rsyslog에서 hostname 대신에 IP address 로 기록하는 방법
rsyslog를 가지고 로그서버를 구축하고 있습니다.
Jun 18 14:40:23 com20 smartd[4045]: Device: /dev/sdf, opened
Jun 18 14:40:23 com20 smartd[4045]: Device: /dev/sdf, not found in smartd database.
Jun 18 14:40:23 com20 smartd[4045]: Device: /dev/sdf, is SMART capable. Adding to "monitor" list.
Jun 18 14:40:23 com20 smartd[4045]: Monitoring 6 ATA and 0 SCSI devices
Jun 18 14:40:25 com20 smartd[4067]: smartd has fork()ed into background mode. New PID=4067.
Jun 18 14:40:26 com20 pcscd: winscard.c:304:SCardConnect() Reader E-Gate 0 0 Not Found
Jun 18 14:40:26 com20 pcscd:last message repeated 2 times
Jun 18 14:40:26 com20 pcscd: winscard.c:304:SCardConnect() Reader E-Gate 0 0 Not Found
Jun 18 15:06:07 hadmin1 kernel: Kernel logging (proc) stopped.
Jun 18 15:06:07 hadmin1 kernel: Kernel logging (proc) stopped.
Jun 18 15:06:07 hadmin1 kernel: Kernel log daemon terminating.
Jun 18 15:06:07 hadmin1 kernel: Kernel log daemon terminating.
Jun 18 15:06:08 hadmin1 rsyslogd: [origin software="rsyslogd" swVersio
이런식으로 잘 기록이 되고 있는데요. 호스명 대신에(com20, hadmin1) IP address로 남기고 싶은데
관련된 옵션을 찾기 어렵네요.
로그서버의 설정은 아래와 같습니다.
[root@com27 ~]# cat /etc/sysconfig/rsyslog
SYSLOGD_OPTIONS="-m 0 -r -x"
KLOGD_OPTIONS="-x"
[root@com27 ~]# cat /etc/rsyslog.conf
$ModLoad ommysql.so
*.* :ommysql:localhost,디비명,계정,패스워드
*.info;mail.none;authpriv.none;cron.none /var/log/messages
authpriv.* /var/log/secure
mail.* -/var/log/maillog
cron.* /var/log/cron
*.emerg *
uucp,news.crit /var/log/spooler
local7.* /var/log/boot.log
클라이언트 설정
[root@hadmin1 ~]# cat /etc/rsyslog.conf
*.info;mail.none;authpriv.none;cron.none /var/log/messages
*.info;mail.none;authpriv.none;cron.none @1.1.1.1
authpriv.* /var/log/secure
authpriv.* @1.1.1.1
mail.* -/var/log/maillog
cron.* /var/log/cron
*.emerg *
uucp,news.crit /var/log/spooler
local7.* /var/log/boot.log
*.* @1.1.1.1
http://www.rsyslog.com/doc-ma
http://www.rsyslog.com/doc-man_rsyslogd.html
-x 옵션이 찾으시는 그것같은데요.
로그취합 고민중이라... 뭔가싶어서 사이트를 둘러봤는데, 너무 난잡하군요.
OTL
http://kb.monitorware.com/hos
http://kb.monitorware.com/hostname-or-ip-address-t9549.html
이게 도움이 될지 모르겠네요.
------------------------------
How many legs does a dog have?
------------------------------
How many legs does a dog have?
댓글 달기