Syslog help needed step by step

Hi People

i am still learning on OpenWRT and i would like to see what is happening on the firewall as in what is being allowed and what is being blocked.

I think i need a syslog setup.I have tried to set this up but no joy is there a good syslog tutorial out there.

i have a copy of kiwi (solarwinds) to view the logs and to remote log if that helps.

TIA

Do you have an external syslog server set up to send logs for saving to disk?

Its installed as above

LUCI > System > system > logging > [enterip] + [saveandapply]

1 Like

Where do you show it's setup?

You say it doesn't work, actually.

  • Did you open the port on the firewall to the device running Kiwi?
  • Did you allow Kiwi network access in the firewall?

its all on a LAN. PC and the RPI Openwrt router are on the same segment.

:confused: OK...but can you answer my questions, please?

i can put a rule in for udp 161(snmp) and TCP 3300 (syslog) LAN to LAN. but how do you mean kiwi access to the firewall.

this is why i am looking for a step by step walk through to install syslog.

i have had a play with https://openwrt.org/docs/guide-user/perf_and_log/log.syslog-ng3

but not getting any messages on kiwi i have installed

syslog-ng
collectd-mod-syslog
ulogd-mod-syslog

no joy at all

I know...I'm not sure what we're missing in understanding, I'll try to use bullet points:

  • There is no OpenWrt firewall between LAN
  • Open firewall on the machine running Kiwi (i.e. Windows Firewall)

:confused:

  • I'm completely lost why you wish to install syslog on OpenWrt
    • Do you stop using Kiwi?
    • Can you better explain?
  • The software to send logs is working by default on the OpenWrt device - @anon50098793 was kind enough to show you how to set it up above
    • Are you confusing the sending of logs with receiving???

Lleachii

I might be getting confused as you say.

Think i need to back track and reevaluate the situation

2 posts were split to a new topic: How to send OpenWrt logs to elasticsearch?

This topic was automatically closed 10 days after the last reply. New replies are no longer allowed.