DIY centralized netbsd syslog server

draft - receiving logs but not to a seperated file just yet

Setup

on the netbsd server

mkdir /var/log/centralized/
vi /etc/syslog.conf

#
# DIY CENTRALIZED LOG SERVER
#

+host1
*.*                                                     /var/log/centralized/host1

enable daemon listen on UDP and apply

vi /etc/rc.conf

syslogd_flags=""

/etc/rc.d/syslogd restart

Ready to go

first test that the log server is reachable

ping 10.1.0.99
nmap -sU -p 514 10.1.0.99
logger --rfc3164 --udp --server 10.1.0.99 --priority warn test-warning
logger --udp --server 10.1.0.99 --priority warn test-warning

on the client(s) - assuming sysklogd

vi /etc/syslog.conf

*.warn                                                  @10.1.0.99

rc.syslog restart

Resources

https://man.netbsd.org/syslogd.8

https://man.netbsd.org/syslog.conf.5

https://troglobit.com/post/2019-11-03-bsd-syslogd-in-linux/

https://github.com/troglobit/sysklogd/

https://wiki.gentoo.org/wiki/Sysklogd


https://stackoverflow.com/questions/2031163/when-to-use-the-different-log-levels ==> warn vs. error: gets sysadmin out of bed


HOME | GUIDES | LECTURES | LAB | SMTP HEALTH | HTML5 | CONTACT
Copyright © 2024 Pierre-Philipp Braun