On Mon, 27 May 2024 at 14:38:44 +0100, Luca Boccassi wrote: > Yes this sounds reasonable - do you already have an idea about which > is which, from the list above?
Nothing reliable, so please check before opening bugs. I know fail2ban and logcheck do read plain-text logs (although as mentioned, fail2ban already has native Journal-reading support too), and I would guess that fwlogwatch, snort and xwatch probably also read the logs. >From my limited knowledge of what they do, I would guess that approx, hippotat, inetutils-*d, request-tracker*, *inetd and spamd are just log sources that need a syslog-compatible logging sink, for which either journald or a traditional syslogd should be equally valid. The others, no idea. smcv