PDA

View Full Version : Setting Up Syslog Server + Fedora Core 5



Jimjames
30th May 2006, 03:33 PM
Hi All,

Could someone help me set up a syslog server on Fedora Core 5 platform.

Regards

pparks1
30th May 2006, 04:25 PM
If you are just looking for a standard syslog server, this should do ya

modify /etc/sysconfig/syslog
change : SYSLOGD_OPTIONS="-m" to SYSLOGD_OPTIONS="-r -m 0"

The -r tells syslog to listen for remote hosts rather than just the local server


Make sure that you allow udp traffic on port 514 with a rule in /etc/sysconfig/iptables similar to

-A RH-Firewall-1-INPUT -m state --state NEW -m udp -p udp --dport 514 -j ACCEPT

Issue the following commands to restart iptables and syslog

service iptables restart
service syslolg restart


On the client machines, I would suggest putting an entry for the syslog server into /etc/hosts

for example,

10.0.0.1 servername.domain.com server loghost

Then, modify /etc/syslog.conf on each host and modify the configuration there.

for example, to log to both the local machine (nice for logwatch reports) and to the centralized syslog server, each line would have 2 entries


authpriv.* /var/log/secure
authpriv.* @loghost


Finally, restart the sylog daemon on the clients

service syslog restart

Jimjames
30th May 2006, 04:37 PM
Thnx much?

I hope that will as well work for cisco devices (routers and switchs)?....where do i set the email address of the admin......and the level of serverty?
Would appreciate!