1
Tutorials and FAQs / Re: syslog-ng loghost
« on: April 12, 2022, 04:10:06 pm »
You can enable remote logging on syslog-ng like this:
create a file /usr/local/etc/syslog-ng.conf.d/remote.conf with this:
# Create the directory
mkdir /var/log/syslog-ng
Stop syslog-ng
pkill -f /usr/local/sbin/syslog-ng
Start syslog-ng
/usr/local/sbin/syslog-ng -f /usr/local/etc/syslog-ng.conf -p /var/run/syslog-ng.pid
If you have a malicious client it can hammer your drive, and too much activity will bog you down.
create a file /usr/local/etc/syslog-ng.conf.d/remote.conf with this:
Code: [Select]
source s_network {
network(
ip("192.168.1.1")
transport("udp")
);
};
destination d_syslog {
file("/var/log/syslog-ng/messages_${HOST}"); };
log { source(s_network); destination(d_syslog); };
# Create the directory
mkdir /var/log/syslog-ng
Stop syslog-ng
pkill -f /usr/local/sbin/syslog-ng
Start syslog-ng
/usr/local/sbin/syslog-ng -f /usr/local/etc/syslog-ng.conf -p /var/run/syslog-ng.pid
If you have a malicious client it can hammer your drive, and too much activity will bog you down.