Mikrotik Logging, incorrect FROMHOST

This is the place for you, if you got rsyslog up and running but wonder how to make it do what you want.

Moderator: rgerhards

Mikrotik Logging, incorrect FROMHOST

Postby impiouspunk on Sat Aug 30, 2008 12:14 am

I've got rsyslog and phplogcon all up and running but having one small problem.

When logging from my Mikrotik devices, the FROMHOST in syslog messages shows up as "firewall,info" (i'm logging my firewall rules at info severity from my Mikrotik devices).

I need rsyslog to show the IP address and/or hostname. I could even attach a prefix from my mikrotik if rsyslog will show that instead of "firewall/info".

Any help, much appreciated.

Thanks,

Matt
impiouspunk
New
 
Posts: 2
Joined: Sat Aug 30, 2008 12:10 am

Professional Services Information

  • Custom written rsyslog.conf?
  • Maintenance Contract?
  • Installation support?

Re: Mikrotik Logging, incorrect FROMHOST

Postby rgerhards on Mon Sep 01, 2008 7:46 am

Hi Matt,

it looks like the Mikrotik sends invalidly formatted syslog messages. In any case, the "fromhost" property has the name (or IP if it is not reverse-resolvable) address if the network sender. That should help you. Full list of properties is here:

http://www.rsyslog.com/doc-property_replacer.html

HTH
Rainer
User avatar
rgerhards
Site Admin
 
Posts: 1780
Joined: Thu Feb 13, 2003 11:57 am

Re: Mikrotik Logging, incorrect FROMHOST

Postby impiouspunk on Tue Sep 02, 2008 3:42 am

rgerhards wrote:Hi Matt,

it looks like the Mikrotik sends invalidly formatted syslog messages. In any case, the "fromhost" property has the name (or IP if it is not reverse-resolvable) address if the network sender. That should help you. Full list of properties is here:

http://www.rsyslog.com/doc-property_replacer.html

HTH
Rainer



But how can I do that? And I need to do it for JUST mikrotik devices....
impiouspunk
New
 
Posts: 2
Joined: Sat Aug 30, 2008 12:10 am

Re: Mikrotik Logging, incorrect FROMHOST

Postby rgerhards on Tue Sep 02, 2008 7:38 am

Well, you need to filter out the microtik devices(e.g. via their IP address) and write them to the database via a custom template.
User avatar
rgerhards
Site Admin
 
Posts: 1780
Joined: Thu Feb 13, 2003 11:57 am

Re: Mikrotik Logging, incorrect FROMHOST

Postby Znuff on Sat Sep 13, 2008 4:37 am

Did you ever find a solution to this?

I'm having the same issue, unfortunatelly...
Znuff
New
 
Posts: 1
Joined: Sat Sep 13, 2008 4:35 am

Google Ads



Return to Configuration

Who is online

Users browsing this forum: No registered users and 0 guests

cron