From owner-freebsd-questions@FreeBSD.ORG Wed Sep 24 13:04:43 2008 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id CFABC106566B for ; Wed, 24 Sep 2008 13:04:43 +0000 (UTC) (envelope-from laurence@istraresearch.com) Received: from nf-out-0910.google.com (nf-out-0910.google.com [64.233.182.187]) by mx1.freebsd.org (Postfix) with ESMTP id 69E788FC13 for ; Wed, 24 Sep 2008 13:04:43 +0000 (UTC) (envelope-from laurence@istraresearch.com) Received: by nf-out-0910.google.com with SMTP id h3so963362nfh.33 for ; Wed, 24 Sep 2008 06:04:42 -0700 (PDT) Received: by 10.210.123.2 with SMTP id v2mr5389454ebc.186.1222261481864; Wed, 24 Sep 2008 06:04:41 -0700 (PDT) Received: from ?172.16.16.55? ([80.179.200.36]) by mx.google.com with ESMTPS id j8sm125626gvb.1.2008.09.24.06.04.38 (version=TLSv1/SSLv3 cipher=RC4-MD5); Wed, 24 Sep 2008 06:04:40 -0700 (PDT) Message-ID: <48DA3AE7.4030206@istraresearch.com> Date: Wed, 24 Sep 2008 16:04:39 +0300 From: Laurence Mayer User-Agent: Thunderbird 2.0.0.14 (X11/20080505) MIME-Version: 1.0 To: Steve Bertrand References: <48DA2333.3070007@istraresearch.com> <48DA375A.9020804@ibctech.ca> In-Reply-To: <48DA375A.9020804@ibctech.ca> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Cc: freebsd-questions@freebsd.org Subject: Re: Syslogd - Different Files X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 24 Sep 2008 13:04:43 -0000 Ok so you dont use `+host' etc as per the man pages. Can you please send the relevant parts of syslog.conf on a remote server on lanx.domain.com. Do you mean remote server syslog.config: local6.* @208.70.104.202 Steve Bertrand wrote: > Laurence Mayer wrote: >> Hi, >> >> Over the last couple of days I have been trying to get syslogd to log >> messages received from remote hosts to different files. >> >> I have read the man pages: >> >> >> >> >> However it is very confusing what exactly to add to the syslog.conf >> file. I have tried numerous variations but still no success. >> >> Could someone please tell me or >> send an example of their syslog.conf file showing how this is done. > > Granted that there is likely more than one way to do it, heres how I do > it (in the servers syslogd.conf): > > local6.* /var/log/lanx.log > local7.* /var/log/fortigate.log > mail.debug /var/log/barracuda.log > > ...each log file represents a different remote host delivering the log > data. So, on lanx.domain.com, I point the syslog service to the IP of > the server, and tell it to use local6 as the facility. > > I then start syslogd on the server as such: > > /usr/sbin/syslogd -a 208.70.104.202/32:514 -a 208.70.104.205/32:514 \ > -a 208.70.104.1/32:514 -f /etc/syslogd.conf > > Steve