Gentoo Archives: gentoo-user

From: Dan Egli <dan@×××××××××××.site>
To: Dr Rainer Woitok <rainer.woitok@×××××.com>, gentoo-user@l.g.o
Subject: Re: [gentoo-user] syslog-ng misbehaving
Date: Thu, 08 Apr 2021 18:18:15
Message-Id: 27a79492-b3e3-4c68-ebbc-60c4ba90fbd9@newideatest.site
1 I swear Thunderbird is sending to the MTA when it should be saving on
2 the IMAP server. Ignore this one for the next one. IT is complete. This
3 one is not.
4
5 On 4/8/2021 12:13 PM, Dan Egli wrote:
6 > On 4/8/2021 9:59 AM, Dr Rainer Woitok wrote:
7 >> Dan,
8 >>
9 >> On Wednesday, 2021-04-07 12:05:10 -0600, you wrote:
10 >>
11 >>> I had posted the whole file. But I can do it again easy enough.
12 >>> ...
13 >>> filter samba { program("samba"); };
14 >>> filter ssh_messages { facility("AUTH") and level("INFO"); };
15 >>> filter syslog { not filter("ssh_messages") and not filter("samba"); };
16 >> Omit the double quotes in this last line. You're needing the NAMES of
17 >> the filters here.
18 >>
19 >
20 > I'm afraid that didn't work either.  I did as you said, and changed
21 > the syslog filter line to read: filter syslog { not filter(sshd) and
22 > not filter (samba); }; which would match the previous lines (see URL
23 > below). I still see sshd messages in /var/log/messages when I ssh into
24 > the machine.
25 >