From: Andrey C. <che...@np...> - 2024-09-19 09:43:30
|
Hi Yannik, Thank you for your prompt and insightful response. I’ll be testing the custom syslog configuration in my lab shortly. As for the pull request, since I'm not entirely sure how to resolve the issue, I believe it leans more toward a bug report. Therefore, I've gone ahead and created one here: https://github.com/inverse-inc/packetfence/issues/8316 -- Andrey Chernyakov Senior Network and Security Engineer email: che...@np... NPS Consult S.A. L-5687, Dalheim Luxembourg On 18 Sep 2024 at 12:52 +0200, Yannik Sembritzki via PacketFence-users <pac...@li...>, wrote: > Hi Andrey, > > I guess you could completely create your own rsyslog config by putting it in a different file (/etc/rsyslog.d/my-custom-syslog.conf). > > Apart from this, extending the the syslogtag field length seems like something that should be fixed in upstream. Could you open a PR for this? > Perhaps the SYSLOG.ident field can be added in upstream too, if it makes sense. I don't know what that contains - googling "rsyslog syslog.ident" did not yield any useful results. > > Best regards > Yannik > > On 18.09.24 10:50, Andrey Chernyakov via PacketFence-users wrote: > > Hello PacketFence community, > > > > I am currently configuring rsyslog on a server running PacketFence to forward log messages with a custom template that extends the syslogtag to 64 characters and adds a SYSLOG.ident field. The configuration works fine, but every time I restart the rsyslog service, my custom configuration gets overridden. > > > > Details: > > > > • PacketFence Version: 13.1 > > • OS: Debian 11 (deployed from PacketFence ZEN appliance image) > > • Rsyslog Configuration: I'm using a custom template in /etc/rsyslog.d/packetfence.conf that looks like this: > > > > $template ForwardedMessageTemplate,"%timegenerated% %HOSTNAME% SYSLOG.ident %syslogtag:1:64%%msg%\n" > > @@192.168.1.100:514;ForwardedMessageTemplate > > > > • Issue: After restarting rsyslog, the custom configuration is replaced, and the default settings are applied. Is there a recommended approach for preserving rsyslog configurations across service restarts in a PacketFence setup? > > > > By default, the syslogtag message is limited to 32 characters. This limitation is evident in log entries such as: > > > > • api-frontend-docker-wrapper[1587 > > • radiusd-load-balancer-docker-wra > > > > > > I'd appreciate any insights or best practices from the community. > > Thanks in advance! > > > > <jokVw0kJDUYhn8bX.png> > > > > -- > > Andrey Chernyakov > > Senior Network and Security Engineer > > > > email: che...@np... > > phone: (+352) 621260657 > > > > NPS Consult S.A. > > L-5687, Dalheim > > Luxembourg > > > > > > _______________________________________________ > > PacketFence-users mailing list > > Pac...@li... > > https://lists.sourceforge.net/lists/listinfo/packetfence-users > > _______________________________________________ > PacketFence-users mailing list > Pac...@li... > https://lists.sourceforge.net/lists/listinfo/packetfence-users |