88 lines
3.3 KiB
Plaintext
88 lines
3.3 KiB
Plaintext
@version: 3.4
|
|
# syslog-ng configuration file.
|
|
#
|
|
# This should behave pretty much like the original syslog on RedHat. But
|
|
# it could be configured a lot smarter.
|
|
#
|
|
# See syslog-ng(8) and syslog-ng.conf(5) for more information.
|
|
#
|
|
# 20000925 gb@sysfive.com
|
|
#
|
|
# Updated by Frank Crawford (<Frank.Crawford@ac3.com.au>) - 10 Aug 2002
|
|
# - for Red Hat 7.3
|
|
# - totally do away with klogd
|
|
# - add message "kernel:" as is done with klogd.
|
|
#
|
|
# Updated by Frank Crawford (<Frank.Crawford@ac3.com.au>) - 22 Aug 2002
|
|
# - use the log_prefix option as per Balazs Scheidler's email
|
|
#
|
|
# Updated by Jose Pedro Oliveira (<jpo at di.uminho.pt>) - 05 Apr 2003
|
|
# - corrected filters 'f_filter2' and 'f_filter6'
|
|
# these filters were only allowing messages of one specific
|
|
# priority level; they should be allowing messages from that
|
|
# priority and upper levels.
|
|
#
|
|
# Updated by Jose Pedro Oliveira (<jpo at di.uminho.pt>) - 25 Jan 2005
|
|
# - Don't sync the d_mail destination
|
|
#
|
|
# Updated by Jose Pedro Oliveira (<jpo at di.uminho.pt>) - 01 Feb 2005
|
|
# - /proc/kmsg is a file not a pipe.
|
|
# (https://lists.balabit.hu/pipermail/syslog-ng/2005-February/006963.html)
|
|
#
|
|
|
|
|
|
options {
|
|
flush_lines (0);
|
|
time_reopen (10);
|
|
chain_hostnames (off);
|
|
use_dns (no);
|
|
use_fqdn (no);
|
|
create_dirs (no);
|
|
keep_hostname (yes);
|
|
perm(0644);
|
|
stats_freq(86400);
|
|
};
|
|
|
|
source s_sys {
|
|
file ("/proc/kmsg" program_override("kernel: "));
|
|
unix-dgram ("/dev/log");
|
|
internal();
|
|
# udp(ip(0.0.0.0) port(514));
|
|
};
|
|
|
|
destination d_cons { file("/dev/console"); };
|
|
destination d_boot { file("/var/log/boot.log"); };
|
|
destination d_fwll { file("/var/log/firewall"); };
|
|
destination d_kern { file("/var/log/kernel"); };
|
|
destination d_ldap { file("/var/log/ldap.log"); };
|
|
destination d_mail { file("/var/log/maillog" flush_lines(10)); };
|
|
destination d_mesg { file("/var/log/messages"); };
|
|
destination d_auth { file("/var/log/secure"); };
|
|
destination d_spol { file("/var/log/spooler"); };
|
|
destination d_mlal { usertty("*"); };
|
|
|
|
filter f_filter1 { facility(kern); };
|
|
filter f_filter2 { level(info..emerg) and
|
|
not facility(mail,authpriv,cron); };
|
|
filter f_filter3 { facility(authpriv); };
|
|
filter f_filter4 { facility(mail); };
|
|
filter f_filter5 { level(emerg); };
|
|
filter f_filter6 { facility(uucp) or
|
|
(facility(news) and level(crit..emerg)); };
|
|
filter f_filter7 { facility(local7); };
|
|
filter f_fwll { facility(kern) and
|
|
(match(" DROPPED " value("MESSAGE")) or match(" ABORTED " value("MESSAGE"))
|
|
or match("UFW BLOCK" value("MESSAGE")) or match("Shorewall:" value("MESSAGE"))); };
|
|
filter f_ldap { program("slapd"); };
|
|
|
|
#log { source(s_sys); filter(f_filter1); destination(d_cons); };
|
|
log { source(s_sys); filter(f_fwll); destination(d_fwll); flags(final); };
|
|
log { source(s_sys); filter(f_filter1); destination(d_kern); };
|
|
log { source(s_sys); filter(f_ldap); destination(d_ldap); flags(final); };
|
|
log { source(s_sys); filter(f_filter3); destination(d_auth); };
|
|
log { source(s_sys); filter(f_filter4); destination(d_mail); };
|
|
log { source(s_sys); filter(f_filter5); destination(d_mlal); };
|
|
log { source(s_sys); filter(f_filter6); destination(d_spol); };
|
|
log { source(s_sys); filter(f_filter7); destination(d_boot); };
|
|
log { source(s_sys); filter(f_filter2); destination(d_mesg); };
|