LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 03-23-2022, 02:43 PM   #1
Nikosis
Member
 
Registered: Dec 2005
Location: In front of the monitor
Distribution: Slackware
Posts: 322

Rep: Reputation: 59
Ulogd nftables logging


Hi
Recently I started looking into nftables since it's going to be iptables successor. While doing so I came across some logging difficulties as maintaing separate log files for different services, and while syslog isn't really up for the task(unless I missed something) and nftables wiki suggested ulogd,so I decided to give it a try, but maybe there are better solutions like rsyslog or syslog-ng, what would you suggest?

So the first thing I noticed is that ulogd while it's marked as executable doesn't start at boot time. So the solution it's either rc.local or rc.M edit. But my question is, is there a conflict of interest between syslog and ulogd, since ulogd doesn't start at a boot time and when it starts I get this:
Code:
ulogd_inppkt_NFLOG.c:501 forcing unbind of existing log handler for protocol 2
ulogd_inppkt_NFLOG.c:501 forcing unbind of existing log handler for protocol 10
ulogd_inppkt_NFLOG.c:501 forcing unbind of existing log handler for protocol 7
which leads me to another question.
Can both of the work at the same time without interfering with eachother and if so what would the config file for ulog look like. Docs on this are really scares.
Also what is the significance of the file below, I'm guessing they're populated with the system boot, but what populates them and why only protocol 2,7,10 were unbinded from nf_log_* and what is the rest of them for?
Code:
 0 NONE (nfnetlink_log)
 1 NONE (nfnetlink_log)
 2 nfnetlink_log (nf_log_ipv4,nfnetlink_log)
 3 nf_log_arp (nf_log_arp,nfnetlink_log)
 4 NONE (nfnetlink_log)
 5 nf_log_netdev (nf_log_netdev,nfnetlink_log)
 6 NONE (nfnetlink_log)
 7 nfnetlink_log (nf_log_bridge,nfnetlink_log)
 8 NONE (nfnetlink_log)
 9 NONE (nfnetlink_log)
10 nfnetlink_log (nf_log_ipv6,nfnetlink_log)
11 NONE (nfnetlink_log)
12 NONE (nfnetlink_log)
Thx
 
  


Reply

Tags
logging, nftables, ulogd



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
IPV6 logging with Ulogd GAR-LINUX Linux - Networking 1 11-27-2012 03:58 AM
IPTables packet logging through ulogd priyadarshan Linux - Security 1 05-18-2009 02:18 PM
ulogd rpm for centos 5 DBabo Linux - Software 4 03-01-2008 05:16 PM
iptables ULOGd timestamping ? michaelsanford Linux - Networking 0 06-28-2005 02:55 PM
ULOGD + Mysql trouble kaN5300 Linux - Networking 4 12-09-2004 12:12 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 02:00 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration