LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 12-29-2010, 02:55 PM   #1
j8177e5
LQ Newbie
 
Registered: Dec 2010
Posts: 3

Rep: Reputation: 0
CentOS Syslog Server Help


Not sure which forum this should be posted in so I'm just creating it in General.

I'm trying to setup a central syslog server on a CentOS 5.4 machine. I'm going to use it to store syslogs from a Cisco firewall. I'm still fairly new to linux and I can't get the logs to come through.

I'll post what change's/ addition I've made to config files, but not the entire config. Please let me know if you need more info to give me a hand. Here's what I've done so far:

- /etc/syslog.conf

# Log firewall messages
local4.* /var/log/firewall

-rw------- 1 root root 0 Dec 21 01:00 firewall

- /etc/sysconfig/syslog

SYSLOGD_OPTIONS="-m 0 -r -x"

- /etc/services

syslog 514/udp

- iptables -L
ACCEPT udp -- 192.168.20.8 192.168.21.177 udp dpt:syslog

- ps -ef | grep syslog

root 3372 1 0 11:49 ? 00:00:00 syslogd -m 0 -r -x


I've been searching on Google for ideas, but no luck. I can't figure out why nothing is getting logged to /var/log/firewall. I've checked the logging settings on the firewall and everything looks fine.
 
Old 12-29-2010, 03:57 PM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
Those thund seem ok, but syslogd is pretty unhelpful for debugging things like this. Personally I would use tcpdump or wireshark to see if the traffic is hitting the machine in the first place. Being unidirectional udp though it won't really shed so much light on what iptables thinks about it compared to tcp.

Also you might wish to use a more user friendly syslig service, like syslog-ng which has a much nicer config and better debugging options.
 
Old 12-29-2010, 03:58 PM   #3
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
Oh, and run 'netstat -plnu. To see if the service is indeed listening nicely on 514
 
Old 06-03-2011, 04:42 AM   #4
lola1987
LQ Newbie
 
Registered: Jun 2011
Posts: 29

Rep: Reputation: Disabled
Reply:installation syslog-ng server in centos

hi i'm trying to install the syslog-ng.3.2.4 in centos 5.6 but it doesn't work ,the syslog-ng can't start ,i would like to know if there if it's a problem of syslog-ng version ?there is a version compatible whit centos 5.6 or not?and where are u download your package?
 
Old 06-03-2011, 05:15 AM   #5
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
please don't hijack other threads. This thread in't even about syslog-ng.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to set up syslog server on Fedora 10 Linux server ? gutiojj Linux - Server 1 03-10-2010 03:02 AM
syslog-ng confgiuration on centOS prasadtvs2003 Linux - Newbie 4 06-15-2009 03:07 AM
LXer: CentOS Directory Server On CentOS 5.2 LXer Syndicated Linux News 0 08-06-2008 09:20 PM
LXer: Centralized Syslog Server Using syslog-NG LXer Syndicated Linux News 0 04-28-2006 06:21 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 12:37 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration