LinuxQuestions.org
View the Most Wanted LQ Wiki articles.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices

Reply
 
Search this Thread
Old 10-25-2006, 09:33 AM   #1
Ransak
Member
 
Registered: Nov 2005
Posts: 35

Rep: Reputation: 15
Insert a string to Syslog?


Is it possible to prepend/append/insert a string to syslog? Or syslog-ng? I need to have a unique identifier in the syslog logs that I'm forwarding to a syslog-ng loghost server, but I can't seem to find out if it's possible to insert a string into syslog and/or syslog-ng.
 
Old 10-25-2006, 09:39 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,398

Rep: Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965
Well it depends what you're really after. syslog-ng can have templates in the config file where you can take the inbound syslog message and format the log into arbitrary formats, presumably inclduing strings of your own choice, but is this really what you're after? if you're after a way to identify certain clients into a networked syslog server then syslog-ng can easily be configured to do reverse DNS lookups etc... and insert these into the messages. Personally I use syslog to identify a source and write each log to a seperate file with the name of the client in it.
 
Old 10-25-2006, 09:59 AM   #3
Ransak
Member
 
Registered: Nov 2005
Posts: 35

Original Poster
Rep: Reputation: 15
I'm using a central Splunk server. I'm pulling auth.* from multiple servers in addition to several Windows servers (using the Snare client) and Cisco devices. I need to insert a unique string (in this case, 'nixlog') on all the *nix servers so syslog-ng applies the correct filter against them to be put into the FIFO I've created for *nix servers (which is then applied to the correct Splunk parser).

Some of the servers have syslog, others have syslog-ng. All could be upgraded to syslog-ng if there is no option for syslog.
 
Old 10-25-2006, 01:08 PM   #4
Ransak
Member
 
Registered: Nov 2005
Posts: 35

Original Poster
Rep: Reputation: 15
I did find this after some searching:

https://lists.balabit.hu/pipermail/s...ry/008385.html

It uses templates with syslog-ng. Has anyone else ever done something like this with syslog-ng? Anyone have an idea how to accomplish this with just syslog?

Last edited by Ransak; 10-25-2006 at 01:35 PM.
 
Old 10-26-2006, 03:51 AM   #5
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,398

Rep: Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965Reputation: 1965
if you're going syslog to syslog, and not able to use logging clients like "logger" then i would encourage you to deliberately use syslog-ng as a standard anyway. most distros have prepackaged syslog-ng binaries available and they are normally configured to be a 100% syslogd and ksyslog replacement, so there's no reconfiguraiton work to do unless you've already modified syslogd on the client box. an increasing number of distros are using syslog-ng by default now anyway...
 
  


Reply

Tags
syslog


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Rewrite rule with query string in the pattern string basahkuyup Linux - Newbie 2 10-17-2006 02:06 AM
LXer: Centralized Syslog Server Using syslog-NG LXer Syndicated Linux News 0 04-28-2006 06:21 PM
Script to insert string in first line of a file minil Programming 13 01-02-2006 11:56 PM
insert string with sed greg108 Programming 7 02-18-2005 01:11 PM
pppsetup : How to insert modem init string xgreen Slackware 1 03-07-2004 07:18 PM


All times are GMT -5. The time now is 07:59 PM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration