<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Log iptables Messages to a Separate File with rsyslog</title>
	<atom:link href="http://blog.shadypixel.com/log-iptables-messages-to-a-separate-file-with-rsyslog/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.shadypixel.com/log-iptables-messages-to-a-separate-file-with-rsyslog/</link>
	<description>tech, politics, etc.</description>
	<lastBuildDate>Mon, 30 Jan 2012 20:31:47 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.2</generator>
	<item>
		<title>By: the sign of four pdf</title>
		<link>http://blog.shadypixel.com/log-iptables-messages-to-a-separate-file-with-rsyslog/#comment-22025</link>
		<dc:creator>the sign of four pdf</dc:creator>
		<pubDate>Fri, 13 Jan 2012 09:30:24 +0000</pubDate>
		<guid isPermaLink="false">http://blog.shadypixel.com/?p=269#comment-22025</guid>
		<description>&lt;strong&gt;the sign of four pdf...&lt;/strong&gt;

[...]Log iptables Messages to a Separate File with rsyslog &#124; Random Bits[...]...</description>
		<content:encoded><![CDATA[<p><strong>the sign of four pdf&#8230;</strong></p>
<p>[...]Log iptables Messages to a Separate File with rsyslog | Random Bits[...]&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sb</title>
		<link>http://blog.shadypixel.com/log-iptables-messages-to-a-separate-file-with-rsyslog/#comment-15697</link>
		<dc:creator>sb</dc:creator>
		<pubDate>Fri, 07 Oct 2011 05:23:43 +0000</pubDate>
		<guid isPermaLink="false">http://blog.shadypixel.com/?p=269#comment-15697</guid>
		<description>Hi,

Thanks for a good and helpful tutorial.

I&#039;ve got one question I was hoping you might be able to answer. I keep getting error messages when i use filters, and I am wondering wether it can be due to a module not being loaded.

Did you load specific modules before implementing the filtering?</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>Thanks for a good and helpful tutorial.</p>
<p>I&#8217;ve got one question I was hoping you might be able to answer. I keep getting error messages when i use filters, and I am wondering wether it can be due to a module not being loaded.</p>
<p>Did you load specific modules before implementing the filtering?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Smith</title>
		<link>http://blog.shadypixel.com/log-iptables-messages-to-a-separate-file-with-rsyslog/#comment-14621</link>
		<dc:creator>John Smith</dc:creator>
		<pubDate>Mon, 05 Sep 2011 16:55:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.shadypixel.com/?p=269#comment-14621</guid>
		<description>Try &quot;dmesg -n5&quot;</description>
		<content:encoded><![CDATA[<p>Try &#8220;dmesg -n5&#8243;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: iptables loglarını farklı dosyaya ayrıştırma senaryosu - Murat Özalp</title>
		<link>http://blog.shadypixel.com/log-iptables-messages-to-a-separate-file-with-rsyslog/#comment-13469</link>
		<dc:creator>iptables loglarını farklı dosyaya ayrıştırma senaryosu - Murat Özalp</dc:creator>
		<pubDate>Fri, 22 Jul 2011 10:09:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.shadypixel.com/?p=269#comment-13469</guid>
		<description>[...] kaynak: http://blog.shadypixel.com/log-iptables-messages-to-a-separate-file-with-rsyslog/      Linux, Sunucu iptables, Linux, logrotate, rsyslog, [...]</description>
		<content:encoded><![CDATA[<p>[...] kaynak: <a href="http://blog.shadypixel.com/log-iptables-messages-to-a-separate-file-with-rsyslog/" rel="nofollow">http://blog.shadypixel.com/log-iptables-messages-to-a-separate-file-with-rsyslog/</a>      Linux, Sunucu iptables, Linux, logrotate, rsyslog, [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Сексшоп, интим магазин</title>
		<link>http://blog.shadypixel.com/log-iptables-messages-to-a-separate-file-with-rsyslog/#comment-12501</link>
		<dc:creator>Сексшоп, интим магазин</dc:creator>
		<pubDate>Sun, 19 Jun 2011 04:22:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.shadypixel.com/?p=269#comment-12501</guid>
		<description>&lt;a href=&quot;http://www.uralintim.ru&quot; rel=&quot;nofollow&quot;&gt;&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p><a href="http://www.uralintim.ru" rel="nofollow"></a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WoLf</title>
		<link>http://blog.shadypixel.com/log-iptables-messages-to-a-separate-file-with-rsyslog/#comment-10448</link>
		<dc:creator>WoLf</dc:creator>
		<pubDate>Tue, 22 Mar 2011 17:07:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.shadypixel.com/?p=269#comment-10448</guid>
		<description>You might want to add a number to the conf file in rsyslog.d and have it load before the other rules.
in example /etc/rsyslog.d/30-iptables.conf is a safe guess for basic ubuntu systems.</description>
		<content:encoded><![CDATA[<p>You might want to add a number to the conf file in rsyslog.d and have it load before the other rules.<br />
in example /etc/rsyslog.d/30-iptables.conf is a safe guess for basic ubuntu systems.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Log iptables Messages to a Separate File with rsyslog</title>
		<link>http://blog.shadypixel.com/log-iptables-messages-to-a-separate-file-with-rsyslog/#comment-8666</link>
		<dc:creator>Log iptables Messages to a Separate File with rsyslog</dc:creator>
		<pubDate>Fri, 14 Jan 2011 21:01:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.shadypixel.com/?p=269#comment-8666</guid>
		<description>[...] to original source: http://blog.shadypixel.com/log-iptables-messages-to-a-separate-file-with-rsyslog/      Cancel [...]</description>
		<content:encoded><![CDATA[<p>[...] to original source: <a href="http://blog.shadypixel.com/log-iptables-messages-to-a-separate-file-with-rsyslog/" rel="nofollow">http://blog.shadypixel.com/log-iptables-messages-to-a-separate-file-with-rsyslog/</a>      Cancel [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: R Duke</title>
		<link>http://blog.shadypixel.com/log-iptables-messages-to-a-separate-file-with-rsyslog/#comment-8017</link>
		<dc:creator>R Duke</dc:creator>
		<pubDate>Mon, 13 Dec 2010 14:57:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.shadypixel.com/?p=269#comment-8017</guid>
		<description>Thanks for this nice tip. I also had the timestamp problem, so now I have added a regex rule:

  :msg, startswith, &quot;ipt: &quot;                       -/var/log/iptables.log
  &amp; ~
  :msg, regex,      &quot;^\[ *[0-9]*\.[0-9]*\] ipt: &quot; -/var/log/iptables.log
  &amp; ~


However, the messages still also go to dmesg (the command). Would like to remove them from there as well.</description>
		<content:encoded><![CDATA[<p>Thanks for this nice tip. I also had the timestamp problem, so now I have added a regex rule:</p>
<p>  :msg, startswith, &#8220;ipt: &#8221;                       -/var/log/iptables.log<br />
  &amp; ~<br />
  :msg, regex,      &#8220;^\[ *[0-9]*\.[0-9]*\] ipt: &#8221; -/var/log/iptables.log<br />
  &amp; ~</p>
<p>However, the messages still also go to dmesg (the command). Would like to remove them from there as well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: btmorex</title>
		<link>http://blog.shadypixel.com/log-iptables-messages-to-a-separate-file-with-rsyslog/#comment-3443</link>
		<dc:creator>btmorex</dc:creator>
		<pubDate>Sun, 08 Nov 2009 21:14:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.shadypixel.com/?p=269#comment-3443</guid>
		<description>The advantage of rsyslog is that you&#039;re probably already using it and you can&#039;t really run a linux system with out some sort of syslog daemon. ulogd might make sense on a dedicated firewall, but it&#039;s sort of ridiculous to have to run a completely separate daemon just to log iptables on a workstation.</description>
		<content:encoded><![CDATA[<p>The advantage of rsyslog is that you&#8217;re probably already using it and you can&#8217;t really run a linux system with out some sort of syslog daemon. ulogd might make sense on a dedicated firewall, but it&#8217;s sort of ridiculous to have to run a completely separate daemon just to log iptables on a workstation.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://blog.shadypixel.com/log-iptables-messages-to-a-separate-file-with-rsyslog/#comment-3441</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Sun, 08 Nov 2009 17:42:24 +0000</pubDate>
		<guid isPermaLink="false">http://blog.shadypixel.com/?p=269#comment-3441</guid>
		<description>Or you could skip rsyslog all together, and use ULOGD and the ULOG target.  More flexibility this way - send the logs to a file, or a database.  No issues with filtering, and you can use as many prefixes as you want without having to reconfigure rsyslog.</description>
		<content:encoded><![CDATA[<p>Or you could skip rsyslog all together, and use ULOGD and the ULOG target.  More flexibility this way &#8211; send the logs to a file, or a database.  No issues with filtering, and you can use as many prefixes as you want without having to reconfigure rsyslog.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

