[nzlug] Syslog to remote log server

yuri yuridg at gmail.com
Mon Jan 1 14:50:18 NZDT 2007


On 01/01/07, Clark Mills wrote:
> For the logging server:
>
>  From man syslogd:
>         -r     This  option  will  enable  the facility to receive
>                message from the network using an  internet  domain
>                socket  with  the syslog service (see services(5)).
>                The default is to not receive any messages from the
>                network.
>
> For RedHat:
>         vi /etc/sysconfig/syslog
>                 SYSLOGD_OPTIONS="-m 0 -r"
>         service syslog restart
>
> or edit your relevant rc file.
>
> Poke a hole in your firewall as required.

What's a good distro for a dedicated syslog server - one that perhaps
does some ongoing heuristic analysis on the logs?

Yuri




More information about the NZLUG mailing list