Forum Discussion
3 Replies
Sort By
- hooleylistCirrostratusYou should be able to adapt a rule like this to log the original client, SNAT and destination IP addresses:
when SERVER_CONNECTED { log local0. "[IP::client_addr], [IP::local_addr], [IP::server_addr]" }
- dennypayneEmployeeShould work, but I'd be careful with putting a rule like this on a high-volume site...you don't want to fill up /var/log and cause performance problems.
- JRahmAdminIf you are on 9.4 or higher you can send directly to a remote log server so you can log higher volumes without being impacted by the disk access necessary for local writes: