Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
sysklogd dumps *all* syslog messages to /var/log/messages
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
ryouga42
n00b
n00b


Joined: 21 Oct 2004
Posts: 19

PostPosted: Tue Oct 26, 2004 7:35 am    Post subject: sysklogd dumps *all* syslog messages to /var/log/messages Reply with quote

I'm using sysklogd after deciding that it was the easiest to set up for network logging. (If someone wants to suggest something like syslog-ng, I'm all ears, I'd just like help configuring such.

Basically, the entire network infrastructure is set up to syslog to this server. Quite a bit of traffic. I'd like to keep the behavior that sends all syslog messages to /var/log/syslog - I've trained my shop on how to use this through Webmin (so much better than Remote Desktop. Ugh) but I'd like to keep the messages from remote systems separate from the messages generated by the local system.

Is this possible to do with sysklogd, do I need to switch to syslog-ng or metalog or such, and how do I configure it/them to do this?

Thanks. :)
Back to top
View user's profile Send private message
hecatomb
Guru
Guru


Joined: 02 Sep 2004
Posts: 525

PostPosted: Tue Oct 26, 2004 12:53 pm    Post subject: Reply with quote

I've read some manuals about syslog now but can't find anything about separating the logs according to hosts. May be I'm to dumb? ;-)
But syslog-ng can!! Just one example: http://www.campin.net/newlogcheck.html
google can give you much more! :-)
Back to top
View user's profile Send private message
ryouga42
n00b
n00b


Joined: 21 Oct 2004
Posts: 19

PostPosted: Tue Oct 26, 2004 1:07 pm    Post subject: Reply with quote

Yeah, I broke down and installed syslog-ng after a bit of running in circles. I didn't really need it broken down by host but it's kind of an added perk.

Except now I can't view it with Webmin anymore - not natively anyway. I have it set up as a dirty hack to use the old syslog.conf and view /var/log/cisco/*.log - but there has to be a better way to do it.

I couldn't find a syslog-ng module for Webmin. Is there some other clean way to view logs over a web interface?
Back to top
View user's profile Send private message
hecatomb
Guru
Guru


Joined: 02 Sep 2004
Posts: 525

PostPosted: Tue Oct 26, 2004 1:19 pm    Post subject: Reply with quote

Yes, there exists a really nice way to manage the syslogs using a webinterface.
Redirect all syslog messages into a mysql database: http://vermeer.org/display_doc.php?doc_id=1
And view it using a php interface: http://vermeer.org/display_project.php?project=php-syslog-ng
Back to top
View user's profile Send private message
ryouga42
n00b
n00b


Joined: 21 Oct 2004
Posts: 19

PostPosted: Tue Oct 26, 2004 1:32 pm    Post subject: Reply with quote

After reading the first website you gave me, I was considering the merits of logging to an SQL server.

But I really like this. Thanks a lot!
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum