如何配置syslog-ng.conf实现接收SNMP协议传输的日志?
Absolutely, you can integrate SNMP trap reception into your syslog-ng workflow. Since syslog-ng doesn’t natively parse SNMP traps, the standard approach uses snmptrapd (part of the Net-SNMP toolkit) to convert SNMP traps into syslog messages, which syslog-ng can then process and store in MySQL. Here’s how to set it up:
Step 1: Configure snmptrapd to Forward Traps to syslog-ng
First, set up snmptrapd to listen for SNMP traps and forward them to your syslog-ng instance. Edit your snmptrapd.conf file (usually located at /etc/snmp/snmptrapd.conf):
# Allow community strings (adjust "public" to match your environment) authCommunity log,execute,net public # Format traps into syslog-compatible messages format2 %B %b %e %H:%M:%S %h %N: %W\n # Forward traps to syslog-ng (use localhost:514 if syslog-ng runs locally) forward default localhost:514
Restart the snmptrapd service to apply changes:
sudo systemctl restart snmptrapd
Step 2: Update syslog-ng.conf to Receive and Store SNMP Traps
Next, modify your syslog-ng.conf to accept the forwarded syslog messages from snmptrapd and send them to your MySQL table.
2.1 Define a Source for SNMP Messages
Add a source that listens for the UDP traffic from snmptrapd (adjust the IP/port if needed):
source s_snmp { udp(ip(0.0.0.0) port(514)); # Listens on all interfaces, port 514 # If snmptrapd sends to local syslog socket, use instead: # unix-dgram("/dev/log"); };
2.2 Define a MySQL Destination
First, ensure you have the syslog-ng MySQL module installed (e.g., libsyslog-ng-mod-mysql on Debian/Ubuntu). Then configure the MySQL destination:
destination d_mysql_snmp { mysql( host("localhost") username("syslog_db_user") # Replace with your MySQL user password("your_secure_password") # Replace with your MySQL password database("syslog_db") # Replace with your database name table("snmp_logs") # The table where you'll store SNMP logs columns("log_time", "source_host", "trap_message") values("$R_DATE", "$HOST", "$MESSAGE") indexes("log_time", "source_host") ); };
2.3 Create the MySQL Table
Before syslog-ng can write to the table, create it with this SQL query (run in MySQL):
CREATE TABLE snmp_logs ( id INT AUTO_INCREMENT PRIMARY KEY, log_time DATETIME NOT NULL, source_host VARCHAR(64) NOT NULL, trap_message TEXT NOT NULL );
2.4 Link Source and Destination with a Log Path
Add a log statement to route SNMP messages from the source to the MySQL destination. You can also add a filter to only process snmptrapd-generated messages:
# Optional: Filter to only include messages from snmptrapd filter f_snmptrapd { program("snmptrapd"); }; log { source(s_snmp); filter(f_snmptrapd); # Remove if you want all port 514 traffic to go to MySQL destination(d_mysql_snmp); };
Step 3: Test and Validate
- Check your syslog-ng configuration for errors:
syslog-ng -s
- Restart syslog-ng to apply changes:
sudo systemctl restart syslog-ng
- Send a test SNMP trap to your server (replace
your-server-ipand community string as needed):
snmptrap -v 2c -c public your-server-ip '' SNMPv2-MIB::coldStart.0
- Check your MySQL
snmp_logstable to confirm the trap was stored successfully.
内容的提问来源于stack exchange,提问作者zakblack

