<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: Force iptables to log messages to a different log file</title> <atom:link href="http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html/feed" rel="self" type="application/rss+xml" /><link>http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html</link> <description>This is a Linux sys admin journal by Vivek about sys admin work, Linux tips &#38; tricks, hacks, news and more.</description> <lastBuildDate>Fri, 10 Feb 2012 20:37:43 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>By: awoms</title><link>http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-178048</link> <dc:creator>awoms</dc:creator> <pubDate>Thu, 05 Jan 2012 15:18:45 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-178048</guid> <description>Everything is working great, thank you.
How do I set up the new /var/log/iptables.log file to archive/create new files when it grows to a certain size?...</description> <content:encoded><![CDATA[<p>Everything is working great, thank you.</p><p>How do I set up the new /var/log/iptables.log file to archive/create new files when it grows to a certain size?&#8230;</p> ]]></content:encoded> </item> <item><title>By: Akash</title><link>http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-175749</link> <dc:creator>Akash</dc:creator> <pubDate>Sat, 19 Nov 2011 11:49:00 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-175749</guid> <description>It help me to clear.. LOG basics concept
Thanks</description> <content:encoded><![CDATA[<p>It help me to clear.. LOG basics concept<br
/> Thanks</p> ]]></content:encoded> </item> <item><title>By: Aly</title><link>http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-156641</link> <dc:creator>Aly</dc:creator> <pubDate>Wed, 16 Jun 2010 15:45:26 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-156641</guid> <description>I know this is an old post, but thanks this worked perfectly.</description> <content:encoded><![CDATA[<p>I know this is an old post, but thanks this worked perfectly.</p> ]]></content:encoded> </item> <item><title>By: jamie</title><link>http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-155499</link> <dc:creator>jamie</dc:creator> <pubDate>Sun, 02 May 2010 09:08:22 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-155499</guid> <description>looks like in ubuntu 10.04, the file is now at /etc/rsyslog.d/50-default.conf
at least i think it is.</description> <content:encoded><![CDATA[<p>looks like in ubuntu 10.04, the file is now at /etc/rsyslog.d/50-default.conf</p><p>at least i think it is.</p> ]]></content:encoded> </item> <item><title>By: Roberto_Dominicano</title><link>http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-153211</link> <dc:creator>Roberto_Dominicano</dc:creator> <pubDate>Thu, 28 Jan 2010 16:31:10 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-153211</guid> <description>Sound interesting.
But I have a question?  And if I would like to filtering mac address limiting the upload and download for any particular  mac address?
How I can do that?
Thanks</description> <content:encoded><![CDATA[<p>Sound interesting.<br
/> But I have a question?  And if I would like to filtering mac address limiting the upload and download for any particular  mac address?<br
/> How I can do that?</p><p>Thanks</p> ]]></content:encoded> </item> <item><title>By: Paul G</title><link>http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-152444</link> <dc:creator>Paul G</dc:creator> <pubDate>Wed, 23 Dec 2009 20:47:47 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-152444</guid> <description>In order to filter firewall logs from /var/log/messages use the below (in previous examples, &quot;=&quot; (equal sign) was used, but it is not working on RHEL for example.
kern.warning                                            /var/log/iptables.log
*.info;kern.!warning;mail.none;authpriv.none;cron.none          /var/log/messages</description> <content:encoded><![CDATA[<p>In order to filter firewall logs from /var/log/messages use the below (in previous examples, &#8220;=&#8221; (equal sign) was used, but it is not working on RHEL for example.</p><p>kern.warning                                            /var/log/iptables.log<br
/> *.info;kern.!warning;mail.none;authpriv.none;cron.none          /var/log/messages</p> ]]></content:encoded> </item> <item><title>By: Al B..</title><link>http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-152311</link> <dc:creator>Al B..</dc:creator> <pubDate>Tue, 15 Dec 2009 19:58:10 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-152311</guid> <description>for ubuntu 9.10 users edit /etc/rsyslog.d/50-default.conf and dont forget to remove *.=warn part otherwise it will still write to var/log/messages. If anyone has a better method please suggest..</description> <content:encoded><![CDATA[<p>for ubuntu 9.10 users edit /etc/rsyslog.d/50-default.conf and dont forget to remove *.=warn part otherwise it will still write to var/log/messages. If anyone has a better method please suggest..</p> ]]></content:encoded> </item> <item><title>By: Prem</title><link>http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-150748</link> <dc:creator>Prem</dc:creator> <pubDate>Tue, 22 Sep 2009 06:39:42 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-150748</guid> <description>Hi ,
I want to know is it possible to log 5 packets for every 2 minutes if it is possible may i know the command.
Thanks in advance...</description> <content:encoded><![CDATA[<p>Hi ,<br
/> I want to know is it possible to log 5 packets for every 2 minutes if it is possible may i know the command.<br
/> Thanks in advance&#8230;</p> ]]></content:encoded> </item> <item><title>By: Ammad</title><link>http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-150718</link> <dc:creator>Ammad</dc:creator> <pubDate>Sat, 19 Sep 2009 14:50:21 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-150718</guid> <description>can i have a iptables logs on web page. i have installed &quot;Iptables log analyzer 0.4 beta&quot; but i think its for suse only and it doesn&#039;t put logs to mysql db as it should do according to documentation.</description> <content:encoded><![CDATA[<p>can i have a iptables logs on web page. i have installed &#8220;Iptables log analyzer 0.4 beta&#8221; but i think its for suse only and it doesn&#8217;t put logs to mysql db as it should do according to documentation.</p> ]]></content:encoded> </item> <item><title>By: Prem</title><link>http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-150716</link> <dc:creator>Prem</dc:creator> <pubDate>Sat, 19 Sep 2009 10:10:56 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-150716</guid> <description>Hi
i have configured 2 log files
1.) iptable.log 2.)iptable1.log
i want to write monitor or write log for an ip say 64.55.11.2 in iptable.log and another ip say 202.20.10.80 in iptable1.log is that possible and how to do this?. Thanks in advance...</description> <content:encoded><![CDATA[<p>Hi<br
/> i have configured 2 log files<br
/> 1.) iptable.log 2.)iptable1.log</p><p>i want to write monitor or write log for an ip say 64.55.11.2 in iptable.log and another ip say 202.20.10.80 in iptable1.log is that possible and how to do this?. Thanks in advance&#8230;</p> ]]></content:encoded> </item> <item><title>By: Ammad</title><link>http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-150514</link> <dc:creator>Ammad</dc:creator> <pubDate>Fri, 04 Sep 2009 09:50:47 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-150514</guid> <description>HI,
its cool, but for addition how do i get hostnames/FQDN of local nodes instead of IP address. i have dns on firewall system for all dynamic dhcp nodes. since logs are useful to get history of nodes, and all nodes are getting ip from dhcp. and this registers ip address to dns server.
thanks.</description> <content:encoded><![CDATA[<p>HI,<br
/> its cool, but for addition how do i get hostnames/FQDN of local nodes instead of IP address. i have dns on firewall system for all dynamic dhcp nodes. since logs are useful to get history of nodes, and all nodes are getting ip from dhcp. and this registers ip address to dns server.</p><p>thanks.</p> ]]></content:encoded> </item> <item><title>By: ds</title><link>http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-149827</link> <dc:creator>ds</dc:creator> <pubDate>Sun, 02 Aug 2009 11:44:11 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-149827</guid> <description>Thanks for this clear guide</description> <content:encoded><![CDATA[<p>Thanks for this clear guide</p> ]]></content:encoded> </item> <item><title>By: dejf</title><link>http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-149602</link> <dc:creator>dejf</dc:creator> <pubDate>Mon, 20 Jul 2009 20:20:49 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-149602</guid> <description>This is just absurd. Loglevel is not meant to differe services, you should use filters or facility instead, syslog-ng makes things a bit easier.</description> <content:encoded><![CDATA[<p>This is just absurd. Loglevel is not meant to differe services, you should use filters or facility instead, syslog-ng makes things a bit easier.</p> ]]></content:encoded> </item> <item><title>By: kris</title><link>http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-149514</link> <dc:creator>kris</dc:creator> <pubDate>Thu, 16 Jul 2009 10:44:52 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-149514</guid> <description>Or you can use ulog.
Install ulogd (in ubuntu: sudo apt-get install ulogd)
If you use fwbuilder to configure your firewall then it&#039;s simple.
In fwbuilder, double click on your firewall --&gt; Firewall Settings --&gt; Logging --&gt; use ULOG
then compile and reinstall the policy and that&#039;s it.
The logs from iptables will be in /var/log/ulog/syslogemu.log</description> <content:encoded><![CDATA[<p>Or you can use ulog.<br
/> Install ulogd (in ubuntu: sudo apt-get install ulogd)</p><p>If you use fwbuilder to configure your firewall then it&#8217;s simple.<br
/> In fwbuilder, double click on your firewall &#8211;&gt; Firewall Settings &#8211;&gt; Logging &#8211;&gt; use ULOG</p><p>then compile and reinstall the policy and that&#8217;s it.<br
/> The logs from iptables will be in /var/log/ulog/syslogemu.log</p> ]]></content:encoded> </item> <item><title>By: Marshall</title><link>http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-148923</link> <dc:creator>Marshall</dc:creator> <pubDate>Thu, 11 Jun 2009 20:25:46 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-148923</guid> <description>Tawfiq: You can disable the console logging by commenting out this line in your syslog.conf
&lt;code&gt;#kern.*                                                 /dev/console&lt;/code&gt;</description> <content:encoded><![CDATA[<p>Tawfiq: You can disable the console logging by commenting out this line in your syslog.conf</p><p><code>#kern.*                                                 /dev/console</code></p> ]]></content:encoded> </item> <item><title>By: Tawfiq</title><link>http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-148596</link> <dc:creator>Tawfiq</dc:creator> <pubDate>Mon, 18 May 2009 05:59:39 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-148596</guid> <description>sorry, it itself created the file (iptables.log)
but it also kept dumping on the active konsole.
any idea?</description> <content:encoded><![CDATA[<p>sorry, it itself created the file (iptables.log)<br
/> but it also kept dumping on the active konsole.<br
/> any idea?</p> ]]></content:encoded> </item> <item><title>By: Tawfiq</title><link>http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-148595</link> <dc:creator>Tawfiq</dc:creator> <pubDate>Mon, 18 May 2009 05:55:03 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-148595</guid> <description>Don&#039;t know if you guys had it, but i added that line is syslog.conf . then restarted it.
added those lines in iptables then restarted it.
the iptables log starts dumping on the active console.
I had to log in rescue mode and undo the stuffs.
may be cause i didn&#039;t have the file /var/log/iptables ?
later today, i will try touch the file and redo the whole thing.
any alternate suggestions?</description> <content:encoded><![CDATA[<p>Don&#8217;t know if you guys had it, but i added that line is syslog.conf . then restarted it.<br
/> added those lines in iptables then restarted it.<br
/> the iptables log starts dumping on the active console.<br
/> I had to log in rescue mode and undo the stuffs.<br
/> may be cause i didn&#8217;t have the file /var/log/iptables ?<br
/> later today, i will try touch the file and redo the whole thing.</p><p>any alternate suggestions?</p> ]]></content:encoded> </item> <item><title>By: pedro</title><link>http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-147783</link> <dc:creator>pedro</dc:creator> <pubDate>Sun, 22 Mar 2009 04:23:29 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-147783</guid> <description>Mario:
don&#039;t need to mock Paul like that... I feel for him and his frustration in getting &quot;there&quot; as well as I do for myself many times.
Routines are there for something, we all hope that it is to make your life easier... but if in order to put the routines at your service you have to put yourself in the shoes of the programmer all the time (for the same ammount of time) then there is no point... and it really gets to you... Its indeed a proper critic in the linux scene.
Now, we don&#039;t need to immediately go to the other side of fence, even the best intended, most researchful guy out there gets some scratches jumping the fence.
Neither autoshit from MS nor ultimate control from some pseudo-eleet.
Linux diversity lacks in sinthesys!
Respect kid.</description> <content:encoded><![CDATA[<p>Mario:</p><p>don&#8217;t need to mock Paul like that&#8230; I feel for him and his frustration in getting &#8220;there&#8221; as well as I do for myself many times.<br
/> Routines are there for something, we all hope that it is to make your life easier&#8230; but if in order to put the routines at your service you have to put yourself in the shoes of the programmer all the time (for the same ammount of time) then there is no point&#8230; and it really gets to you&#8230; Its indeed a proper critic in the linux scene.<br
/> Now, we don&#8217;t need to immediately go to the other side of fence, even the best intended, most researchful guy out there gets some scratches jumping the fence.<br
/> Neither autoshit from MS nor ultimate control from some pseudo-eleet.<br
/> Linux diversity lacks in sinthesys!</p><p>Respect kid.</p> ]]></content:encoded> </item> <item><title>By: jon</title><link>http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-147400</link> <dc:creator>jon</dc:creator> <pubDate>Mon, 23 Feb 2009 22:11:18 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-147400</guid> <description>in general, this worked fine for me, even though i used the log-levels names instead of numbers.
after i had everything set-up, the settings didnt seem to have any effect until i noticed i had
to explicitly restart the kernel log daemon (/etc/init.d/klogd restart). i dont know if this is true for any other distributions than debian, which i&#039;m running.
a nice documentation of the predefined iptables targets, such as LOG, can be found here:
http://www.faqs.org/docs/iptables/targets.html
under 6.5.4. LOG target, the topic discussed here is also explained another time for the --log-level option</description> <content:encoded><![CDATA[<p>in general, this worked fine for me, even though i used the log-levels names instead of numbers.<br
/> after i had everything set-up, the settings didnt seem to have any effect until i noticed i had<br
/> to explicitly restart the kernel log daemon (/etc/init.d/klogd restart). i dont know if this is true for any other distributions than debian, which i&#8217;m running.<br
/> a nice documentation of the predefined iptables targets, such as LOG, can be found here:<br
/> <a
href="http://www.faqs.org/docs/iptables/targets.html" rel="nofollow">http://www.faqs.org/docs/iptables/targets.html</a><br
/> under 6.5.4. LOG target, the topic discussed here is also explained another time for the &#8211;log-level option</p> ]]></content:encoded> </item> <item><title>By: kaxa</title><link>http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-144773</link> <dc:creator>kaxa</dc:creator> <pubDate>Tue, 26 Aug 2008 09:52:23 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/tips/force-iptables-to-log-messages-to-a-different-log-file.html#comment-144773</guid> <description>10x Vivek Gite</description> <content:encoded><![CDATA[<p>10x Vivek Gite</p> ]]></content:encoded> </item> </channel> </rss>
