I use these rules to log my iptables drop rules:
Code:
$IPT -N drop_input 2> /dev/null
$IPT -A drop_input -j LOG --log-prefix 'FW DROP INPUT:'
$IPT -A drop_input -j DROP
$IPT -N drop_output 2> /dev/null
$IPT -A drop_output -j LOG --log-prefix 'FW DROP OUTPUT:'
$IPT -A drop_output -j DROP
$IPT -N drop_forward 2> /dev/null
$IPT -A drop_forward -j LOG --log-prefix 'FW DROP FORWARD:'
$IPT -A drop_forward -j DROP
But now every dropped connection is logged in /var/log/syslog
I would like to log them in 3 separate files like:
/var/log/iptables/input
/var/log/iptables/output
/var/log/iptables/forward
How would I do this?