Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Syslog-NG or other? Logging from a firewall
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
cuban
Guru
Guru


Joined: 23 Aug 2003
Posts: 448
Location: Houston, TX

PostPosted: Fri Aug 06, 2004 3:05 pm    Post subject: Syslog-NG or other? Logging from a firewall Reply with quote

Hey all,

I'd like to have my PIX firewall log to my gentoo box. I'm currently running SYSLOG-NG and the PIX can log to any facility level. How can I configure syslog-ng to accept these log entries, and place them into /var/log/firewall?

I've tried looking around and all I can find are docs for whatever syslog redhat uses.

TIA,
Daniel
_________________
Tell your ISP to support SPF/SASL AUTH (http://spf.pobox.com) today!
Back to top
View user's profile Send private message
kashani
Advocate
Advocate


Joined: 02 Sep 2002
Posts: 2032
Location: San Francisco

PostPosted: Fri Aug 06, 2004 4:17 pm    Post subject: Reply with quote

Check out this thread. There's a config for syslog-ng halfway down. No need for facilities with syslog-ng as it's smarter than the old syslog.

https://forums.gentoo.org/viewtopic.php?t=37887&

kashani
_________________
Will personally fix your server in exchange for motorcycle related shop tools in good shape.
Back to top
View user's profile Send private message
cuban
Guru
Guru


Joined: 23 Aug 2003
Posts: 448
Location: Houston, TX

PostPosted: Mon Aug 09, 2004 12:33 pm    Post subject: Reply with quote

Interesting. So I just tell the PIX to log to any facility and syslog-ng figures it out?
_________________
Tell your ISP to support SPF/SASL AUTH (http://spf.pobox.com) today!
Back to top
View user's profile Send private message
kashani
Advocate
Advocate


Joined: 02 Sep 2002
Posts: 2032
Location: San Francisco

PostPosted: Mon Aug 09, 2004 2:12 pm    Post subject: Reply with quote

The point of facilities was that mutiple devices could log to the same server and you could filter things based on which facility they came in. All routers went to facility 2, switch to facility 3, and so on. In this case you can have syslog-ng do a reverse lookup on any device that logs to it and create $host.log on the fly. Much simpler and cleaner IMHO.

I don't actually have a Pix at the moment, but the routers and switches log directly to the IP with no facility setting.
_________________
Will personally fix your server in exchange for motorcycle related shop tools in good shape.
Back to top
View user's profile Send private message
cuban
Guru
Guru


Joined: 23 Aug 2003
Posts: 448
Location: Houston, TX

PostPosted: Mon Aug 09, 2004 2:55 pm    Post subject: Reply with quote

Ah, okay. Sweet! Thanks.
_________________
Tell your ISP to support SPF/SASL AUTH (http://spf.pobox.com) today!
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum