How do I forward named query logs without filling /var/log/messages
Hello,
My issue is slightly different from others that I've seen. There have been other questions about named filling up /var/log/messages and setting named.conf to log to a specific file rather than using syslog.
However, in my case, I have to filter my query logs through rsyslog so that they can be forwarded to Splunk, but I still don't want them filling up /var/log/messages
The way I had set this up is, in my named.conf, I specify:
channel query_log {
syslog local6;
severity info;
print-severity yes;
print-time yes;
print-category yes;
};
And in my rsyslog.conf:
local6.* /apps/named/var/log/query.log
local6.* @@<loggingserver>:<port>
These are the only references to local6 in rsyslog.conf. However, it appears that my query logs are also being replicated into /var/log/messages which is filling up my /var/log partition.
Is there maybe a different way to send query logs to my remote server?
Thanks!
|