LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 09-09-2010, 09:46 AM   #1
marvin00001
Member
 
Registered: Apr 2005
Posts: 59

Rep: Reputation: 15
Shorewall - Logwatch


Hello


Can anyone help me with a Howto or some pointers on how to get logwatch working with shorewall logs. I tried fwlogwatch but could not get that working.

Cheers
 
Old 09-09-2010, 02:07 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by marvin00001 View Post
I tried fwlogwatch but could not get that working.
You haven't post on LQ about that. What went wrong?


Quote:
Originally Posted by marvin00001 View Post
how to get logwatch working with shorewall logs.
Shorewall is nothing more than a firewall management tool. By default firewall logging is done by the the in-kernel part of the firewall on Linux (called the Netfilter framework) and not Shorewall (using ULOG). Netfilter sends messages to syslogd. In /etc/syslog.conf is defined where those logs go. However Logwatch supports ulogd as well. Logwatch reporting is done by enabling the "iptables" service, files Logwatch reads to gather firewall logging are defined in (/usr/share/)logwatch/default.conf/services/iptables.conf and the actual parsing script is /usr/share/logwatch/scripts/services/iptables. To troubleshoot why something is not working you could make Logwatch process things more verbosely using the "--debug" switch. Also review what services you enabled in your logwatch.conf. If needed you can post contents (preferably in BB code tags) using something like 'grep -v ^# logwatch.conf|grep .' to weed out comments.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Better logwatch x_terminat_or_3 Linux - Server 4 11-24-2009 12:02 AM
I want to disable logwatch on our RHEL servers to stop the logwatch mail svik Linux - Enterprise 10 08-27-2009 02:51 PM
Does logwatch run automatically? How can I reset logwatch? abefroman Linux - Software 4 06-17-2009 02:17 AM
shorewall config question with /etc/shorewall/rules peter72 Linux - Networking 3 01-01-2007 09:33 PM
Logwatch?? Palula Linux - Newbie 2 08-02-2005 08:14 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 07:00 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration