[ GORSHTAK @ 17.12.2010. 18:05 ] @
Cilj mi je da cisco logove šaljem CentOS-u u lokalnoj mreži i ne znam da li je zapelo na ciscu ili linuxu.

Do sad šta sam uradio na ciscu:

logging enable
logging timestamp
logging buffer-size 4098
logging console emergencies
logging buffered warnings
logging trap debugging
logging asdm informational
logging host inside 192.168.1.5


I izgled conf fajla

# cat /etc/syslog.conf
# Log all kernel messages to the console.
# Logging much else clutters up the screen.
#kern.* /dev/console

# Log anything (except mail) of level info or higher.
# Don't log private authentication messages!
*.info;mail.none;news.none;authpriv.none;cron.none /var/log/messages

# The authpriv file has restricted access.
authpriv.* /var/log/secure

# Log all the mail messages in one place.
mail.* -/var/log/maillog


# Log cron stuff
cron.* /var/log/cron

# Everybody gets emergency messages
*.emerg *

# Save news errors of level crit and higher in a special file.
uucp,news.crit /var/log/spooler

# Save boot messages also to boot.log
local7.* /var/log/boot.log

#
# INN
#
news.=crit /var/log/news/news.crit
news.=err /var/log/news/news.err
news.notice /var/log/news/news.notice


Da li je još nešto potrebno da se definiše? ACL, nešto u linuxu ......
[ GORSHTAK @ 18.12.2010. 10:01 ] @
Rešeno, u /etc/sysconfig/syslog treba da postoji linija SYSLOGD_OPTIONS="-m 0 -r" da bi omogućio logovanje sa drugih servera