]> TLD Linux GIT Repositories - packages/syslog-ng.git/blob - syslog-ng.conf
- sample config entries for syslog server
[packages/syslog-ng.git] / syslog-ng.conf
1 @version: 3.16
2 @include "scl.conf"
3 #
4 # Syslog-ng configuration for TLD Linux
5 #
6 # See syslog-ng(8) and syslog-ng.conf(5) for more information.
7 #
8
9 options {
10         flush_lines(0);
11         owner(root);
12         group(logs);
13         perm(0640);
14         create_dirs(yes);
15         dir_owner(root);
16         dir_group(logs);
17         dir_perm(0750);
18         stats_freq(3600);
19         time_reopen(10);
20         time_reap(360);
21         mark_freq(600);
22         threaded(yes);
23 };
24
25 source s_sys {
26         system();
27         internal();
28 };
29
30 # uncomment the line below and change ip/port if you want to run syslog server
31 #source s_net   udp(ip(192.168.1.100),port(514));
32
33 #destination d_loghost  { udp("loghost" port(514)); };
34
35 destination d_kern      { file("/var/log/kernel"); };
36 destination d_messages  { file("/var/log/messages"); };
37 destination d_authlog   { file("/var/log/secure"); };
38 destination d_mail      { file("/var/log/maillog"); };
39 destination d_uucp      { file("/var/log/spooler"); };
40 destination d_debug     { file("/var/log/debug"); };
41 destination d_cron      { file("/var/log/cron"); };
42 destination d_syslog    { file("/var/log/syslog"); };
43 destination d_daemon    { file("/var/log/daemon"); };
44 destination d_lpr               { file("/var/log/lpr"); };
45 destination d_user      { file("/var/log/user"); };
46 destination d_ppp               { file("/var/log/ppp"); };
47 destination d_ftp               { file("/var/log/xferlog"); };
48 destination d_audit     { file("/var/log/audit"); };
49 destination d_postgres  { file("/var/log/pgsql"); };
50 destination d_freshclam { file("/var/log/freshclam.log"); };
51
52 destination d_shorewall { file("/var/log/shorewall"); };
53
54 destination d_console   { usertty("root"); };
55 #destination d_console_all      { file("/dev/tty12"); };
56
57 destination d_xconsole  { pipe("/dev/xconsole"); };
58
59 destination d_newscrit  { file("/var/log/news/news.crit" owner(news) group(news)); };
60 destination d_newserr   { file("/var/log/news/news.err" owner(news) group(news)); };
61 destination d_newsnotice        { file("/var/log/news/news.notice" owner(news) group(news)); };
62
63 # uncomment the line below if you want to run syslog server
64 #destination d_from_net { file("/var/log/$HOST.log" owner(root) group(root) perm(0644) dir_perm(0700) create_dirs(yes)); };
65
66 # Filters for standard syslog(3) facilities
67 #filter f_audit         { facility(audit); };
68 filter f_authpriv       { facility(authpriv, auth); };
69 filter f_cron           { facility(cron); };
70 filter f_daemon         { facility(daemon); };
71 filter f_ftp            { facility(ftp); };
72 filter f_kern           { facility(kern); };
73 filter f_lpr            { facility(lpr); };
74 filter f_mail           { facility(mail); };
75 filter f_news           { facility(news); };
76 filter f_syslog         { facility(syslog); };
77 filter f_user           { facility(user); };
78 filter f_uucp           { facility(uucp); };
79 filter f_local0         { facility(local0); };
80 filter f_local1         { facility(local1); };
81 filter f_local2         { facility(local2); };
82 filter f_local3         { facility(local3); };
83 filter f_local4         { facility(local4); };
84 filter f_local5         { facility(local5); };
85 filter f_local6         { facility(local6); };
86 filter f_local7         { facility(local7); };
87
88 # Filters for standard syslog(3) priorities
89 filter p_debug          { level(debug); };
90 filter p_info           { level(info); };
91 filter p_notice         { level(notice); };
92 filter p_warn           { level(warn); };
93 filter p_err            { level(err); };
94 filter p_alert          { level(alert); };
95 filter p_crit           { level(crit); };
96 filter p_emergency      { level(emerg); };
97
98 # Additional filters for specific programs/use
99 filter f_freshclam      { program(freshclam); };
100 filter f_ppp            { program(pppd) or program(chat); };
101 filter f_postgres       { program(postgres); };
102 filter f_shorewall      { facility(kern) and match("Shorewall:" value("MESSAGE")); };
103
104 # uncomment the line below if you want to run syslog server
105 #log { source(s_net); destination(d_from_net); flags(final); };
106
107 # log shorewall to separate log file by default
108 log { source(s_src); filter(f_shorewall); destination(d_shorewall); flags(final); };
109
110 log { source(s_sys); filter(f_authpriv);        destination(d_authlog); };
111 log { source(s_sys); filter(f_cron);            destination(d_cron); };
112 log { source(s_sys); filter(f_daemon);          destination(d_daemon); };
113 log { source(s_sys); filter(f_ftp);             destination(d_ftp); };
114 log { source(s_sys); filter(f_kern);            destination(d_kern); };
115 log { source(s_sys); filter(f_lpr);             destination(d_lpr); };
116 log { source(s_sys); filter(f_mail);                    destination(d_mail); };
117 log { source(s_sys); filter(f_news); filter(p_crit);    destination(d_uucp); };
118 log { source(s_sys); filter(f_news); filter(p_crit);    destination(d_newscrit); };
119 log { source(s_sys); filter(f_news); filter(p_err);     destination(d_newserr); };
120 log { source(s_sys); filter(f_news); filter(p_warn);    destination(d_newsnotice); };
121 log { source(s_sys); filter(f_news); filter(p_notice);  destination(d_newsnotice); };
122 log { source(s_sys); filter(f_news); filter(p_info);    destination(d_newsnotice); };
123 log { source(s_sys); filter(f_news); filter(p_debug);   destination(d_newsnotice); };
124 log { source(s_sys); filter(f_syslog);          destination(d_syslog); };
125 log { source(s_sys); filter(f_user);            destination(d_user); };
126 log { source(s_sys); filter(f_uucp);            destination(d_uucp); };
127
128 log { source(s_sys); filter(p_debug);           destination(d_debug); };
129
130 log { source(s_sys); filter(f_daemon); filter(f_ppp);           destination(d_ppp); };
131 log { source(s_sys); filter(f_local6); filter(f_freshclam);     destination(d_freshclam); };
132 log { source(s_sys); filter(f_local0); filter(f_postgres);      destination(d_postgres); };
133
134 log { source(s_sys); filter(p_emergency);       destination(d_console); };
135 #log { source(s_sys); destination(d_console_all); };
136
137 #  This is a catchall statement, and should catch all messages which were not
138 #  accepted any of the previous statements.
139 log { source(s_sys); destination(d_messages); flags(fallback); };
140
141 # Network syslogging
142 #log { source(s_sys); destination(d_loghost); };