-
Notifications
You must be signed in to change notification settings - Fork 6
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
create own logfile for blocking lines #6
Comments
You don't need to change BlockCountries to write a new logfile. But you do need to change $LOG for the analysis to work if you change the file name or location. The actual log entry is created by the kernel (netfilter). To get output sent to another logfile, you need to configure the syslog daemon on your system. There are a couple of them, depending on your distribution (and your choices). The most basic is
Edit You'll also need to update Finally, you do need to update There's a pretty good general description of how to do this (not BlockCountries -specific) at https://blog.shadypixel.com/log-iptables-messages-to-a-separate-file-with-rsyslog/ Google will turn up other tutorials and other syslogd alternatives. The latest release of BlockCountries allows you to set The values for As a practical matter, only NOTICE or INFORMATIONAL are useful. |
Since I haven't heard from you in a week, I assume you are satisfied. I'm closing this issue. In the future, please indicate whether issues that you raised are addressed satisfactorily and close your issues when they are. Thanks. |
Hi tlhackque,
as far as I can see the current logging goes to:
root@server:~# colortail -f /var/log/messages
==> /var/log/messages <==
Jan 22 11:29:06 server kernel: [3151900.967133] [Blocked CC]: IN=venet0 OUT= MAC= SRC=58.140.209.21 DST=0.0.0.0 LEN=60 TOS=0x00 PREC=0x00 TTL=44 ID=23949 DF PROTO=TCP SPT=37383 DPT=23 WINDOW=5840 RES=0x00 SYN URGP=0
would it be possible to setup a own Logfile into var/log
e.g.
/var/log/blocking.log
so it would be needed to create a new entry for the config file to setup this logging.
I try to modify the Script by changing the $Log
my $LOG = '/var/log/messages*'; # Note: This is a wildcard to handle log rotation. .gz files will decompressed on the fly and processed.
my $LOG = '/var/log/blocking*';
but it still write the Blockings into messages, after restarting the script.
The text was updated successfully, but these errors were encountered: