Linux Netfilter discussions
 help / color / mirror / Atom feed
* logging to syslog in a stealth way
@ 2005-09-13 12:42 Albretch Mueller
  2005-09-13 15:54 ` Georgi Alexandrov
  0 siblings, 1 reply; 4+ messages in thread
From: Albretch Mueller @ 2005-09-13 12:42 UTC (permalink / raw)
  To: netfilter

Hi *,

I could tell this is more of a Unix/Linux and syslog question, but since my 
end intention is using it with netfilter, I could imagine someone has come 
accross something like that before.

I would like for the logs produced by iptable (generally in 
/var/log/syslog), to be processed by an ng-syslog client and just popped as 
UDP packets

Search I did the mailing list (http://marc.theaimsgroup.com/?l=netfilter) 
for 'syslog udp' and couldn't find helpful info/leads and 'ng-syslog' or 
'ngsyslog' didn't give me a hit

How could you do something like that?

Thanks
Albretch




^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: logging to syslog in a stealth way
  2005-09-13 12:42 logging to syslog in a stealth way Albretch Mueller
@ 2005-09-13 15:54 ` Georgi Alexandrov
  0 siblings, 0 replies; 4+ messages in thread
From: Georgi Alexandrov @ 2005-09-13 15:54 UTC (permalink / raw)
  To: netfilter

Albretch Mueller wrote:

> Hi *,
>
> I could tell this is more of a Unix/Linux and syslog question, but 
> since my end intention is using it with netfilter, I could imagine 
> someone has come accross something like that before.
>
> I would like for the logs produced by iptable (generally in 
> /var/log/syslog), to be processed by an ng-syslog client and just 
> popped as UDP packets
>
> Search I did the mailing list 
> (http://marc.theaimsgroup.com/?l=netfilter) for 'syslog udp' and 
> couldn't find helpful info/leads and 'ng-syslog' or 'ngsyslog' didn't 
> give me a hit
>
> How could you do something like that?
>
> Thanks
> Albretch
>
>
>
>
What exactly you want to achieve with that ?

regards,
Georgi Alexandrov


^ permalink raw reply	[flat|nested] 4+ messages in thread

* RE: logging to syslog in a stealth way
       [not found] <MC8-F29NvzHr4sRQde100197b9c@MC8-F29.hotmail.com>
@ 2005-09-15 15:26 ` Albretch Mueller
  2005-09-15 15:33   ` /dev/rob0
  0 siblings, 1 reply; 4+ messages in thread
From: Albretch Mueller @ 2005-09-15 15:26 UTC (permalink / raw)
  To: netfilter

>What exactly you want to achieve with that ?

As the subject clearly states :-) "logging to syslog in a stealth way"

Do you know of any other/better way to do it?

Albretch

// - - - - - - - - - - - - - - - - - - - -
Date: Tue, 13 Sep 2005 18:54:02 +0300
From: Georgi Alexandrov <tehlists@hotpop.com>
Subject: Re: logging to syslog in a stealth way
To: netfilter@lists.netfilter.org
Message-ID: <4326F61A.8020402@hotpop.com>
Content-Type: text/plain; charset=windows-1251; format=flowed

Albretch Mueller wrote:

>Hi *,
>
>I could tell this is more of a Unix/Linux and syslog question, but since my 
>end intention is using it with netfilter, I could imagine someone has come 
>accross something like that before.
>
>I would like for the logs produced by iptable (generally in 
>/var/log/syslog), to be processed by an ng-syslog client and just popped as 
>UDP packets
>
>Search I did the mailing list (http://marc.theaimsgroup.com/?l=netfilter) 
>for 'syslog udp' and couldn't find helpful info/leads and 'ng-syslog' or 
>'ngsyslog' didn't give me a hit
>
>How could you do something like that?
>
>Thanks
>Albretch
>
>
>
>
What exactly you want to achieve with that ?

regards,
Georgi Alexandrov




^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: logging to syslog in a stealth way
  2005-09-15 15:26 ` Albretch Mueller
@ 2005-09-15 15:33   ` /dev/rob0
  0 siblings, 0 replies; 4+ messages in thread
From: /dev/rob0 @ 2005-09-15 15:33 UTC (permalink / raw)
  To: netfilter

On Thursday 2005-September-15 10:26, Albretch Mueller wrote:
> >What exactly you want to achieve with that ?
>
> As the subject clearly states :-) "logging to syslog in a stealth
> way"
>
> Do you know of any other/better way to do it?

Stealth means you are hiding. Who are you hiding from? You want logging 
to go to a remote syslog server but NOT to appear in the logs of the 
iptables machine?

Clarity of subject notwithstanding, your ultimate goal is far from 
clear. If my guess was correct, I think your only choice is ULOG. LOG 
is going to pass to the local kernel logging daemon.
-- 
    mail to this address is discarded unless "/dev/rob0"
    or "not-spam" is in Subject: header


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2005-09-15 15:33 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-09-13 12:42 logging to syslog in a stealth way Albretch Mueller
2005-09-13 15:54 ` Georgi Alexandrov
     [not found] <MC8-F29NvzHr4sRQde100197b9c@MC8-F29.hotmail.com>
2005-09-15 15:26 ` Albretch Mueller
2005-09-15 15:33   ` /dev/rob0

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox