尝试设置 Syslog-NG,但根本无法让它监听。我在配置中添加了以下内容:
source s_net {
tcp(ip(0.0.0.0) port(514));
udp(ip(0.0.0.0) port(514));
};
然后我重新启动了服务
:/etc/syslog-ng$ sudo service syslog-ng restart
:/etc/syslog-ng$ sudo systemctl status syslog-ng
● syslog-ng.service - System Logger Daemon
Loaded: loaded (/lib/systemd/system/syslog-ng.service; enabled; vendor preset: enabled)
Active: active (running) since Fri 2019-05-24 13:52:16 UTC; 8s ago
Docs: man:syslog-ng(8)
Main PID: 3988 (syslog-ng)
Tasks: 1
Memory: 1.9M
CPU: 29ms
CGroup: /system.slice/syslog-ng.service
└─3988 /usr/sbin/syslog-ng -F
它正在运行但没有开放端口...
:/etc/syslog-ng$ ss -tunelp | grep 514
s:/etc/syslog-ng$ ss -tunelp
Netid State Recv-Q Send-Q Local Address:Port Peer Address:Port
udp UNCONN 0 0 *:68 *:* ino:33007 sk:1 <->
tcp LISTEN 0 128 *:22 *:* ino:33247 sk:2 <->
tcp LISTEN 0 128 :::22 :::* ino:33249 sk:3 v6only:1 <->
我对 rsyslog 也有类似的经历。
UFW 已关闭
:/etc/syslog-ng$ sudo ufw status
Status: inactive
任何帮助将不胜感激
答案1
您必须在日志语句中包含网络源 (s_net),否则它将不会被使用。例如:
destination d_fromnet {file("/var/log/fromnet");};
log {source(s_net); destination(d_fromnet);};