File tree Expand file tree Collapse file tree 4 files changed +39
-15
lines changed Expand file tree Collapse file tree 4 files changed +39
-15
lines changed Original file line number Diff line number Diff line change
1
+ :msg, regex, ".*_DROP: .* DPT=7777 .*" /var/log/firewalld-denied-kf2.log
2
+ & stop
3
+ :msg, regex, ".*_REJECT: .* DPT=7777 .*" /var/log/firewalld-denied-kf2.log
4
+ & stop
5
+
6
+ :msg, contains, "_DROP: " /var/log/firewalld-denied.log
7
+ & stop
8
+ :msg, contains, "_REJECT: " /var/log/firewalld-denied.log
9
+ & stop
Load Diff This file was deleted.
Original file line number Diff line number Diff line change 12
12
systemd :
13
13
name : rsyslog.service
14
14
state : restarted
15
+
16
+ - name : Reload journald configuration
17
+ systemd :
18
+ name : systemd-journald.service
19
+ state : restarted
Original file line number Diff line number Diff line change 10
10
state : started
11
11
enabled : true
12
12
13
- - name : Configure KF2 DDoS logging
13
+ - name : Redirect logging of denied packets
14
14
copy :
15
- src : kf2-ddos .conf
16
- dest : /etc/rsyslog.d/kf2-ddos .conf
15
+ src : firewalld-denied .conf
16
+ dest : /etc/rsyslog.d/firewalld-denied .conf
17
17
owner : root
18
18
group : root
19
19
mode : ' 0644'
20
20
notify : Reload rsyslog configuration
21
21
22
- - name : Log packets denied by firewalld
23
- lineinfile :
24
- path : /etc/firewalld/firewalld.conf
25
- regexp : ' ^LogDenied='
26
- line : LogDenied=all
27
- notify : Reload firewalld configuration
22
+ - name : Limit journald storage
23
+ ini_file :
24
+ path : /etc/systemd/journald.conf
25
+ section : Journal
26
+ option : SystemMaxUse
27
+ value : 100M
28
+ no_extra_spaces : true
29
+ create : false
30
+ backup : true
31
+ notify : Reload journald configuration
32
+
33
+ # This will be enabled on-demand via klf
34
+ # - name: Log packets denied by firewalld
35
+ # lineinfile:
36
+ # path: /etc/firewalld/firewalld.conf
37
+ # regexp: '^LogDenied='
38
+ # line: LogDenied=all
39
+ # notify: Reload firewalld configuration
28
40
29
41
- include_role :
30
42
name : bviktor.firewalld
41
53
- include_role :
42
54
name : bviktor.logrotate
43
55
vars :
44
- name : kf2-ddos
45
- pattern : /var/log/kf2-ddos.log
56
+ name : firewalld-denied
57
+ pattern : |-
58
+ /var/log/firewalld-denied.log
59
+ /var/log/firewalld-denied-kf2.log
46
60
retention : 7
You can’t perform that action at this time.
0 commit comments