LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-10-2016, 03:34 AM   #1
ftm66711
LQ Newbie
 
Registered: Oct 2016
Posts: 1

Rep: Reputation: Disabled
syslog RAW message does not contain IP or Hostame


I am using a remote log server to collect logs from remote hosts.
on some of my remote hosts I've installed syslog and on the others rsyslog.
the issue is here that on the hosts which are configured by classic syslog, raw message logs do not contain neither ip address nor hostname. it is sth as below :


Facility auth (4), Severity critical (2)
Msg: Oct 10 11:06:06 su: [ID 810491 auth.crit] 'su root' failed for app on /dev/pts/2


However my raw messages from servers configured by rsyslog are receiving such as below :

Facility authpriv (10), Severity notice (5)
Msg: Oct 10 11:14:05 mnp su: pam_unix(su-l:auth): authentication failure; logname=app uid=32005 euid=0 tty=pts/0 ruser=app rhost= user=root

"mnp" is hostname of my remote host.

I am wondering where is the problem??? also it's not possible to change classic syslog to rsyslog in my remote hosts. I need an identifier such as hostname or at least IP address in my syslog messages.

Thanks in Advance

Last edited by ftm66711; 10-10-2016 at 03:35 AM.
 
Old 10-13-2016, 05:17 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by ftm66711 View Post
I am wondering where is the problem???
If there is a problem (I didn't see any relevant configuration files nor debug output) then it's probably buried in the Related RFCs and working groups part of the Rsyslogd Wiki page... (as in enhancement of RFC 3164).


Quote:
Originally Posted by ftm66711 View Post
also it's not possible to change classic syslog to rsyslog in my remote hosts.
Well then you're basically stuck.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
kdebug PPPd option is not logging into /etc/syslog to log the kernel level raw PPP rakesh_krishnan Linux - Newbie 1 03-05-2015 02:08 AM
[SOLVED] syslog message redirect Gholi Linux - Server 1 08-25-2011 03:45 PM
Syslog-ng: filtering out a message ReefShark Linux - Server 0 07-30-2008 06:11 AM
Extract body message from raw e-mail rigel_kent Programming 2 06-03-2006 06:07 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:45 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration