#743553 rsyslog: build omudpspoof module

Package:
rsyslog
Source:
rsyslog
Description:
reliable system and kernel logging daemon
Submitter:
Chris Stromsoe
Date:
2023-08-09 11:15:05 UTC
Severity:
wishlist
Tags:
#743553#5
Date:
2014-04-03 18:18:28 UTC
From:
To:
Please add --enable-omudpspoof to the build flags to enable building of
the omudpspoof module.

#743553#12
Date:
2017-11-30 00:42:13 UTC
From:
To:
Hi Chris


Could you elaborate why you want to see this module enabled and what you
want to use it for?

Regards,
Michael

#743553#19
Date:
2017-11-30 02:21:01 UTC
From:
To:
I have a tiered syslog collection system where multiple collectors
retransmit received packets in a mesh to ensure that every collector has
all of the UDP traffic.

Right now, I need to install samplicate to listen on *:514/udp and
transmit to rsyslog bound to localhost for local storage and duplicate
traffic to the rest of the mesh.

I would prefer having rsyslog listen on *:514/udp and do all of the
processing and retransmission as part of the standard config.

#743553#24
Date:
2021-07-09 11:36:57 UTC
From:
To:
Hi,

I believe that I have a use for the omudpspoof module.

I have a number of sites using debian hosts configured as routers. These
use dynamic routing. Logs are sent to a server in one of the sites by
udp for archive and analysis purposes. Separate log files are generated
based on sending host. Temporary changes in routing result in split log
files. This makes automatic analysis more difficult. Sending log traffic
with the source set to an "inside" ip would solve this.

Pleasy advise if you want me to elaborate further or if I can be of
other assistance. Thank you for you work on maintaining this package.

Regards
Magnus

#743553#29
Date:
2023-08-09 11:05:17 UTC
From:
To:
This is a longstanding wish (2014!), it would be nice
to have this module installable without rebuilding
this package on my own.

It is the basic connectivity module and as we have all
the "advanced" module (eg. elasticsearch) this is
the module to build a nice farm of syslog servers
running all rsyslogd.

So it would be very nice to have this soon.

Or I have to roll back into the Redhat World.

Best regards, Jens Hektor