suggestion: blocked port logging to other than syslog
Posted: 12 Sep 2013, 17:21
This is really big on my wishlist because it makes syslog monitoring very difficult on a busy system.
Right now to have Port Scan Tracking enabled, you must allow dropped connection logging which can only go to the syslog.
There is no option to log to any other file to reduce syslog clutter and retain port scan monitoring.
Is it just a system limitation that the firewall cannot log anywhere other than syslog?
Or is this possible to have logged elsewhere with monitoring?
Perhaps designating one of the "custom_log" settings?
Thank you as always for considering. CSF really is a brilliant program, keep up the great work.
Right now to have Port Scan Tracking enabled, you must allow dropped connection logging which can only go to the syslog.
There is no option to log to any other file to reduce syslog clutter and retain port scan monitoring.
Is it just a system limitation that the firewall cannot log anywhere other than syslog?
Or is this possible to have logged elsewhere with monitoring?
Perhaps designating one of the "custom_log" settings?
Thank you as always for considering. CSF really is a brilliant program, keep up the great work.