FreeBSD 7.0-RELEASEВ /etc/rc.conf
syslogd_enable="YES"
syslogd_flags="-vv4Ca 0.0.0.0/0:*"
cat /etc/syslog.conf
# $FreeBSD: src/etc/syslog.conf,v 1.28 2005/03/12 12:31:16 glebius Exp $
#
# Spaces ARE valid field separators in this file. However,
# other *nix-like systems still insist on using tabs as field
# separators. If you are sharing this file between systems, you
# may want to use only tabs as field separators here.
# Consult the syslog.conf(5) manpage.
+192.168.100.110
local2.* /var/log/cisco110.log
+*
*.err;kern.warning;auth.notice;mail.crit /dev/console
*.notice;authpriv.none;kern.debug;lpr.info;mail.crit;news.err /var/log/messages
security.* /var/log/security
auth.info;authpriv.info /var/log/auth.log
mail.info /var/log/maillog
lpr.info /var/log/lpd-errs
ftp.info /var/log/xferlog
cron.* /var/log/cron
*.=debug /var/log/debug.log
*.emerg *
# uncomment this to log all writes to /dev/console to /var/log/console.log
#console.info /var/log/console.log
# uncomment this to enable logging of all log messages to /var/log/all.log
# touch /var/log/all.log and chmod it to mode 600 before it will work
#*.* /var/log/all.log
# uncomment this to enable logging to a remote loghost named loghost
#*.* @loghost
# uncomment these if you're running inn
# news.crit /var/log/news/news.crit
# news.err /var/log/news/news.err
# news.notice /var/log/news/news.notice
!startslip
*.* /var/log/slip.log
!ppp
*.* /var/log/ppp.log
!*
На Cisco 192.168.100.110 есть:
logging trap debugging
logging facility local2
logging 192.168.100.10
В дампе вижу пакеты от неё
IP 192.168.100.110.53965 > 192.168.100.10.514: SYSLOG local2.notice, length: 95
То есть логи приходят.
Порты слушаются:
root syslogd 85821 6 udp4 *:514 *:*
Процесс висит:
ps ax | grep sys
85821 ?? Ss 0:00.00 /usr/sbin/syslogd -vv4Ca 0.0.0.0/0:*
Логов нет. :(((( Хельп.