* logging to syslog in a stealth way
@ 2005-09-13 12:42 Albretch Mueller
2005-09-13 15:54 ` Georgi Alexandrov
0 siblings, 1 reply; 4+ messages in thread
From: Albretch Mueller @ 2005-09-13 12:42 UTC (permalink / raw)
To: netfilter
Hi *,
I could tell this is more of a Unix/Linux and syslog question, but since my
end intention is using it with netfilter, I could imagine someone has come
accross something like that before.
I would like for the logs produced by iptable (generally in
/var/log/syslog), to be processed by an ng-syslog client and just popped as
UDP packets
Search I did the mailing list (http://marc.theaimsgroup.com/?l=netfilter)
for 'syslog udp' and couldn't find helpful info/leads and 'ng-syslog' or
'ngsyslog' didn't give me a hit
How could you do something like that?
Thanks
Albretch
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: logging to syslog in a stealth way
2005-09-13 12:42 logging to syslog in a stealth way Albretch Mueller
@ 2005-09-13 15:54 ` Georgi Alexandrov
0 siblings, 0 replies; 4+ messages in thread
From: Georgi Alexandrov @ 2005-09-13 15:54 UTC (permalink / raw)
To: netfilter
Albretch Mueller wrote:
> Hi *,
>
> I could tell this is more of a Unix/Linux and syslog question, but
> since my end intention is using it with netfilter, I could imagine
> someone has come accross something like that before.
>
> I would like for the logs produced by iptable (generally in
> /var/log/syslog), to be processed by an ng-syslog client and just
> popped as UDP packets
>
> Search I did the mailing list
> (http://marc.theaimsgroup.com/?l=netfilter) for 'syslog udp' and
> couldn't find helpful info/leads and 'ng-syslog' or 'ngsyslog' didn't
> give me a hit
>
> How could you do something like that?
>
> Thanks
> Albretch
>
>
>
>
What exactly you want to achieve with that ?
regards,
Georgi Alexandrov
^ permalink raw reply [flat|nested] 4+ messages in thread
* RE: logging to syslog in a stealth way
[not found] <MC8-F29NvzHr4sRQde100197b9c@MC8-F29.hotmail.com>
@ 2005-09-15 15:26 ` Albretch Mueller
2005-09-15 15:33 ` /dev/rob0
0 siblings, 1 reply; 4+ messages in thread
From: Albretch Mueller @ 2005-09-15 15:26 UTC (permalink / raw)
To: netfilter
>What exactly you want to achieve with that ?
As the subject clearly states :-) "logging to syslog in a stealth way"
Do you know of any other/better way to do it?
Albretch
// - - - - - - - - - - - - - - - - - - - -
Date: Tue, 13 Sep 2005 18:54:02 +0300
From: Georgi Alexandrov <tehlists@hotpop.com>
Subject: Re: logging to syslog in a stealth way
To: netfilter@lists.netfilter.org
Message-ID: <4326F61A.8020402@hotpop.com>
Content-Type: text/plain; charset=windows-1251; format=flowed
Albretch Mueller wrote:
>Hi *,
>
>I could tell this is more of a Unix/Linux and syslog question, but since my
>end intention is using it with netfilter, I could imagine someone has come
>accross something like that before.
>
>I would like for the logs produced by iptable (generally in
>/var/log/syslog), to be processed by an ng-syslog client and just popped as
>UDP packets
>
>Search I did the mailing list (http://marc.theaimsgroup.com/?l=netfilter)
>for 'syslog udp' and couldn't find helpful info/leads and 'ng-syslog' or
>'ngsyslog' didn't give me a hit
>
>How could you do something like that?
>
>Thanks
>Albretch
>
>
>
>
What exactly you want to achieve with that ?
regards,
Georgi Alexandrov
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: logging to syslog in a stealth way
2005-09-15 15:26 ` Albretch Mueller
@ 2005-09-15 15:33 ` /dev/rob0
0 siblings, 0 replies; 4+ messages in thread
From: /dev/rob0 @ 2005-09-15 15:33 UTC (permalink / raw)
To: netfilter
On Thursday 2005-September-15 10:26, Albretch Mueller wrote:
> >What exactly you want to achieve with that ?
>
> As the subject clearly states :-) "logging to syslog in a stealth
> way"
>
> Do you know of any other/better way to do it?
Stealth means you are hiding. Who are you hiding from? You want logging
to go to a remote syslog server but NOT to appear in the logs of the
iptables machine?
Clarity of subject notwithstanding, your ultimate goal is far from
clear. If my guess was correct, I think your only choice is ULOG. LOG
is going to pass to the local kernel logging daemon.
--
mail to this address is discarded unless "/dev/rob0"
or "not-spam" is in Subject: header
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2005-09-15 15:33 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-09-13 12:42 logging to syslog in a stealth way Albretch Mueller
2005-09-13 15:54 ` Georgi Alexandrov
[not found] <MC8-F29NvzHr4sRQde100197b9c@MC8-F29.hotmail.com>
2005-09-15 15:26 ` Albretch Mueller
2005-09-15 15:33 ` /dev/rob0
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox