SuSE firewall and syslog.conf

Posted on 2004-09-03
Last Modified: 2013-12-15
my firewall seems to be filling up all sorts of log files that i don't want it in.  okay, so that's a bit of hyperbole, but the firewall messages are showing up in /var/log/messages, /var/log/warn and /var/log/firewall.  (i don't know if it makes any difference, but it's SuSE 8.0 running kernel 2.4.18.)

i'd like to drop the loggin to messages and warn and leave everything in firewall, but i'm not sure what to do with my syslog.conf file.  below are the lines from syslog.conf that mention the three files in question:
*.=warn;*.=err                  -/var/log/warn
*.crit                           /var/log/warn
*.*;mail.none;news.none;authpriv.none;auth.none         -/var/log/messages
kern.*          -/var/log/firewall

i'm not worried about errant kernel messages appearing in the firewall file - they only account for about 1.5% of the messages.  i've found websites saying that the firewall logs to kern.=info and kern.=debug.  what about boot messages (the other 1.5% of the firewall file) - what log level do they get passed through?

Question by:kevincasey
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2

Author Comment

ID: 12105701
any suggestions?  anyone?

Expert Comment

ID: 12148332

   If you are running a gui based firewall configuration program look for the logging directive for the individual firewall rules that you do not want to see and disable the logging.  


Author Comment

ID: 12162320
i'm not using a gui based tool.  i'm doing this by hand.

i ended up hacking this one together myself.  since i couldn't figure out what level the firewall was logging at, i ended up dumping all the kernel messages into the firewall log.  the two lines i ended up editing are below:

*.*;kern,mail,news,authpriv,auth.none           -/var/log/messages
kern.*          -/var/log/firewall

Accepted Solution

DarthMod earned 0 total points
ID: 15749341
PAQed with points (300) refunded

Community Support Moderator

Featured Post

Certified OpenStack Administrator Course

We just refreshed our COA course based on the Newton exam.  With 14 labs, this course goes over the different OpenStack services that are part of the certification: Dashboard, Identity Service, Image Service, Networking, Compute, Object Storage, Block Storage, and Orchestration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you have a server on collocation with the super-fast CPU, that doesn't mean that you get it running at full power. Here is a preamble. When doing inventory of Linux servers, that I'm administering, I've found that some of them are running on l…
Fine Tune your automatic Updates for Ubuntu / Debian
Learn several ways to interact with files and get file information from the bash shell. ls lists the contents of a directory: Using the -a flag displays hidden files: Using the -l flag formats the output in a long list: The file command gives us mor…
Learn how to navigate the file tree with the shell. Use pwd to print the current working directory: Use ls to list a directory's contents: Use cd to change to a new directory: Use wildcards instead of typing out long directory names: Use ../ to move…
Suggested Courses

628 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question