OPNsense Forum

Archive => 20.1 Legacy Series => Topic started by: nivek1612 on January 27, 2020, 02:27:02 PM

Title: Remote Syslog Settings - 20.1.RC
Post by: nivek1612 on January 27, 2020, 02:27:02 PM
Can't find anything in the 20.1 release notes but GUI in 19.7 at

System: Settings: Logging had a section for remote syslog

at 20.1.RC its missing and only Local Logging options exist

Did I miss something ?



Title: Re: Remote Syslog Settings - 20.1.RC
Post by: franco on January 27, 2020, 02:47:00 PM
From the upcoming 20.1 release notes:

To prevent stale configuration files for remote syslog we advise to setup the new targets first and disable the old ones under System: Settings: Logging

https://docs.opnsense.org/manual/settingsmenu.html#logging-targets


Cheers,
Franco
Title: Re: Remote Syslog Settings - 20.1.RC
Post by: nivek1612 on January 27, 2020, 03:05:11 PM
Yes I missed that :-(

Mine wasn't set up anyway, so nothing to delete but what I had missed in the docs was this

"The remote logging feature will likely be removed in OPNsense 20.1, since the new Logging / targets offers more flexibility and has overlapping functionality. We advise to switch as soon as possible."

One final question now I've seen this I would have assumed the "syslog-ng" service would also be deleted (mine is still active) or is that a 20.1.1 activity/cleanup





Title: Re: Remote Syslog Settings - 20.1.RC
Post by: franco on January 27, 2020, 03:12:21 PM
Syslog-ng is the main syslogger. The older "syslogd" may be removed at some later point in time depending on how we go forward dealing with circular logging support.


Cheers,
Franco
Title: Re: Remote Syslog Settings - 20.1.RC
Post by: nivek1612 on January 27, 2020, 03:14:02 PM
thank you all clear now

20.1.RC1 is surviving all the load testing and reboots etc that I'm throwing at it so seems very good so far
Title: Re: Remote Syslog Settings - 20.1.RC
Post by: franco on January 27, 2020, 03:25:08 PM
glad to hear :)
Title: Re: Remote Syslog Settings - 20.1.RC
Post by: guest23316 on February 02, 2020, 03:24:28 PM
The updated remote logging via System>Settings>Logging/Targets is not passing firewall logs. 

Enabled - checked
Transport - UDP(4)
Application - all
Levels - all
Facilities - all
Hostname - set
Port - set

The host is receiving logs confirmed with tcpdump and a alternate moloch capture of traffic.  However, I no longer receive firewall logs since updating.  I've set application, levels and facilities to all as I debug and troubleshoot.  Any clarity or assistance would be greatly appreciated.


UPDATE///Disregard logging was disabled - everything is working now