From owner-freebsd-questions@FreeBSD.ORG Thu Apr 24 06:02:03 2003 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 3B10137B401 for ; Thu, 24 Apr 2003 06:02:03 -0700 (PDT) Received: from mail.munk.nu (213-152-51-194.dsl.eclipse.net.uk [213.152.51.194]) by mx1.FreeBSD.org (Postfix) with ESMTP id 4479D43F3F for ; Thu, 24 Apr 2003 06:02:02 -0700 (PDT) (envelope-from munk@mail.munk.nu) Received: from munk by mail.munk.nu with local (Exim 4.14) id 198gMc-0005II-IY for questions@FreeBSD.ORG; Thu, 24 Apr 2003 14:02:10 +0100 Date: Thu, 24 Apr 2003 14:02:10 +0100 From: Jez Hancock To: questions@FreeBSD.ORG Message-ID: <20030424130210.GC20162@users.munk.nu> Mail-Followup-To: questions@FreeBSD.ORG References: <20030424071545.GA45006@marvin.penguinpowered.org.uk> <8blfavg8puflk0bu7osgrnr8u831kbl92m@4ax.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <8blfavg8puflk0bu7osgrnr8u831kbl92m@4ax.com> User-Agent: Mutt/1.4.1i Sender: User Munk Subject: Re: syslog logging question X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 24 Apr 2003 13:02:03 -0000 On Thu, Apr 24, 2003 at 01:29:56PM +0100, John Murphy wrote: > Wayne Pascoe wrote: > > >I have ipfilter on some of my boxes. In /etc/syslog.conf, I have the > >following lines: > > > >!ipmon > >*.* /var/log/ipf.log > > > >This works, and I get all entries in /var/log/ipf.log, which is good. > >The problem I have is that I also get all entries in /var/log/messages > > > >What do I need to do to stop syslog logging these messages to both > >locations and start logging only to /var/log/ipf.log ? > > I don't have an entry in syslog.conf for ipmon but I have: > ipmon_flags="-D /var/log/ipf.log" # typically "-Ds" or "-D /var/log/ipflog" > in /etc/rc.conf The default -Ds logs to syslog with facility local0. man ipmon: -s Packet information read in will be sent through syslogd rather than saved to a file. The default facility when compiled and installed is local0. The following levels are used: LOG_INFO - packets logged using the "log" keyword as the action rather than pass or block. LOG_NOTICE - packets logged which are also passed LOG_WARNING - packets logged which are also blocked LOG_ERR - packets which have been logged and which can be con- sidered "short". handy I suppose if you do any postprocessing of the ipmon log output via syslogd. Regards, Jez