0

I currently manage a qmail installation, set up on Centos using the qmailrocks guide (which seems to have vanished from the Internet now). So - daemontools, multilog, vpopmail, qmail.

I've been asked to set up a Splunk server for analysing the logs from all our servers, and I can't seem to find any way of making Splunk read multilog messages. I've had a dig around the qmail documentation and found splogger, which is able to log messages to syslog (which Splunk CAN read). So, is there an easy way of replacing multilog with splogger for a qmail installation managed by daemontools, or do I need to completely change how I start qmail?

om3rta
  • 3
  • 4

1 Answers1

0

Look for the run file in /var/qmail/supervise/qmail-smtpd/log and replace the multilog line with splogger with the appropriate arguments for splogger. Restart qmail-smtpd with the svc -h /serverice/qmail-smtpd command. Make backups of any changed files of course.

patlc
  • 16
  • 1