LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Red Hat
User Name
Password
Red Hat This forum is for the discussion of Red Hat Linux.

Notices


Reply
  Search this Thread
Old 09-02-2014, 03:23 PM   #1
AWSmith
Member
 
Registered: Jun 2012
Posts: 32

Rep: Reputation: Disabled
Syslog-ng and RHEL 7?


I've checked at balabit.com and their site indicates that its supported up to RHEL 6. I've got a shiny new RHEL7 server and I don't want to go back to 6 but it looks like its going to be necessary.

I've configured it and it loads, but it doesn't actually write anything to disk. running in debug mode in the foreground it acts as if its not receiving any input at all.

SELINUX disabled.

Not asking for help to get it configured but has anyone been able to do this?
 
Old 09-02-2014, 05:36 PM   #2
AlucardZero
Senior Member
 
Registered: May 2006
Location: USA
Distribution: Debian
Posts: 4,824

Rep: Reputation: 615Reputation: 615Reputation: 615Reputation: 615Reputation: 615Reputation: 615
What syslog daemon does RHEL 7 come with? Can you use that? Are you going to post your config?

Last edited by AlucardZero; 09-02-2014 at 05:37 PM.
 
1 members found this post helpful.
Old 09-02-2014, 05:43 PM   #3
Smokey_justme
Member
 
Registered: Oct 2009
Distribution: Slackware
Posts: 534

Rep: Reputation: 203Reputation: 203Reputation: 203
Doesn't RHEL 7 come with systemd and, thus, journald... I think you need to set journald to forward things somehow... but I might be wrong...

LE: Maybe take a look here and adjust to RHEL... https://wiki.archlinux.org/index.php/syslog-ng

Last edited by Smokey_justme; 09-02-2014 at 05:46 PM.
 
1 members found this post helpful.
Old 09-03-2014, 01:45 AM   #4
czanik
LQ Newbie
 
Registered: Dec 2010
Distribution: openSUSE Fedora FreeBSD
Posts: 9

Rep: Reputation: 2
If you use syslog-ng PE, then you have to wait for about a month until official support for RHEL 7 arrives.

If you use syslog-ng OSE, version 3.5.6 is available in the EPEL repository: https://fedoraproject.org/wiki/EPEL (obviously, without the PE features).
 
1 members found this post helpful.
Old 09-03-2014, 07:54 AM   #5
AWSmith
Member
 
Registered: Jun 2012
Posts: 32

Original Poster
Rep: Reputation: Disabled
Many thanks to my sysadmin bretheren out there. I hope your day is filled with uptime and lots of Community Coffee (yes, a shameless plug, no I don't work for them...).


Ok, so I'm going to give it one last go with RHEL 7. I really wanted to compile and use it that way. i'm going To try out the link provided for Fedora.

I'll post a config once I finish.
 
Old 09-03-2014, 03:51 PM   #6
AWSmith
Member
 
Registered: Jun 2012
Posts: 32

Original Poster
Rep: Reputation: Disabled
Solved.

And I have to give some credit to everyone on the thread because they led me to different research paths to the answer.

The fix:

1. Download the latest (I used today's latest stable) version of syslog-ng.
2. Download the latest event program also from balabit.com.
3. Extract the event program, ./configure; make; make install - it worked well with a default program.
4. export PKG_CONFIG_PATH=/usr/local/lib/pkgconfig (this presumes you have run ./configure with defaults on RHEL7).
5. Extract the syslog-ng program.
********* --- VIP --->6. ./configure --enable-linux-caps;make;make install
7. syslog-ng.conf: configure this with your stuff. Use the udp() driver for selecting network sourced data.
8. Turn off or configure the firewall which is on by default.
9. ? turn off SE Linux (I typically do this anyway) or configure it to allow the program.

Last edited by AWSmith; 09-03-2014 at 03:55 PM.
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Setting up Central Syslog Server Using RHEL 5.8 and rsyslog bkendall Linux - Server 3 07-12-2012 05:10 PM
RHEL syslog vs audit log idlehands Linux - Security 1 06-24-2010 05:44 PM
I need help getting syslog to log remotely, this is just the regular syslog. abefroman Linux - Software 2 06-05-2008 11:36 AM
RHEL and syslog-ng sidra Linux - Distributions 2 08-13-2006 01:32 PM
LXer: Centralized Syslog Server Using syslog-NG LXer Syndicated Linux News 0 04-28-2006 06:21 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Red Hat

All times are GMT -5. The time now is 01:23 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration