LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 05-23-2007, 02:23 PM   #1
koncept
LQ Newbie
 
Registered: Sep 2005
Posts: 13

Rep: Reputation: 0
syslog-ng & subnet filters


Hello,

I am trying to setup syslog-ng to filter based upon the source subnets this way i can use php-syslog and give different groups different lists. (the server can handle it w/o a problem) but i cannot get the netmask filter to work and i do not want to do individual host entries. i have tried google and the results i found didn't help i was either only getting one of the hosts or none.

thanks in advanced


edit:
feel free to close this, they were working. the order that i put them in made it appear as though they were not

Last edited by koncept; 05-23-2007 at 02:50 PM.
 
Old 05-23-2007, 02:56 PM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
hmm, never knew that filter existed... interesting.
 
Old 05-23-2007, 03:25 PM   #3
koncept
LQ Newbie
 
Registered: Sep 2005
Posts: 13

Original Poster
Rep: Reputation: 0
yups, i just started playing with syslog servers after an incident last week. i knew syslog-ng was the right one for us but had never used it. it has only been used on our core and firewalls. we now needed all the information logged and since we have 1200 access points on campus and about another 300 switches/routers it only made sense to split it up

one of the filter i am using looks like this, if you want to see the rest of the config i would be glad to post it.

Code:
filter f_WiFi       { netmask("10.100.51.0/255.255.254.0") or netmask("10.100.53.0/255.255.254.0")
                        or netmask("10.100.55.0/255.255.254.0") or netmask("10.100.57.0/255.255.254.0"); };
 
Old 05-23-2007, 03:27 PM   #4
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
if it's at all interesting to you, i'm currently implementing syslog-ng in conjunction with splunk indexing the stored logs. together they make a real neat combination.
 
Old 05-23-2007, 03:31 PM   #5
koncept
LQ Newbie
 
Registered: Sep 2005
Posts: 13

Original Poster
Rep: Reputation: 0
splunk sounds alot like php-syslog-ng (http://www.phpwizardry.com/php-syslog-ng.php) but looks far more advanced *judging by the site*

did you look at php-syslog? or just go straight to splunk? is it worth switching...there is a demo on the other site for comparison if you want...
 
Old 05-23-2007, 03:38 PM   #6
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
well this is for 1st line support and all sorts of low skilled IT staff, so whilst php-... is fine for basic stuff, within enterprise it's a long long way off... main problem i had is that splunk isn't naturally a syslog server, "just" a generic log message indexer / searching tool so for the syslog side, still needed somethign under the hood to interpret syslog itself.

the licensed versions of splunk are pretty awesome... the 3.0 beta won't load on any box i've tried it on this morning though!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
logrotate, syslog-ng & cron hattori.hanzo Linux - Newbie 1 11-08-2006 12:08 PM
syslog-ng, network logging & hostnames humbletech99 Linux - Security 1 05-06-2006 10:32 AM
syslog-ng & Pix Problems mpapet Debian 1 01-27-2006 03:30 PM
scanning e-maill &setting up filters David W Linux - Security 1 01-23-2006 04:15 PM
/var/adm/messages & syslog Khalid Linux - General 0 11-08-2001 05:40 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 04:09 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration