Re: [gentoo-user] syslog-ng filtering

2010-03-18 Thread Alan McKinnon
On Wednesday 17 March 2010 23:43:39 Ralph Slooten wrote: On 18 March 2010 09:40, Keith Dart ke...@dartworks.biz wrote: You can comment that out and then those annoying run-cron entries won't be logged. Yes, dropping those entries on the client side is an option, however then I have to do

Re: [gentoo-user] syslog-ng filtering

2010-03-17 Thread Fred Leon
Ralph Slooten axll...@gmail.com a écrit : On 17 March 2010 13:00, Roy Wright r...@wright.org wrote: I just started with the example at: http://en.gentoo-wiki.com/wiki/Syslog-ng HTH, Roy Thanks Roy, however they have the same syntax which isn't working on my side. filter f_shorewall { not

Re: [gentoo-user] syslog-ng filtering

2010-03-17 Thread Alan McKinnon
On Wednesday 17 March 2010 01:22:59 Ralph Slooten wrote: Hi all, Has anyone here worked out how to filter out syslog messages using syslog-ng v3? The old syntax doesn't work (well complains bitterly about performance and says to use regex), and no matter what I try I cannot get the new

Re: [gentoo-user] syslog-ng filtering

2010-03-17 Thread Ralph Slooten
Fantastic, you hit the nail right on the head! Works like a charm now. Now I'm wondering how it is you found out that it was this way and not the other? Robert maintains the documentation for rsync which I did look at, but with 225 pages I wasn't able to find this useful piece of information. Man

Re: [gentoo-user] syslog-ng filtering

2010-03-17 Thread Alan McKinnon
On Wednesday 17 March 2010 22:16:20 Ralph Slooten wrote: Fantastic, you hit the nail right on the head! Works like a charm now. Now I'm wondering how it is you found out that it was this way and not the other? Robert maintains the documentation for rsync which I did look at, but with 225

Re: [gentoo-user] syslog-ng filtering

2010-03-17 Thread Keith Dart
=== On Thu, 03/18, Ralph Slooten wrote: === Maybe I'm the idiot here, however I thought that this was a common way of getting rid of unwanted crud from the syslog? === Probably the best method is to not send it there in the first place. For example, the script run by cron,

Re: [gentoo-user] syslog-ng filtering

2010-03-17 Thread Ralph Slooten
On 18 March 2010 09:40, Keith Dart ke...@dartworks.biz wrote: You can comment that out and then those annoying run-cron entries won't be logged. Yes, dropping those entries on the client side is an option, however then I have to do it for each client in the network. Doing it on the server

[gentoo-user] syslog-ng filtering

2010-03-16 Thread Ralph Slooten
Hi all, Has anyone here worked out how to filter out syslog messages using syslog-ng v3? The old syntax doesn't work (well complains bitterly about performance and says to use regex), and no matter what I try I cannot get the new syntax to work :-/ I have a syslog-ng server which logs to MySQL

Re: [gentoo-user] syslog-ng filtering

2010-03-16 Thread Roy Wright
On Mar 16, 2010, at 6:22 PM, Ralph Slooten wrote: Hi all, Has anyone here worked out how to filter out syslog messages using syslog-ng v3? The old syntax doesn't work (well complains bitterly about performance and says to use regex), and no matter what I try I cannot get the new syntax

Re: [gentoo-user] syslog-ng filtering

2010-03-16 Thread Ralph Slooten
On 17 March 2010 13:00, Roy Wright r...@wright.org wrote: I just started with the example at: http://en.gentoo-wiki.com/wiki/Syslog-ng HTH, Roy Thanks Roy, however they have the same syntax which isn't working on my side. filter f_shorewall { not match(regex value(Shorewall)); } I just