All of lore.kernel.org
 help / color / mirror / Atom feed
* Ulogd
@ 2002-10-07  7:15 darkstar
  2002-10-07  9:59 ` Ulogd Antony Stone
  0 siblings, 1 reply; 4+ messages in thread
From: darkstar @ 2002-10-07  7:15 UTC (permalink / raw)
  To: netfilter

Quick question, I use ulog for all logging and would like to start
logging to a MySQL database.
I want to log to a database on another server. Would it be better
(traffic wise) to log directly to the database or to rather import a log
file at the end of the day into the database..???

Thanks
Paulo





^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: Ulogd
  2002-10-07  7:15 Ulogd darkstar
@ 2002-10-07  9:59 ` Antony Stone
  0 siblings, 0 replies; 4+ messages in thread
From: Antony Stone @ 2002-10-07  9:59 UTC (permalink / raw)
  To: netfilter

On Monday 07 October 2002 8:15 am, darkstar wrote:

> Quick question, I use ulog for all logging and would like to start
> logging to a MySQL database.
> I want to log to a database on another server. Would it be better
> (traffic wise) to log directly to the database or to rather import a log
> file at the end of the day into the database..???

I'd say it depends on two things, maybe three:

1. How steady is the traffic on the link between your servers, and does it 
saturate ?   If you have spare capacity most of the time, there's no harm in 
sending the logs continuously.   If it saturates, then you would generate 
most log entries when there's most traffic, making the problem worse, so best 
to batch it up for a quiet period in the moddle of the night...

2. What do you want to do with the logs on the database ?   If you have no 
interest in processing them as they come in, there's no need to get them 
"live", so a batch upload might be best.   If your database will be used for 
live traffic analyses and you want to see what's come inn in the past 5 
minutes, you need a continuous update.

3. If you get some serious problem and your firewall gets compromised, 
crashes, bursts into flames etc., how bothered are you about losing the 
current day's logs ?   If you don't care, then a batch upload is okay; if you 
want to see what happened just before the disaster, you need to send to the 
database server continuously.

Hope this helps,

Antony.

-- 

This is not a rehearsal.
This is Real Life.


^ permalink raw reply	[flat|nested] 4+ messages in thread

* ULOGD
@ 2004-05-07  9:52 zze-KHOURY Jad FTRD/DMI/CAE
  2004-05-07 10:34 ` ULOGD Sven Schuster
  0 siblings, 1 reply; 4+ messages in thread
From: zze-KHOURY Jad FTRD/DMI/CAE @ 2004-05-07  9:52 UTC (permalink / raw)
  To: netfilter

Hi,
I want to use the ULOG target instead of LOG target on my firewall rules
so I have to download the ULOGD Deamon. I found the ulogd for a linux
mandrake but I need it for a RedHat V.9.
Any help!!
Best regards
jad


^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: ULOGD
  2004-05-07  9:52 ULOGD zze-KHOURY Jad FTRD/DMI/CAE
@ 2004-05-07 10:34 ` Sven Schuster
  0 siblings, 0 replies; 4+ messages in thread
From: Sven Schuster @ 2004-05-07 10:34 UTC (permalink / raw)
  To: zze-KHOURY Jad FTRD/DMI/CAE; +Cc: netfilter

[-- Attachment #1: Type: text/plain, Size: 670 bytes --]


Hi Jad,

On Fri, May 07, 2004 at 11:52:32AM +0200, zze-KHOURY Jad FTRD/DMI/CAE told us:
> Hi,
> I want to use the ULOG target instead of LOG target on my firewall rules
> so I have to download the ULOGD Deamon. I found the ulogd for a linux
> mandrake but I need it for a RedHat V.9.

Two choices:
1. compile it from source
2. look at rpmsearch.com/freshrpms/insert your favorite rpm search
   engine if you can find rpm packages for redhat 9

HTH

Sven

> Any help!!
> Best regards
> jad

-- 
Linux zion 2.6.6-rc1 #1 Sat Apr 17 11:50:12 CEST 2004 i686 athlon i386 GNU/Linux
 12:33:15  up 1 day, 12:28,  1 user,  load average: 0.00, 0.00, 0.00

[-- Attachment #2: Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2004-05-07 10:34 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-10-07  7:15 Ulogd darkstar
2002-10-07  9:59 ` Ulogd Antony Stone
  -- strict thread matches above, loose matches on Subject: below --
2004-05-07  9:52 ULOGD zze-KHOURY Jad FTRD/DMI/CAE
2004-05-07 10:34 ` ULOGD Sven Schuster

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.