Alain Satre wrote:

> What about specifying the line twice?
> i.e.
>        /var/log/maillog
>       @syslog.server

This works.

> I would hope that doesnt allow untrsted hosts to send
> syslog data to your host?

It does, and is a known issue.

> Is there a way to allow certain ip's? or just all or nothing?

Use ipchains (or whatever is appropriate for your kernel revision)
to narrow down the IP range that syslog can accept (if you need
to know the port, look in /etc/services).  Note that if someone
can guess the IP address(es) that you are monitoring, then they can
easily forge packets that will circumvent your filtering rule.
This, too, is a known issue.

