Page MenuHomePhabricator

Write ulogd logs to a dedicated logfile
Open, MediumPublic

Description

Currently ulogd firewall logs go to both /var/log/messages and /var/log/syslog and they can be quite noisy.

It might make sens to have them log to a dedicated file.

Event Timeline

ayounsi triaged this task as Medium priority.Nov 15 2019, 4:27 PM
ayounsi created this task.
Restricted Application added a subscriber: Aklapper. · View Herald TranscriptNov 15 2019, 4:27 PM

This was discussed in T116011 and the code to log to a separate file exists. the Reason for choosing to log to syslog was to simplify shipping logs to kafaka.

Another option could be to tune the logs so they are not so noisy. We could either change the logging frequencies/burst or filter out noise entries like we do for bootp

FWIW I'm ok with doing whichever is easiest, IIRC we can ship to kafka first and then add rules to log to a separate file.