Syslog-ng 不会监听

Syslog-ng 不会监听

尝试设置 Syslog-NG,但根本无法让它监听。我在配置中添加了以下内容:

source s_net {
               tcp(ip(0.0.0.0) port(514));
               udp(ip(0.0.0.0) port(514));
};

然后我重新启动了服务

:/etc/syslog-ng$ sudo service syslog-ng restart
:/etc/syslog-ng$ sudo systemctl status syslog-ng
● syslog-ng.service - System Logger Daemon
   Loaded: loaded (/lib/systemd/system/syslog-ng.service; enabled; vendor preset: enabled)
   Active: active (running) since Fri 2019-05-24 13:52:16 UTC; 8s ago
     Docs: man:syslog-ng(8)
 Main PID: 3988 (syslog-ng)
    Tasks: 1
   Memory: 1.9M
      CPU: 29ms
   CGroup: /system.slice/syslog-ng.service
           └─3988 /usr/sbin/syslog-ng -F

它正在运行但没有开放端口...

:/etc/syslog-ng$ ss -tunelp | grep 514
s:/etc/syslog-ng$ ss -tunelp
Netid  State      Recv-Q Send-Q                                                      Local Address:Port                                                                     Peer Address:Port
udp    UNCONN     0      0                                                                       *:68                                                                                  *:*                   ino:33007 sk:1 <->
tcp    LISTEN     0      128                                                                     *:22                                                                                  *:*                   ino:33247 sk:2 <->
tcp    LISTEN     0      128                                                                    :::22                                                                                 :::*                   ino:33249 sk:3 v6only:1 <->

我对 rsyslog 也有类似的经历。

UFW 已关闭

:/etc/syslog-ng$ sudo ufw status
Status: inactive

任何帮助将不胜感激

答案1

您必须在日志语句中包含网络源 (s_net),否则它将不会被使用。例如:

destination d_fromnet {file("/var/log/fromnet");};
log {source(s_net); destination(d_fromnet);};

相关内容