Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Syslog facilities #59

Open
qriff opened this issue Aug 9, 2018 · 4 comments
Open

Syslog facilities #59

qriff opened this issue Aug 9, 2018 · 4 comments

Comments

@qriff
Copy link

qriff commented Aug 9, 2018

Seems there is a difference between syslog remote, local and to file. REMOTE declares levels and is forced with facilities, LOCAL seems to disregard it all and just dumps it raw like FILE.

Aug  9 09:22:38 Servername Artillery has blocked (blacklisted) the following IP for SSH brute forcing violations: 195.xxx.xxx.102

Aug  9 09:22:38 Servername Artillery has blocked (blacklisted) the following IP for SSH brute forcing violations: 195.xxx.xxx.102

Aug  9 09:22:38 Servername Artillery has blocked (blacklisted) the following IP for SSH brute forcing violations: 195.xxx.xxx.102

...

vs

Aug  9 09:22:38 Servername artillery/brute[4348] Blocked (blacklisted) the following IP for SSH brute forcing violations: 195.xxx.xxx.102

Aug  9 09:22:38 Servername artillery/brute[4348] Blocked (blacklisted) the following IP for SSH brute forcing violations: 195.xxx.xxx.102

Aug  9 09:22:38 Servername artillery/brute[4348] Blocked (blacklisted) the following IP for SSH brute forcing violations: 195.xxx.xxx.102

...

There is also the repetition of messages...

@russhaun
Copy link

russhaun commented Aug 9, 2018

from the config file on line 124-125
Specify SYSLOG TYPE to be local, file or remote. LOCAL will pipe to syslog, REMOTE will pipe to remote SYSLOG, and file will send to alerts.log in local artillery directory.

I think this is expected behavior on linux. (someone please correct me if i am wrong) like i said before i am a windows guy by practice so just give me some time. i will look into duplicate issue for you.

@oldkingcone
Copy link

Thats how it works @russhaun, at least thats how it has worked for me, results may vary.

@qriff
Copy link
Author

qriff commented Aug 10, 2018

@russhaun
Copy link

hey @qriff check out the latest release your issue might be resolved

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants