CentOS Icon CentOS Logo
CentOS Text
   
  
www.centos.org Forum Index
   CentOS 5 - General Support
  [SOLVED] Remote syslog

 

 Bottom   Previous Topic   Next Topic
  •  Rate Thread
      Rate this Thread
      Excellent
      Good
      Average
      Bad
      Terrible
Poster Thread
  •  AlanBartlett
      AlanBartlett
Re: [SOLVED] Remote syslog
#7
Moderator
Joined: 2007/10/22
From ~/Earth/UK/England/Suffolk
Posts: 9135
Thank you for reporting back.

For posterity (and on your behalf) this thread is now marked [SOLVED].
_________________
Alan

100% Unix & Linux. Co-founder of the ELRepo Project.
Posted on: 2012/3/1 2:57
Create PDF from Post Print
Top
  •  jnojr
      jnojr
Re: Remote syslog
#6
Regular Board Member
Joined: 2007/11/29
From Reston, VA
Posts: 54
Quote:

TrevorH wrote:
Look harder for firewall rules?


And this is what it actually was

Reverse DNS is broken on the network in question, which causes several problems. One was iptables hanging at a stock rule for Multicast DNS, and because I didn't pay close enough attention and saw the default policies were all ACCEPT, I just "saw" that the firewall wasn't involved. All is well now. Thanks!!!
Posted on: 2012/2/29 18:03
Create PDF from Post Print
Top
  •  TrevorH
      TrevorH
Re: Remote syslog
#5
Moderator
Joined: 2009/9/24
From Brighton, UK
Posts: 6334
Look harder for firewall rules? Tcpdump sees packets as they arrive and before iptables so even if iptables is dropping the packets, you will still see them with tcpdump.
_________________
Linux/VoIP Systems Administrator
Posted on: 2012/2/29 0:32
Create PDF from Post Print
Top
  •  jnojr
      jnojr
Re: Remote syslog
#4
Regular Board Member
Joined: 2007/11/29
From Reston, VA
Posts: 54
Running under the assumption that maybe sysklogd just sucks too much for this to work, I installed rsyslog 3.22.1-3 from the CentOS DVD and configured it. And I'm seeing the same issue... logs from remote devices just aren't being written.

I'm clearly missing something, but every piece of documentation and every post I can find that has anything to do with this assumes that everything just works perfectly at this point. What else could possibly be involved here???
Posted on: 2012/2/28 15:22
Create PDF from Post Print
Top
  •  jnojr
      jnojr
Re: Remote syslog
#3
Regular Board Member
Joined: 2007/11/29
From Reston, VA
Posts: 54
Quote:

mrat3e1 wrote:
do you have iptables enabled? does tcpdump show udp/514 traffic arriving on the interface?

Is 514 listening?


No, yes, and yes.
Posted on: 2012/2/27 12:56
Create PDF from Post Print
Top
  •  mrat3e1
      mrat3e1
Re: Remote syslog
#2
Newbie
Joined: 2012/2/24
From
Posts: 2
do you have iptables enabled? does tcpdump show udp/514 traffic arriving on the interface?

$sudo iptables -L

will show your current ruleset.

Is 514 listening?

$ sudo lsof -i:514

or $netstat -na | grep 514
Posted on: 2012/2/24 21:53
Create PDF from Post Print
Top
  •  jnojr
      jnojr
[SOLVED] Remote syslog
#1
Regular Board Member
Joined: 2007/11/29
From Reston, VA
Posts: 54
CentOS 5.7, sysklogd 1.4.1-46

I added "-r" to /etc/sysconfig/syslog and restarted the syslog service. With tcpdump, I can see that other devices are sending traffic to UDP 514, but nothing is showing up in /var/log/messages, which is where Googling suggests they'll end up without changing /etc/syslogd.conf I'm not finding any other troubleshooting pointers... by all indications, it's supposed to "just work" at this point. Any ideas?
Posted on: 2012/2/24 18:52
Create PDF from Post Print
Top
 Top   Previous Topic   Next Topic

 


 You cannot start a new topic.
 You can view topic.
 You cannot reply to posts.
 You cannot edit your posts.
 You cannot delete your posts.
 You cannot add new polls.
 You cannot vote in polls.
 You cannot attach files to posts.
 You cannot post without approval.




"Linux" is a registered trademark of Linus Torvalds. | All other trademarks are property of their respective owners. | All other content is Copyright @ 2004-2009 by the CentOS Project or "each individual contributor (forums, comments, etc.) unless otherwise assigned".| Theme based on a theme by 7dana.com