Re: central logging
[Martin Schulte]
> Now i found a way, how store store information about log-ins on
> tjener.
Very good. :)
> I'm using syslog-ng.
Why syslog-ng? I thought rsyslog was more flexible than syslog-ng?
Why do you need to change the clients? As far as I can see, the
default on the clients are to forward all syslog messages (see
/usr/share/debian-edu-config/rsyslog-client), so all pam_unix auth
messages should already be forwarded.
If the server is configured to store these messages, that could be
done with rsyslog too. If a simple rule to store all auth messages is
not enough, you could filter the messages through a program to pick
the ones you want, using a ^/path/to/program destination.
Happy hacking,
--
Petter Reinholdtsen
Reply to: