Forum Discussion
BIG-IP send all syslog messages as local5 facility
Hello Devs!
Our client wants every syslog message sent by the BIG-IP to be on local5 facility. I understand that this is not the behavior of syslog-ng. But is it possible? I tinkered around the syslog options and could not find this option, not even on the CLI (we are running v15.1.0.5).
They're trying to emulate a Netscaler config
add audit syslogAction AUDIT_SRV_SYSLOG 1.2.3.4 -logLevel EMERGENCY ALERT CRITICAL ERROR WARNING NOTICE -dateFormat DDMMYYYY -logFacility LOCAL5 -timeZone LOCAL_TIME
This config sends all the messages to syslog server 1.2.3.4 as local5.
Thanks, Rafael.
i dont believe this is easily possible. the BIG-IP uses many different facility values itself by default, so changing those will confuse system that asume the default ones.
you might be able to overwrite something by tinkering in the syslog-ng.conf but i wouldnt advise that.
i assume you want this to recognize the logging better on the syslog server? isn't that possible on source IP or such?
- rafaelbnCirrostratus
Hey boneyard! How's it going my friend? Thank you for your reply.
I thought the same as you. I would have to tinker with the syslog-ng and I could very easily break something and I also advised our client against it.
They use some very old syslog solution and designed that way. For now I said that it would not be possible. Let's see if they upgrade that legacy solution to a better one.
Thanks for your time, Rafael.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com