# syslog-ng configuration issue

**URL:** <https://forums.suse.com/t/syslog-ng-configuration-issue/32214>\
**Category:** SLES Configure-Administer\
**Created:** [March 29, 2018, 5:39pm UTC](https://forums.suse.com/t/syslog-ng-configuration-issue/32214 "2018-03-29T17:39:23Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![cisaksen](https://avatars.discourse-cdn.com/v4/letter/c/49beb7/32.png) [@cisaksen](https://forums.suse.com/u/cisaksen)\
**Post date:** [March 29, 2018, 5:39pm UTC](https://forums.suse.com/t/syslog-ng-configuration-issue/32214/1 "2018-03-29T17:39:23Z")

</div>

I’m trying to setup a syslog-ng server and it’s sort of working. The intent is to receive syslog messages from other servers and sort them on the syslog server based on the incoming IP address of the server/device/appliance that is sending them. So I want a separate log file for each system.

I setup a external source directive in syslog-ng.conf  
source extsrc {  
udp(ip(“X.X.X.X”) port(514));  
};

then I setup 2 files that are included and in the main syslog-ng.conf (verified that they are included properly)  
each have a filter, destination and log directive (in this order)

The destination & log directives appear to be fine. It’s the filter I’m having trouble with in both files.

In each the filter is setup as such  
(DNS lookup is NOT enabled)

filter f\_name { host( or host(""); };

problem I’m having is syslog messages I’m receiving are being written to all the log files not just the one I want it in. It’s as if the filter isn’t even there.

Any help would be great.  
Thanks

---

<div class="post-metadata">

**Author:** ![smflood](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/smflood/32/10576_2.png) [@smflood](https://forums.suse.com/u/smflood)\
**Post date:** [March 29, 2018, 7:21pm UTC](https://forums.suse.com/t/syslog-ng-configuration-issue/32214/2 "2018-03-29T19:21:11Z")

</div>

On 29/03/18 15:44, cisaksen wrote:  
[color=blue]

> I’m trying to setup a syslog-ng server and it’s sort of working. The  
> intent is to receive syslog messages from other servers and sort them on  
> the syslog server based on the incoming IP address of the  
> server/device/appliance that is sending them. So I want a separate log  
> file for each system.
> 
> I setup a external source directive in syslog-ng.conf  
> source extsrc {  
> udp(ip(“X.X.X.X”) port(514));  
> };
> 
> then I setup 2 files that are included and in the main syslog-ng.conf  
> (verified that they are included properly)  
> each have a filter, destination and log directive (in this order)
> 
> The destination & log directives appear to be fine. It’s the filter I’m  
> having trouble with in both files.
> 
> In each the filter is setup as such  
> (DNS lookup is NOT enabled)
> 
> filter f\_name { host( or host(“”); };
> 
> problem I’m having is syslog messages I’m receiving are being written to  
> all the log files not just the one I want it in. It’s as if the filter  
> isn’t even there.[/color]

Please can you clarify the above last paragraph - are the relevant  
syslog messages being written to the separate log files (as required) as  
well as all the other log files?

If so, that would suggest your filtering is working but that you haven’t  
adjusted all the other log statements to \_not\_log if match new filter.

## HTH.

Simon  
SUSE Knowledge Partner

* * *

## If you find this post helpful and are logged into the web interface, please show your appreciation and click on the star below. Thanks.

---

<div class="post-metadata">

**Author:** ![cisaksen](https://avatars.discourse-cdn.com/v4/letter/c/49beb7/32.png) [@cisaksen](https://forums.suse.com/u/cisaksen)\
**Post date:** [March 29, 2018, 7:48pm UTC](https://forums.suse.com/t/syslog-ng-configuration-issue/32214/3 "2018-03-29T19:48:55Z")

</div>

Easiest way would be to write it out.

## File1

filter f\_name1 { host( or host(“”); };  
destination d\_name1 { file(/var/log/name1.log"); };  
log { source(extsrc); destination(d\_name1) filter(f\_name1); };

## File2

filter f\_name2 { host( or host(“”); };  
destination d\_name2 { file(/var/log/name2.log"); };  
log { source(extsrc); destination(d\_name2) filter(f\_name2); };

If a syslog message comes in from ipaddress1 - it gets written to both logs. Now I’m not sure a IP address is usable in a host statement. Seen couple of articles on using netmask but there are some conflicting information regarding a match on ip vs a ip from a subnet.

---

<div class="post-metadata">

**Author:** ![smflood](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/smflood/32/10576_2.png) [@smflood](https://forums.suse.com/u/smflood)\
**Post date:** [March 29, 2018, 8:08pm UTC](https://forums.suse.com/t/syslog-ng-configuration-issue/32214/4 "2018-03-29T20:08:36Z")

</div>

On 29/03/18 17:54, cisaksen wrote:  
[color=blue]

> Easiest way would be to write it out.
> 
> ## File1
> 
> filter f\_name1 { host( or host(“”); };  
> destination d\_name1 { file(/var/log/name1.log"); };  
> log { source(extsrc); destination(d\_name1) filter(f\_name1); };
> 
> ## File2
> 
> filter f\_name2 { host( or host(“”); };  
> destination d\_name2 { file(/var/log/name2.log"); };  
> log { source(extsrc); destination(d\_name2) filter(f\_name2); };
> 
> If a syslog message comes in from ipaddress1 - it gets written to both  
> logs. Now I’m not sure a IP address is usable in a host statement.  
> Seen couple of articles on using netmask but there are some conflicting  
> information regarding a match on ip vs a ip from a subnet.[/color]

To match an IP address try using netmask(a.b.c.d/32) rather than host.

## HTH.

Simon  
SUSE Knowledge Partner

* * *

## If you find this post helpful and are logged into the web interface, please show your appreciation and click on the star below. Thanks.

---

<div class="post-metadata">

**Author:** ![cisaksen](https://avatars.discourse-cdn.com/v4/letter/c/49beb7/32.png) [@cisaksen](https://forums.suse.com/u/cisaksen)\
**Post date:** [March 29, 2018, 8:39pm UTC](https://forums.suse.com/t/syslog-ng-configuration-issue/32214/5 "2018-03-29T20:39:41Z")

</div>

Ok I’ll try that, but I must misunderstand what the filter directive is.

My understanding is that a message must match the filter in order to be written to the specified log file ? Is this not correct ?

---

<div class="post-metadata">

**Author:** ![cisaksen](https://avatars.discourse-cdn.com/v4/letter/c/49beb7/32.png) [@cisaksen](https://forums.suse.com/u/cisaksen)\
**Post date:** [March 29, 2018, 9:19pm UTC](https://forums.suse.com/t/syslog-ng-configuration-issue/32214/6 "2018-03-29T21:19:01Z")

</div>

Ok - now I’m really confused-- I verified that a message must match the filter in order to be written to the specified log file.

Here is what is really interesting, I’m running syslog-ng interactively /usr/sbin/syslog-ng -Fevd per [https://syslog-ng.com/documents/html/syslog-ng-ose-3.6-guides/en/syslog-ng-ose-guide-admin/html/chapter-troubleshooting-syslog-ng.html](https://syslog-ng.com/documents/html/syslog-ng-ose-3.6-guides/en/syslog-ng-ose-guide-admin/html/chapter-troubleshooting-syslog-ng.html)

to troubleshoot and what do I see but that the filters are in fact matching & not-matching respectively, but it is still writing the message to the log file even when it states that is not a match.

[2018-03-29T14:09:43.695449] Initializing destination file writer; template=’/var/log/syslog/name2.log’, filename=’/var/log/syslog/name2.log’  
[2018-03-29T14:09:43.696451] Filter rule evaluation begins; rule=‘f\_name2’, location=’/etc/syslog-ng/conf.d/name2.conf:7:18’  
[2018-03-29T14:09:43.696469] Filter node evaluation result; result=‘not-match’  
[2018-03-29T14:09:43.696478] Filter rule evaluation result; result=‘not-match’, rule=‘f\_name2’, location=’/etc/syslog-ng/conf.d/name2.conf:7:18
