Rsyslog – prevent local host logging twice

I’ve enabled remote logging in my rsyslog.conf with:

# provides UDP syslog reception
module(load="imudp")
input(type="imudp" port="514")

and then in /etc/rsyslog.d/devices.conf, I have

$template RemoteLogs,"/var/log/devices/%HOSTNAME%.log" 
*.*  ?RemoteLogs

I’m finding though that the local machine (the rsyslog server) is logging its events not just to the relevant /var/log/filename but also /etc/log/devices/pi.log

How do i prevent the logs in /etc/log/devices/ for the local host (called pi) please?

Thanks

Answers:

Thank you for visiting the Q&A section on Magenaut. Please note that all the answers may not help you solve the issue immediately. So please treat them as advisements. If you found the post helpful (or not), leave a comment & I’ll get back to you as soon as possible.

Method 1

When specifying the input, also say which ruleset to apply. Input outside the ruleset will not be processed by the ruleset, and vice-versa.

module(load="imudp")
input(type="imudp" port="514" ruleset="remote")
ruleset(name="remote"){
 $template RemoteLogs,"/var/log/devices/%HOSTNAME%.log" 
 *.*  ?RemoteLogs
}


All methods was sourced from stackoverflow.com or stackexchange.com, is licensed under cc by-sa 2.5, cc by-sa 3.0 and cc by-sa 4.0

0 0 votes
Article Rating
Subscribe
Notify of
guest

0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
0
Would love your thoughts, please comment.x
()
x