如何在syslog-ng客户端创建过滤规则丢弃指定文本日志行?
Hey there! Since you're new to syslog-ng, let's break this down step by step so you can add those filtering rules without disrupting your existing working setup.
syslog-ng uses filter definitions to target specific logs, and you'll use the not operator to exclude matching logs from being sent to your central storage. Here's how to set up both of your required rules:
1. Filter to Drop Logs Containing "some text pattern"
First, we'll create a filter that identifies logs with your target text, then exclude them from your transmission pipeline.
Open your syslog-ng configuration file (usually located at
/etc/syslog-ng/syslog-ng.conf) in a text editor.Add a filter definition somewhere in the file (I recommend grouping all filters together for readability):
filter f_drop_some_text { match("some text pattern" value("MESSAGE")); };f_drop_some_textis a custom name for your filter (feel free to rename it to something more descriptive).match(...)looks for the exact text in theMESSAGEfield of the log (this is where the main log content lives).
Locate the existing
logblock that sends logs to your central storage. It should look something like this:log { source(s_local); destination(d_central_storage); };Modify this block to exclude the filtered logs by adding the
filter(not ...)line:log { source(s_local); filter(not f_drop_some_text); destination(d_central_storage); };
2. Filter to Drop Logs Containing "-- MARK --"
For the -- MARK -- logs (like your example: Mar 19 15:34:36 10.232.194.98 [Mar 19 15:34:37] [localhost] local_access_log : -- MARK --), we'll use the same pattern.
- Add another filter definition (or combine it with the first one, if you prefer):
filter f_drop_mark { match("-- MARK --" value("MESSAGE")); };
Option A: Apply Both Filters Separately
Update your log block to exclude both sets of logs:
log { source(s_local); filter(not f_drop_some_text); filter(not f_drop_mark); destination(d_central_storage); };
Option B: Combine Filters for Simplicity
If you want a cleaner configuration, merge the two filters into one:
filter f_drop_unwanted { match("some text pattern" value("MESSAGE")) or match("-- MARK --" value("MESSAGE")); }; log { source(s_local); filter(not f_drop_unwanted); destination(d_central_storage); };
Final Steps to Activate the Configuration
- Backup your original config first, just in case:
cp /etc/syslog-ng/syslog-ng.conf /etc/syslog-ng/syslog-ng.conf.bak - Save your edited configuration file.
- Restart syslog-ng to apply the changes:
# For systemd-based systems (like Ubuntu 16.04+, RHEL 7+) systemctl restart syslog-ng # For older init.d systems service syslog-ng restart - Test it out! Generate a test log with
logger "-- MARK --"and check your central storage to confirm the log isn't being sent.
内容的提问来源于stack exchange,提问作者Subi

