Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Differences between different logger daemons
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Installing Gentoo
View previous topic :: View next topic  
Author Message
faets
n00b
n00b


Joined: 29 Jun 2002
Posts: 2
Location: land oz of.

PostPosted: Sat Jun 29, 2002 11:45 am    Post subject: Differences between different logger daemons Reply with quote

I was killing time while waiting for "emerge system" to finish on my iBook and decided to find out exactly what is the difference between the various system log daemons listed in the 1.2 install instructions.

I couldn't find any discussion in the forums, and I couldn't find any specific discussions using google. So I ended up just checking out the blurbs as posted by the various maintainers on Freshmeat.net. For future reference I'll post a quick rundown here...

sysklogd:
This is the stock standard logger daemon supplied with the majority of linux distributions. It does all the things you'd expect of a logger daemon. I'm sure it set the de facto standard and it just looks like it doesn't offer anything special.

syslog-ng:
Syslogd replacement for the "new generation". Among what seems to be its funkier features are regular expression based filtering and the ability to forward logs, over TCP connections, to a remote host.

metalog:
The install instructions mentions metalog is popular with "power users". Its features, like syslog-ng, included log forwarding and filtering but it claims it is easier to configure and is aimed at improving upon syskloogds performance.


The only logger I have had any experience with is sysklogd but based on the blurbs I went with metalog. I'd be interested in what others have to say about the pros/cons of the various loggers.
Back to top
View user's profile Send private message
SubZero
n00b
n00b


Joined: 09 Jun 2002
Posts: 17
Location: Brazil

PostPosted: Thu Jul 25, 2002 5:43 pm    Post subject: Reply with quote

I was just reading your post to decide with one is best.

I'm seeing that the logs generated by metalog has a strange value for the timestamp, so I can't run it with qmailanalog.

I will try syslog-ng and see if it is compatible with others log analyzers.
Back to top
View user's profile Send private message
legoleg
n00b
n00b


Joined: 05 Jul 2002
Posts: 14

PostPosted: Thu Jul 25, 2002 6:20 pm    Post subject: Reply with quote

There's a decent description of each in the Security Guide. Go here to see it. It starts right after code listing 6.... hope this helps.

Oleg
_________________
Where is my sig?
Back to top
View user's profile Send private message
Wilhelm
Tux's lil' helper
Tux's lil' helper


Joined: 27 May 2003
Posts: 149

PostPosted: Sat Jun 21, 2003 12:24 pm    Post subject: Reply with quote

I stepped over from metalog to sysklogd because metalog doesn't do syslog remote logging.

I believe sysklogd to be the only one but when metalog adds remote logging i'm back :)
Back to top
View user's profile Send private message
strolls
n00b
n00b


Joined: 17 Mar 2003
Posts: 18

PostPosted: Fri Jul 18, 2003 4:46 pm    Post subject: Reply with quote

Wilhelm wrote:
I stepped over from metalog to sysklogd because metalog doesn't do syslog remote logging... I believe sysklogd to be the only one...


syslog-ng also does remote logging. I want to use it because I believe it will allow me to filter network log information from my router & printer better.

The /etc/syslog-ng/syslog-ng.conf installed by Gentoo by default seems pretty basic, however. There appears to be a better one given in this forum posting.
Back to top
View user's profile Send private message
Wilhelm
Tux's lil' helper
Tux's lil' helper


Joined: 27 May 2003
Posts: 149

PostPosted: Fri Aug 01, 2003 2:59 pm    Post subject: Reply with quote

strolls wrote:
Wilhelm wrote:
I stepped over from metalog to sysklogd because metalog doesn't do syslog remote logging... I believe sysklogd to be the only one...


syslog-ng also does remote logging. I want to use it because I believe it will allow me to filter network log information from my router & printer better.

The /etc/syslog-ng/syslog-ng.conf installed by Gentoo by default seems pretty basic, however. There appears to be a better one given in this forum posting.


I stepped over to syslog-ng too. It wasn't easy seting up but now i have a logging server which logs everything.
Back to top
View user's profile Send private message
jthj
Apprentice
Apprentice


Joined: 04 Jun 2002
Posts: 176
Location: The Matrix Has Me....

PostPosted: Fri Feb 13, 2004 9:35 pm    Post subject: Reply with quote

Is there a good site with some documentation or tutorials on how the filtering works in syslog-ng?
_________________
01001010 01010100 01001000 01001010
Back to top
View user's profile Send private message
michaelb
l33t
l33t


Joined: 06 Jun 2002
Posts: 686
Location: Ann Arbor, MI

PostPosted: Fri Feb 13, 2004 9:51 pm    Post subject: Reply with quote

Many. A little googling will turn up more than you could ever read. You might want to start with this one.
_________________
Behold, The power of SEARCH!
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Installing Gentoo All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum