Gentoo Logo
Gentoo Spaceship




Note: Due to technical difficulties, the Archives are currently not up to date. GMANE provides an alternative service for most mailing lists.
c.f. bug 424647
List Archive: gentoo-security
Navigation:
Lists: gentoo-security: < Prev By Thread Next > < Prev By Date Next >
Headers:
To: gentoo-security@g.o
From: Andreas Herrmann <sma@...>
Subject: Re: How to make iptables log to a separate log file?
Date: Sun, 27 Nov 2005 18:14:55 +0000
You can use following entrys in your syslog-ng.conf to log firewall messages 
to a seperate file than the normal kernel output.

# source kernsrc { file("/proc/kmsg"); };
# destination kern { file("/var/log/kern.log"); };
# destination firewall { file("/var/log/firewall.log"); };
# filter f_firewall { match("firewall"); };
# filter f_kern { facility(kern) and not filter(f_firewall);};
# log { source(kernsrc); filter(f_kern); destination(kern); };
# log { source(kernsrc); filter(f_firewall); destination(firewall); };


On Sunday 27 November 2005 15:46, Lasse Birnbaum Jensen wrote:
> Try using ULOG with the ULOGD daemon
>
> > I have installed iptables yesterday and currently using a basic script
> > from web to enable firewall. The script logs the dropped packets using
> > following entries
> >
> > /sbin/iptables -A INPUT -j LOG --log-prefix "FIREWALL:INPUT "
> > /sbin/iptables -I INPUT 1 -p tcp -m state --state INVALID -j LOG
> > --log-prefix "FIREWALL:INVALID "
> >
> > iptables seem to be working fine but the problem is that it is logging
> > everything in /var/log/messages but I want it to log it some other file.
> > May be /var/log/iptables. I have googled and found that syslog-ng can do
> > it and some entries in /etc/syslog-ng/syslog-ng.conf should work but I am
> > not sure how to do it. "man syslog-ng.conf" is not making much sense for
> > me either (newbie).
> >
> > Can some one please give me any links where I can read about how to
> > easily configure syslog-ng.conf and achieve what I desire. If you could
> > give exact entries then I would be more than greatful.
> >
> > TIA
> > Regards,
> > Abhay Kedia
>
> --
> Venlig hilsen / Best regards
> Lasse Birnbaum Jensen

-- 
Fachschaft Mathematik/Physik
Andreas Herrmann
University of Bayreuth
95440 Bayreuth
Germany

email   sma@...
www     http://hacktor.fs.uni-bayreuth.de/~sma/
private +44-787-0115648
-- 
gentoo-security@g.o mailing list


Replies:
Re: How to make iptables log to a separate log file?
-- aa6qn
Re: How to make iptables log to a separate log file?
-- MaxieZ
References:
How to make iptables log to a separate log file?
-- Abhay Kedia
Re: How to make iptables log to a separate log file?
-- Lasse Birnbaum Jensen
Navigation:
Lists: gentoo-security: < Prev By Thread Next > < Prev By Date Next >
Previous by thread:
Re: How to make iptables log to a separate log file?
Next by thread:
Re: How to make iptables log to a separate log file?
Previous by date:
Re: How to make iptables log to a separate log file?
Next by date:
Re: How to make iptables log to a separate log file?


Updated Jun 17, 2009

Summary: Archive of the gentoo-security mailing list.

Donate to support our development efforts.

Copyright 2001-2013 Gentoo Foundation, Inc. Questions, Comments? Contact us.