[645] | 1 | # syslog-ng configuration file. |
---|
| 2 | # |
---|
| 3 | # This should behave pretty much like the original syslog on RedHat. But |
---|
| 4 | # it could be configured a lot smarter. |
---|
| 5 | # |
---|
| 6 | # See syslog-ng(8) and syslog-ng.conf(5) for more information. |
---|
| 7 | # |
---|
| 8 | |
---|
| 9 | options { |
---|
[1259] | 10 | sync (0); |
---|
| 11 | time_reopen (10); |
---|
| 12 | log_fifo_size (1000); |
---|
| 13 | long_hostnames (off); |
---|
| 14 | use_dns (no); |
---|
| 15 | use_fqdn (no); |
---|
| 16 | create_dirs (no); |
---|
| 17 | keep_hostname (yes); |
---|
[645] | 18 | }; |
---|
| 19 | |
---|
| 20 | source s_sys { |
---|
[1259] | 21 | file ("/proc/kmsg" log_prefix("kernel: ")); |
---|
| 22 | unix-stream ("/dev/log"); |
---|
| 23 | internal(); |
---|
| 24 | # udp(ip(0.0.0.0) port(514)); |
---|
[645] | 25 | }; |
---|
| 26 | |
---|
| 27 | destination d_cons { file("/dev/console"); }; |
---|
| 28 | destination d_mesg { file("/var/log/messages"); }; |
---|
| 29 | destination d_auth { file("/var/log/secure"); }; |
---|
| 30 | destination d_mail { file("/var/log/maillog" sync(10)); }; |
---|
| 31 | destination d_spol { file("/var/log/spooler"); }; |
---|
| 32 | destination d_boot { file("/var/log/boot.log"); }; |
---|
| 33 | destination d_cron { file("/var/log/cron"); }; |
---|
[1259] | 34 | #destination d_kern { file("/var/log/kern"); }; |
---|
[645] | 35 | destination d_mlal { usertty("*"); }; |
---|
| 36 | |
---|
| 37 | destination d_zroot { program("/etc/syslog-ng/d_zroot.pl"); }; |
---|
[817] | 38 | #destination d_watch { program("/usr/local/libexec/watch-syslog.py"); }; |
---|
[645] | 39 | |
---|
[1259] | 40 | #filter f_kernel { facility(kern); }; |
---|
| 41 | filter f_default { level(info..emerg) and |
---|
| 42 | not (facility(mail) |
---|
| 43 | or facility(authpriv) |
---|
| 44 | or facility(cron)); }; |
---|
| 45 | filter f_auth { facility(authpriv); }; |
---|
| 46 | filter f_mail { facility(mail); }; |
---|
| 47 | filter f_emergency { level(emerg); }; |
---|
| 48 | filter f_news { facility(uucp) or |
---|
| 49 | (facility(news) |
---|
| 50 | and level(crit..emerg)); }; |
---|
| 51 | filter f_boot { facility(local7); }; |
---|
| 52 | filter f_cron { facility(cron); }; |
---|
[645] | 53 | |
---|
[817] | 54 | filter f_oom { facility(kern) and (match("Out of memory:") or match("Killed process")); }; |
---|
[645] | 55 | |
---|
[1259] | 56 | #log { source(s_sys); filter(f_kernel); destination(d_cons); }; |
---|
| 57 | #log { source(s_sys); filter(f_kernel); destination(d_kern); }; |
---|
| 58 | log { source(s_sys); filter(f_default); destination(d_mesg); }; |
---|
| 59 | log { source(s_sys); filter(f_auth); destination(d_auth); }; |
---|
| 60 | log { source(s_sys); filter(f_mail); destination(d_mail); }; |
---|
| 61 | log { source(s_sys); filter(f_emergency); destination(d_mlal); }; |
---|
| 62 | log { source(s_sys); filter(f_news); destination(d_spol); }; |
---|
| 63 | log { source(s_sys); filter(f_boot); destination(d_boot); }; |
---|
| 64 | log { source(s_sys); filter(f_cron); destination(d_cron); }; |
---|
[645] | 65 | |
---|
[1259] | 66 | log { source(s_sys); filter(f_auth); destination(d_zroot); }; |
---|
| 67 | #log { source(s_sys); filter(f_default); destination(d_watch); }; |
---|
[817] | 68 | log { source(s_sys); filter(f_oom); destination(d_zroot); }; |
---|
[645] | 69 | |
---|
[1259] | 70 | # vim:ft=syslog-ng:ai:si:ts=4:sw=4:et: |
---|