Syslog not forwarding remote messages

Viewed 1973

I configured /etc/syslog.conf with below configuration

*.* @10.10.10.2:514
*.* @@10.10.10.2:514

and logged through below code

openlog("Test-Msg", LOG_PID, LOG_LOCAL0);
for (int i = 0; i <10; i++)
{
    syslog(LOG_ALERT, "My msg %d", i);
    std::cout<<"-------------Writing Syslog "<<i<<"\n";
}

closelog();

but its not forwarding to remote server. instead of that it creates a file "@10.10.10.2:514" & "@@10.10.10.2:514" and logging all the message there.

Tested with wireshark, no messages are forwarded to remote system.

I am using yocto platform and busybox 1.22 syslog implementation.

Update

In yocto I saw one more configuration file /etc/syslog-startup.conf and there I configured

DESTINATION=remote  # log destinations (buffer file remote)
REMOTE=10.10.10.2:514          # where to log (syslog remote)

Now its started forwarding all the messages, but as per the linux manuals syslog conf must support *.=alert @<host:port> filter. If I have to use the above configuration how can I apply the filters?

3 Answers

I'm also looking into this. busybox supports remote logging, but it seems to forward all the messages. There is no support for filtering combined with remote logging. I installed rsyslog on the image to solve this.

I also found out that rsyslog does not rotate files out of the box. Logrotate was installed as dependency but there is no cron daemon running. I had to install cronie and configure cronie, logrotate and rsyslog.

Related