rsyslog ignores iptables LOG targets
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
rsyslog (Ubuntu) |
New
|
Undecided
|
Unassigned |
Bug Description
Binary package hint: rsyslog
Ubuntu Karmic 9.10 Beta, rsyslog 4.2.0-2ubuntu4
First rule of the INPUT chain in iptables:
LOG tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:80 LOG flags 0 level 4 prefix `FW_TEST: '
Connection attempts matching that rule don't get logged anywhere; I added a a couple of rules to the default config (attached file) for debugging, still nothing.
Grepping /var/log/* for FW_TEST doesn't find anything; grepping dmesg shows what's expected, e.g.:
[ 7218.452367] FW_TEST: IN=lo OUT= MAC=00:
I did some simple testing. I could make 'contains' work, but not 'startswith'. If you change your config to use 'contains' FW_TEST instead and then do a 'sudo restart rsyslog', do things work? If so, we can change this bug into one about just startswith.