SYSLOG

Hi sunnycoder,

Here is what i have managed to do till now.
1. I have made the client machines to forward thier logs to a single SYSLOG server by editing thier syslog.conf. I have also configured the MAXTNT to forward its  logs to to the syslog server.
2. It is confirmed that  enrty   "  syslog                      514/udp   "       exists in /etc/services.
3. I have changed the /etc/sysconfig/syslog            SYSLOGD_OPTIONS = " -m 0 -r " .
4. Restarted the syslog and verified that -r  option is activated.

Now I need to know what should  I do to separate local machine's logs and network machines logs. What if I want to store MAXTNT's / Cisco Router / Cisco Switch logs in a separate directory. I know that I should be  editing the file syslog.conf, but what should I put there ?
 
Thanks....
ATIQAHMED.
atiqahmedAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

jlevieCommented:
The standard syslog daemon on most Linux distributions isn't capable of logging to different files based on the system source of the messages. I believe that syslog-ng (see http://www.balabit.com/products/syslog_ng/)  can do this.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Karl Heinz KremerCommented:
The syslog-ng sample configuration file at http://www.campin.net/syslog-ng.conf shows (near the end of the file) under the heading "automatic host sorting (usually used on a loghost)" how you can use different log files for different machines.

jlevie is right that the standard Linux syslogd does not support this.
0
jlevieCommented:
Split between jlevie & khkremer
0
Karl Heinz KremerCommented:
No comment has been added lately, so it's time to clean up this TA.
I will leave a recommendation in the Cleanup topic area that this question is:
Split between jlevie and khkremer
Please leave any comments here within the next four days.

PLEASE DO NOT ACCEPT THIS COMMENT AS AN ANSWER!

khkremer
EE Cleanup Volunteer
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Linux

From novice to tech pro — start learning today.