action
system/logging/action
Type: Directory
Actions that store or send the messages selected by the rules in /system/logging. The default actions are memory (the buffer /log shows), disk (files named log), echo (open terminal sessions) and remote (a syslog server, with no address set). Each memory action keeps its own buffer, which clear empties. See Log.
| Flag | Name | Description |
|---|---|---|
| * | default | One of the default actions: memory, disk, echo and remote. |
| Y | managed |
| Argument | Type | Description |
|---|---|---|
| name ( mandatory ) | string | Name of the action, letters and digits only. Rules refer to the action by this name, and for target=memory it is also the buffer name shown in the buffer field of /log. |
| target ( mandatory ) | enum (memory | disk | echo | remote | email | script) { memory:0, disk:1, echo:2, remote:3, email:4, script:5 } | Where the messages go:
|
| memory-lines | num | Number of entries the buffer keeps, 1..65535. When the buffer is full, each new entry drops the oldest one, unless memory-stop-on-full is set. Default: 1000. |
| memory-stop-on-full | bool | When yes, the buffer keeps its first memory-lines entries and drops new ones until it is emptied with clear. Default: no. |
| disk-file-name | string | Name of the log files, without the extension. The action writes to <name>.0.txt; when that file is full, it becomes <name>.1.txt and a new <name>.0.txt starts. To write to another disk or folder, put its name first, for example usb1/log. The folder must exist, otherwise the action is refused with bad disk file name. Two disk actions cannot use the same file name. Default: log. |
| disk-lines-per-file | num | Number of lines in each file before the action starts a new file, 1..65535. Default: 1000. |
| disk-file-count | num | Number of files the action keeps, 1..65535. When a new file starts and the count is reached, the oldest file and its entries are dropped. Default: 2. |
| disk-stop-on-full | bool | Stop writing to this action when the log files are full, instead of dropping the oldest entries. Default: no. |
| remote | alt { ipv6: ip6Addr , ip: ipAddr , hostname: string } | Address of the syslog server: an IPv4 or IPv6 address or a host name. The default remote action has 0.0.0.0 (no server set). Default: 0.0.0.0. |
| remote-port | num | Port of the syslog server. Default: 514. |
| src-address | alt { ipv6: ip6Addr , ip: ipAddr } | Source address of the packets sent to the syslog server. 0.0.0.0 leaves the choice to the router. Default: 0.0.0.0. |
| remote-log-format | enum (default | syslog | cef) | Format of the messages sent to the syslog server:
|
| remote-protocol | enum (udp | tcp | tls) | Transport to the syslog server. Every format works with every transport, and actions that send to the same address and port share one connection.
|
| check-certificate | bool | For remote-protocol=tls: whether to verify the server certificate against the trusted certificates in /certificate. When the verification fails, the router does not send, logs ssld,error client session, logging, remote IP: <address>, ssl: no trusted CA certificate found and tries again later. The name in the certificate is not compared with the server address, so trust only the CA of your log servers. Default: no. |
| cef-event-delimiter | string | Characters added at the end of every cef message, also over UDP. Default: \r\n. |
| syslog-time-format | enum (bsd-syslog | iso8601) | Time format of
|
| syslog-facility | enum (kern | user | mail | daemon | auth | syslog | lpr | news | uucp | cron | authpriv | ftp | ntp | local0 | local1 | local2 | local3 | local4 | local5 | local6 | local7) { kern:0, user:1, mail:2, daemon:3, auth:4, syslog:5, lpr:6, news:7, uucp:8, cron:9, authpriv:10, ftp:11, ntp:12, local0:16, local1:17, local2:18, local3:19, local4:20, local5:21, local6:22, local7:23 } | Facility in the
|
| syslog-severity | enum (auto | emergency | alert | critical | error | warning | notice | info | debug) { auto:0xffffffff, emergency:0, alert:1, critical:2, error:3, warning:4, notice:5, info:6, debug:7 } | Severity in the
|
| email-to | string | Address the email action sends to. Each matching message is sent as its own email, with <topics> <message> as the subject and the body, through the SMTP server, port, TLS mode and sender set in /tool/e-mail. See Email. |
| email-cc | multi { array-id, cc: string } | Additional recipients of the email action, in the CC header. Several addresses are allowed. |
| email-start-tls | bool | Not used by the email action: STARTTLS follows the tls setting in /tool/e-mail. Default: no. |
| remember | bool | For target=echo: keep the messages logged while no terminal session is open and print them at the next login, once. Default: yes. |
| add-topics-string | bool | For remote-log-format=syslog: put the topics in front of the message, <PRI><time> <identity> <topics> <message>. The default format always contains the topics. Default: no. |
| script | enum () | For target=script: the script from /system/script to run for each matching message. The script gets the variables $topics (the topics as text, for example system,error,critical) and $message. Messages that match while the script is still running are skipped, and a message the script logs itself does not run it again. |
| vrf | enum () | VRF the remote action connects from. Default: main. |