Logging ssh messages in a separate file using syslog-ng
Hi all,
I am facing a problem while trying to log SSH messages in a separate file, say, /var/log/ssh_logs. I have tried modifying the syslog-ng.conf file as follows:
filter f_ssh { facility(auth, authpriv) and match("sshd\[[0-9]+\]:"); };
destination d_ssh { file ("/var/logs/sshd_logs"); };
log {
source(s_local);
source(s_external);
filter(f_ssh);
destination(d_ssh);
};
But still I am not able to get the ssh logs in the new file. They continue to go to /var/log/auth.
Hope somebody can help me out as it is a not urgent.
Thanks in advance.
|