# more syslog?

**URL:** <https://community.zeek.org/t/more-syslog/397>\
**Category:** Zeek\
**Created:** [July 13, 2003, 7:59pm UTC](https://community.zeek.org/t/more-syslog/397 "2003-07-13T19:59:31Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vern](https://yyz1.discourse-cdn.com/flex011/user_avatar/community.zeek.org/vern/32/630_2.png) [@Vern](https://community.zeek.org/u/Vern)\
**Post date:** [July 13, 2003, 7:59pm UTC](https://community.zeek.org/t/more-syslog/397/1 "2003-07-13T19:59:31Z")

</div>

> While I am enjoying running my new bro-0.8\_32, I find that some of the  
> stuff gets reported to syslog (such as ContentGap and some FTP attacks),  
> while the rest is getting piled to multiple files (ftp.log, http.log,  
> etc). I looked at the manual and the \*.bro file and it looks like its  
> hard-coded with ALERT statements. Is there any way to globally redirect  
> everything to syslog?

There's no single mechanism for doing this.

You should be able to send all the log files to a single location by  
redef'ing the various log file variables such as ftp\_log, etc. For many  
environments, you wouldn't want to syslog all of it, as it rapidly runs  
into an immense amount of logging.

For finer-grained control over ALERT processing, Robin Sommer has contributed  
the notion of an event that's generated after ALERT does its processing.  
(This is in the 0.8a34 release that I just announced.) It looks like:

&nbsp;&nbsp;event alert\_action(a: alert\_info, action: AlertAction)

Because it's parameterized with the corresponding action, you can then  
incorporate the action into your decision about what to do with the alert.  
ALERT still generates a syslog for loggable actions, and prints the alert  
to the alert log; perhaps it shouldn't, I'm undecided at this point.

Looking down the road, Umesh Shankar has implemented a "match" facility  
that will provide more powerful event filtering & action designation.  
I haven't integrated his changes yet, but will soon - I finally have dug  
out for a bit and have some time for Bro development.

&nbsp;&nbsp;&nbsp;&nbsp;Vern

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:36pm UTC](https://community.zeek.org/t/more-syslog/397/2 "2022-05-06T15:36:48Z")

</div>


