Opened 7 years ago

Closed 5 years ago

Last modified 17 months ago

#6 closed enhancement (fixed)

Ulog or libnetfilter_log support to replace syslog

Reported by: victor Owned by: fredl
Priority: major Milestone: 0.8
Component: suite Version:
Keywords: Cc: fredl@…

Description

Syslog component is hard to setup for many users and a bit redundant because it logs to a file where vuurmuur_log picks it up and after converting, logs it again.

Change History (13)

comment:1 Changed 7 years ago by victor

  • Type changed from defect to enhancement

comment:2 Changed 6 years ago by tigerp

  • Owner changed from victor to tigerp

comment:3 Changed 6 years ago by tigerp

  • Status changed from new to assigned

comment:4 Changed 6 years ago by victor

  • Milestone changed from 0.7 to undecided

comment:5 Changed 5 years ago by victor

  • Milestone changed from undecided to 0.9

comment:6 Changed 5 years ago by fredl

  • Cc fredl@… added

I'm just realizing that the inotify effort I've been putting into vuurmuur_conf for ticket #72 is basically trying to get some control over logfiles vuurmuur already controls! The log viewing of vuurmuur_conf 'tails' the vuurmuur logfiles which are created and controlled by vuurmuur_log. So unless we let some other mechanism like logrotate.d scripts rotate those files we already have full control over our own logfiles.

So I started digging around some more into vuurmuur_log itself and found this ticket which seems quite interesting. I'd like to put some effort into this one too if tigerp agrees.

comment:7 Changed 5 years ago by fredl

  • Owner changed from tigerp to fredl
  • Status changed from assigned to new

comment:8 Changed 5 years ago by fredl

  • Component changed from vuurmuur to suite

comment:9 Changed 5 years ago by fredl

  • Status changed from new to assigned

I've started working on this in the branches/vuurmuur-ulog branch.

comment:10 Changed 5 years ago by fredl

The configuration option works in the ulog branch's 'Vuurmuur Config -> Logging' now. The sample config.conf has examples. If the RULE_NFLOG and NFGRP parameters are not in config.conf, vuurmuur_conf on startup will notify the user and set RULE_NFLOG and NFGRP to their defaults ("Yes" and "8").

comment:11 Changed 5 years ago by fredl

  • Milestone changed from 1.0 to 0.9
  • Resolution set to fixed
  • Status changed from assigned to closed

All the code for this is now in the vuurmuur-ulog branch. This branch should be merged into main after 0.8 has been released.

comment:12 Changed 5 years ago by fredl

I've been thinking on how to document this as it's probably in milestone 0.9 only and with 0.8 not even out the door yet it could be a while before this is available to the general public. I've written an article on http://wordpress.3dn.nl/2009/11/25/iptabes-nflog-support-in-vuurmuur/ but I figured documentation for this should also be here.

comment:13 Changed 17 months ago by victor

  • Milestone changed from 0.9 to 0.8
Note: See TracTickets for help on using tickets.