Re: syslog from Solaris via ssh to Linux syslog server

From: Darren Tucker (dtucker_at_gate.dodgy.net.au)
Date: 09/28/05


Date: 28 Sep 2005 12:30:56 GMT

On 2005-09-27, Uniprince <pculver@salesforce.com> wrote:
> I am trying to send the syslogs from Solaris 9 servers to a central
> syslog server running Red Hat Linux. Does the Red Hat server have be
> defined as a loghost? Do I remove the loghost from /etc/hosts on the

If you're trying to send the syslog messages via ssh tunnels then that
won't work. syslog packets are UDP and SSH port forwarding only does TCP.

Some of the alternative syslogs (syslog-ng) might be able to use TCP
but I'm not sure.

-- 
Darren Tucker (dtucker at zip.com.au)
GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4  37C9 C982 80C7 8FF4 FA69
    Good judgement comes with experience. Unfortunately, the experience
usually comes from bad judgement.


Relevant Pages

  • Re: Need to implemet Syslog server
    ... >On my network I need to implement a Syslog server ... Pretty much everything but Windows will ... likely talk to syslog if told to, ... A great many other managed network devices support syslogging, ...
    (Security-Basics)
  • [HPADM] SUMMARY: syslog redirection
    ... server is down, entries will be lost. ... Syslog sends over UDP on a "broadcast and forget" concept. ... information that is subject to United States laws and regulations. ... I'm being asked to route syslog messages to a central server. ...
    (HP-UX-Admin)
  • Re: How to allow port 514?
    ... a packet filter allows traffic into the server itself. ... If you want to run your syslog on the server you would use a packet filter. ... In ISA Policy Elements, right click Protocol Definitions, ... in Publishing, right click Server ...
    (microsoft.public.windows.server.sbs)
  • RE: Syslog Server on Debian Etch
    ... Syslog was working fine on the clients, I had it installed to a diff ... Is anyone else monitoring Juniper Netscreen firewalls? ... Syslog Server on Debian Etch ...
    (Debian-User)
  • SUMMARY: forwarded syslog messages are missing originating hostname
    ... I am running Solaris 9 with the latest_recommended. ... to send their syslog messages to a central server, ... as a relay server to forward all syslog messages to a third server. ... originating servers hostname and state that they are only from the relay ...
    (SunManagers)