Network
router-log: the router's syslog, kept on this machine
Edit on GitHubmodules/nixos/network/router-log.nix. The OpenWrt keeps its log in a 128 KB ring in RAM: it is
gone at the next power cut, and a busy DNS log would rotate it away in minutes. Since 08/10/2026
this machine receives it over the LAN and keeps 30 days in /var/log/router/router.log, the first
step of phase 1 of the threat monitoring plan (docs/open-items.md).
Why it is built the way it is
- The router only. A log receiver open to the house is a way to forge the record it exists to
keep. The firewall admits UDP 5514 from
my.router.addressalone (thelocalsend.nixidiom), and rsyslog's ruleset drops any line whose source is not that address, so a forgery needs both. - Not 514. An unprivileged, unusual port, so no device on the LAN mistakes this machine for a general syslog sink.
- No local rules.
defaultConfig = "": this machine's own logs stay in the journal, where they were; rsyslog exists here only for the router's. - 30 days, compressed, readable by wheel. The retention the owner chose, because the DNS log
is everyone's browsing;
wheelso the glance band can read it without root.
The order is the point
- This receiver, BEFORE anything changes on the router.
log_ipon the router (system.@system[0].log_ip,log_port='5514',log_proto='udp').- Only then
logquerieson dnsmasq: turned on first, the query log would only churn the 128 KB ring and push the router's own warnings out of it.
All three were done on 08/10/2026, in that order. A query line reads
dnsmasq[1]: <n> <client>/<port> query[A] <name> from <client>, and a blocked one answers
config <name> is NXDOMAIN.