[rsyslog] SSH Success and Failure logs in separate files

2014-03-20 Thread Muhammad Asif
Hi Geeks! Is it possible to save ssh success and ssh failure attempt logs in separate files. If yes please help me. Regards Muhammad Asif ___ rsyslog mailing list http://lists.adiscon.net/mailman/listinfo/rsyslog http://www.rsyslog.com/professional-serv

[rsyslog] Doc update suggestion

2014-03-20 Thread Nathan Brown
Was doing some filtering using system variables, namely the `$myhostname` as it's referred to in the property replacer documentation. After many trials I finally discovered that to use it in an if statement I had to add another $ if $hostname == $$myhostname then { I didn't see this reference

[rsyslog] Docs formatting issues

2014-03-20 Thread Nathan Brown
Was looking for docs on rainerscript and found this page: http://www.rsyslog.com/doc/v7-stable/rainerscript/rscript_abnf.html Formatting needs some love ___ rsyslog mailing list http://lists.adiscon.net/mailman/listinfo/rsyslog http://www.rsyslog.com/pr

Re: [rsyslog] duplicate imfile sends

2014-03-20 Thread Jeremy Hoel
It does make it a bit more difficult to troubleshoot when not everything matches up with expectations. I would think if it was something in the config all the logs would have been doubled up and that wasn't happening. Oh well. Computers do weird things. On Mar 20, 2014 5:29 PM, "David Lang" wrot

Re: [rsyslog] duplicate imfile sends

2014-03-20 Thread David Lang
On Thu, 20 Mar 2014, Jeremy Hoel wrote: No, there wasn't; that's what lead me to think it was rsyslog and not bro. But I think I may have found the problem. There where two "$IncludeConfig\ /etc/rsyslog.d/*.conf" lines in the conf file. I removed one and the dups for dns stopped. That explai

Re: [rsyslog] duplicate imfile sends

2014-03-20 Thread Jeremy Hoel
No, there wasn't; that's what lead me to think it was rsyslog and not bro. But I think I may have found the problem. There where two "$IncludeConfig\ /etc/rsyslog.d/*.conf" lines in the conf file. I removed one and the dups for dns stopped. But I can't figure why there weren't dups in the dns l

Re: [rsyslog] duplicate imfile sends

2014-03-20 Thread David Lang
On Thu, 20 Mar 2014, Jeremy Hoel wrote: Well, I've commented out the action part. It just has the imfile to read the file and I've restarted and it's not sending any of the read dhcp files, but it is sending the dns ones (not duplicated). I put it back on, restart and it picks up the log and s

Re: [rsyslog] duplicate imfile sends

2014-03-20 Thread Jeremy Hoel
Well, I've commented out the action part. It just has the imfile to read the file and I've restarted and it's not sending any of the read dhcp files, but it is sending the dns ones (not duplicated). I put it back on, restart and it picks up the log and starts sending dups again. So very odd. O

Re: [rsyslog] duplicate imfile sends

2014-03-20 Thread David Lang
On Thu, 20 Mar 2014, Jeremy Hoel wrote: OK, but then the actions are two different ones based on the rsyslog-users tags and they go to different ports. So there is one action to 10521 (for dns) and one to 10522 (for dhcp). I've tried doing both imfile inputs in one conf file and that didn't see

Re: [rsyslog] librelp 1.2.5

2014-03-20 Thread Andre Lorbach
RPM's have been updated as well. Best regards, Andre > -Original Message- > From: rsyslog-boun...@lists.adiscon.com [mailto:rsyslog- > boun...@lists.adiscon.com] On Behalf Of Florian Riedl > Sent: Thursday, March 20, 2014 3:28 PM > To: rsyslog-users > Subject: [rsyslog] librelp 1.2.5 > >

[rsyslog] librelp 1.2.5

2014-03-20 Thread Florian Riedl
Hi all, we have just released librelp 1.2.5. This version of librelp allows to use anonymous TLS on platforms where GnuTLS misses certificate verification function. This permits to use at least anon TLS on platforms like RHEL and CENTOS 6. Changelog and Download: *http://www.librelp.com/2014/03/

Re: [rsyslog] could not load module '/lib64/rsyslog/imrelp.so (version 7.6.0)

2014-03-20 Thread Rainer Gerhards
On Fri, Mar 14, 2014 at 8:28 PM, Rainer Gerhards wrote: > Pls do. If you have a support contract, that simplifies things > cobsiderably :) > > Indeed, that simplified things as I thought. I was able to have a deep look at the code base yesterday ... and it thankfully turns out that it is actually