Syslog not logging remote host
wmoran at potentialtech.com
Sat Apr 14 00:48:12 UTC 2007
"Janos Dohanics" <web at 3dresearch.com> wrote:
> I'm trying capture logs from m0n0wall, but the log file is empty.
> Here is my configuration:
> On the logging machine, in /etc/rc.conf:
> syslogd_flags="-a 10.61.70.1"
> In /etc/syslog.conf:
> *.* /var/log/m0n0wall.log
> /var/log/m0n0wall.log exists and writable:
> -rw-rw-r-- 1 root network 0 Apr 13 00:32 /var/log/m0n0wall.log
> The m0n0wall is configured to send logs to 10.61.70.100, which is the
> logging machine.
> What am I missing?
Start with tcpdump on the receiving machine:
tcpdump 'port 514'
to see if you're even receiving messages from the monowall machine.
If not, then double-check your config on the monowall machine. If so,
check the receiving machine.
Did you restart syslogd on both systems after making config changes?
More information about the freebsd-questions