clearly written that my
> requirement is
> > > NOT, to get the logs from the client.  I want  to
> set one
> > > server , which will get  all the information from
> the
> > > central log master. Yes , I know it can be done
> through
> > > ssh/rsync. But I wanted to know , if there is any
> option in
> > > syslog-ng .
> > >
> > > Thanks
> > >
> > >
> > >
> > > --- On Fri, 12/5/08, liuruihong
> > > <liuruihong <at> baidu.com> wrote:
> > >
> > > > From: liuruihong
> <liuruihong <at> baidu.com>
> > > > Subject: 答复: [syslog-ng] Need help to
> send logs to
> > > a different server
> > > > To: swap_project <at> yahoo.com,
> "'Syslog-ng
> > > users' and developers' mailing
> list'"
> > > <syslog-ng <at> lists.balabit.hu>
> > > > Date: Friday, December 5, 2008, 3:23 AM
> > > > in the client,you can define many remote log
> server
> > > > simultaneously.syslog
> > > > and syslog-ng all support this function.
> > > > You can find in the manual:)
> > > >
> > > >
> > > > 谢谢!
> > > >
> > > > 刘蕊红 |sys|6758
> > > >
> > > > -----邮件原件-----
> > > > 发件人:
> syslog-ng-bounces <at> lists.balabit.hu
> > > > [mailto:syslog-ng-bounces <at> lists.balabit.hu]
> 代表
> > > Swapna
> > > > 发送时间: 2008年12月5日 4:17
> > > > 收件人: syslog-ng <at> lists.balabit.hu
> > > > 主题: [syslog-ng] Need help to send logs
> to a
> > > different
> > > > server
> > > >
> > > > Hi,
> > > >
> > > >
> > > > We have syslog-ng configuration  as follows:
> > > >
> > > >    -  There are 50 clients  communicating to
> one log
> > > server
> > > >
> > > >    -  The  log server is kept in secured
> place where
> > > nobody
> > > > have access
> > > >
> > > >    -  All the logs  of 50 clients  are
> coming to the
> > > log
> > > > server  and
> > > >       the logs are kept  as follow
> > > >
> > > >           /var/log/syslog-ng/<client
> > > > host>/extended.log
> > > >
> > > >
> > > > We want  all the log of each client  to
> relay into a
> > > > seperate server live.
> > > > Means the  current log  file of each  host
> will go to
> > > the
> > > > new server
> > > > simultaneously  as  it is going to the
> central log
> > > server.
> > > >
> > > >
> > > > We can configure a  second  log server  like
> the
> > > existing
> > > > one.  But our
> > > > requirement  is,  that all the logs will be
> received
> > > from
> > > > the central log
> > > > server not from the client  hosts.
> > > >
> > > > Any help is  really appreciated.
> > > >
> > > > Thanks
> > > >
> > > >
> > > >
> > > >
> > > >
> > >
> >
> ______________________________________________________________
> > ______________
> > > > __
> > > > Member info:
> > > >
> https://lists.balabit.hu/mailman/listinfo/syslog-ng
> > > > Documentation:
> > > >
> > >
> http://www.balabit.com/support/documentation/?product=syslog-ng
> > > > FAQ:
> http://www.campin.net/syslog-ng/faq.html
> > >
> > >
> > >
> > >
> >
> ______________________________________________________________
> > ________________
> > > Member info:
> > >
> https://lists.balabit.hu/mailman/listinfo/syslog-ng
> > > Documentation:
> > >
> http://www.balabit.com/support/documentation/?product=syslog-ng
> > > FAQ: http://www.campin.net/syslog-ng/faq.html
> > >
> > >
> > >
> >
> ______________________________________________________________
> > ________________
> > > Member info:
> > >
> https://lists.balabit.hu/mailman/listinfo/syslog-ng
> > > Documentation:
> > >
> http://www.balabit.com/support/documentation/?product=syslog-ng
> > > FAQ: http://www.campin.net/syslog-ng/faq.html
> >
> >
> >
> --------------------------------------------------------
> 
> NOTICE: If received in error, please destroy and notify
> sender. Sender does not intend to waive confidentiality or
> privilege. Use of this email is prohibited when received in
> error.
> ______________________________________________________________________________
> Member info:
> https://lists.balabit.hu/mailman/listinfo/syslog-ng
> Documentation:
> http://www.balabit.com/support/documentation/?product=syslog-ng
> FAQ: http://www.campin.net/syslog-ng/faq.html

      
______________________________________________________________________________
Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng
Documentation: http://www.balabit.com/support/documentation/?product=syslog-ng
FAQ: http://www.campin.net/syslog-ng/faq.html


Gmane