[logs] Syslog-ng filters - How to figure out which filter was tripped

From: Clark, Bill W. (Bill.Clark@private)
Date: Thu May 13 2004 - 07:57:39 PDT

  • Next message: Thomas Biege: "[logs] Call for Participation Workshop DIMVA 2004"

    Anybody  know of a way to determine which filter is being used in
    syslog-ng?   
    
    I have several filters that watch for various combinations of hosts and
    matches and then send the event to an email script.  I have had problems
    determining which filter to examine.  In some cases I have examined all
    filters and  not found a good reason why something was run through the
    filter.
    
    It would be great if there was a way to log filter actions so that you
    knew which filter was tripped and what exactly it was that was caught by
    the filter.
    
    Perhaps I should look for the syslog-ng dev mailing list and see if I
    can get this feature discussed.
    
    Bill Clark
    _______________________________________________
    LogAnalysis mailing list
    LogAnalysis@private
    http://lists.shmoo.com/mailman/listinfo/loganalysis
    



    This archive was generated by hypermail 2b30 : Thu May 13 2004 - 08:32:04 PDT