From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from pigeon.gentoo.org ([208.92.234.80] helo=lists.gentoo.org) by finch.gentoo.org with esmtp (Exim 4.60) (envelope-from ) id 1NrggN-0002Qi-Rz for garchives@archives.gentoo.org; Wed, 17 Mar 2010 00:00:20 +0000 Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id 41858E0817; Tue, 16 Mar 2010 23:59:25 +0000 (UTC) Received: from smtprelay.hostedemail.com (smtprelay0049.hostedemail.com [216.40.44.49]) by pigeon.gentoo.org (Postfix) with ESMTP id 25CD0E0817 for ; Tue, 16 Mar 2010 23:59:25 +0000 (UTC) Received: from filter.hostedemail.com (ff-bigip1 [10.5.19.254]) by smtprelay02.hostedemail.com (Postfix) with SMTP id DA3F819355BA for ; Tue, 16 Mar 2010 23:59:24 +0000 (UTC) X-Panda: scanned! X-Session-Marker: 726F79407772696768742E6F7267 X-Filterd-Recvd-Size: 1418 Received: from royw-macbook.wright.local (unknown [209.112.224.122]) (Authenticated sender: roy@wright.org) by omf04.hostedemail.com (Postfix) with ESMTP for ; Tue, 16 Mar 2010 23:59:24 +0000 (UTC) Content-Type: text/plain; charset=us-ascii Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-user@lists.gentoo.org Reply-to: gentoo-user@lists.gentoo.org Mime-Version: 1.0 (Apple Message framework v1077) Subject: Re: [gentoo-user] syslog-ng filtering From: Roy Wright In-Reply-To: <17bd4e851003161622x21b7e78chc228017250c7ff0f@mail.gmail.com> Date: Tue, 16 Mar 2010 19:00:49 -0500 Content-Transfer-Encoding: quoted-printable Message-Id: <06BE1C10-57F5-4568-9190-AC4A718F4034@wright.org> References: <17bd4e851003161622x21b7e78chc228017250c7ff0f@mail.gmail.com> To: gentoo-user@lists.gentoo.org X-Mailer: Apple Mail (2.1077) X-Archives-Salt: 968c34fb-5b1d-41de-b2f9-6602fcb6d7f0 X-Archives-Hash: 316a26598be0bf6472124f22f63a1152 On Mar 16, 2010, at 6:22 PM, Ralph Slooten wrote: > Hi all, >=20 > Has anyone here worked out how to filter out syslog messages using = syslog-ng v3? The old syntax doesn't work (well complains bitterly about = performance and says to use regex), and no matter what I try I cannot = get the new syntax to work :-/ I have a syslog-ng server which logs to = MySQL for multiple clients in a network, however the database just keeps = growing with irrelevant data I'd prefer to just quietly ignore on the = server side.=20 >=20 I just started with the example at: http://en.gentoo-wiki.com/wiki/Syslog-ng HTH, Roy