filter f_kernel {
facility(kern)
and level(notice..emerg)
@include "/etc/syslog-ng/patterndb.d/include/not2kern/";
@include "/usr/local/etc/syslog-ng/patterndb.d/include/not2kern/";
};
filter f_audit {
message("(<audit-[0-9]+>|audit:|audit_printk_skb:) ");
};
destination d_kernel { file("/var/log/kern.log"); };
log { source(src); filter(f_kernel); destination(d_kernel); };