Ho installato ulogd-2.0.0_beta4 ma fallisce lo start. Su ulogd.log viene registrato:
- Code: Select all
Fri Apr 6 10:55:43 2012 <5> ulogd.c:372 registering plugin `NFLOG'
Fri Apr 6 10:55:43 2012 <5> ulogd.c:372 registering plugin `NFCT'
Fri Apr 6 10:55:43 2012 <5> ulogd.c:372 registering plugin `IFINDEX'
Fri Apr 6 10:55:43 2012 <5> ulogd.c:372 registering plugin `IP2STR'
Fri Apr 6 10:55:43 2012 <5> ulogd.c:372 registering plugin `IP2BIN'
Fri Apr 6 10:55:43 2012 <5> ulogd.c:372 registering plugin `PRINTPKT'
Fri Apr 6 10:55:43 2012 <5> ulogd.c:372 registering plugin `HWHDR'
Fri Apr 6 10:55:43 2012 <5> ulogd.c:372 registering plugin `PRINTFLOW'
Fri Apr 6 10:55:43 2012 <5> ulogd.c:372 registering plugin `LOGEMU'
Fri Apr 6 10:55:43 2012 <5> ulogd.c:372 registering plugin `SYSLOG'
Fri Apr 6 10:55:43 2012 <5> ulogd.c:372 registering plugin `XML'
Fri Apr 6 10:55:43 2012 <5> ulogd.c:372 registering plugin `BASE'
Fri Apr 6 10:55:43 2012 <8> ulogd.c:1179 not even a single working plugin stack
Il problema è in ulogd.conf, perchè ci sono tutti gli stack commentati. Come esposto in questa discussione "http://www.gossamer-threads.com/lists/gentoo/user/234915" , basta decommentare uno degli stack ed il problema si risolve. Ma... quale decommento? Questi sono gli stack:
- Code: Select all
#stack=log1:NFLOG,base1:BASE,ifi1:IFINDEX,ip2str1:IP2STR,print1:PRINTPKT,emu1:LOGEMU
#stack=log2:NFLOG,base1:BASE,ifi1:IFINDEX,ip2str1:IP2STR,print1:PRINTPKT,emu1:LOGEMU
#stack=ulog1:ULOG,base1:BASE,ip2str1:IP2STR,print1:PRINTPKT,emu1:LOGEMU
#stack=log2:NFLOG,mark1:MARK,base1:BASE,ifi1:IFINDEX,ip2str1:IP2STR,print1:PRINTPKT,emu1:LOGEMU
#stack=ct1:NFCT,ip2str1:IP2STR,print1:PRINTFLOW,emu1:LOGEMU
#stack=ct1:NFCT,op1:OPRINT
#stack=ct1:NFCT,xml1:XML
#stack=log1:NFLOG,xml1:XML
#stack=log2:NFLOG,base1:BASE,pcap1:PCAP
#stack=log2:NFLOG,base1:BASE,ifi1:IFINDEX,ip2bin1:IP2BIN,mac2str1:HWHDR,mysql1:MYSQL
#stack=log2:NFLOG,base1:BASE,ifi1:IFINDEX,ip2str1:IP2STR,mac2str1:HWHDR,pgsql1:PGSQL
#stack=log3:NFLOG,base1:BASE,ifi1:IFINDEX,ip2str1:IP2STR,print1:PRINTPKT,sys1:SYSLOG
#stack=ct1:NFCT,ip2bin1:IP2BIN,mysql2:MYSQL
#stack=ct1:NFCT,ip2str1:IP2STR,pgsql2:PGSQL
#stack=ct1:NFCT,ip2str1:IP2STR,pgsql3:PGSQL
#stack=ct1:NFCT,ip2str1:IP2STR,nacct1:NACCT
Io voglio usare ulogd come sistema di log per FWBuilder, senza alcun database, con registrazione su file ulogd.syslogemu.
Escludendo gli stack che fanno evidente riferimento a database (MYSQL e PGSQL), tutti gli altri non li capisco.
Qualcuno conosce/capisce la differenza tra questi stack?
