• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 490
  • Last Modified:

Linux Logging

I am new to Linux. I need to ensure that I have my system setup to log everything correctly to my central syslog server. Right now, I have the following in my syslog.conf. Now, I just want to ask, will this log everything? I cannot find any documentation on how to actually configure a level of logging for these logs. It almost seems to me that they are logged by default and your just tell it what level to log and I am logging everything. Is that correct?

# Log all kernel messages to the console.
# Logging much else clutters up the screen.
#kern.*                                                 /dev/console

# Log anything (except mail) of level info or higher.
# Don't log private authentication messages!
*.info;mail.none;authpriv.none;cron.none                /var/log/messages

# The authpriv file has restricted access.
authpriv.*                                              /var/log/secure

# Log all the mail messages in one place.
mail.*                                                  -/var/log/maillog

# Log cron stuff
cron.*                                                  /var/log/cron

# Everybody gets emergency messages
  • 2
  • 2
2 Solutions
Insert the below syntax into syslog.conf to log alerts remotely.
*.*                 @hostname
The hostname shall be your remote server and once it is done restart the syslog daemon as follows.
service syslog restart
Use "man syslogd" for more detail information on configuring syslog.conf.
just so you know what the *.* is for...

The left * tells syslog that you want all log facilities to be logged.
The right * tells syslog to log all levels of logging for whatever facility is to the left of the '.' (In this case - all facilities)

yep all facilities and all levels of the logging should be logged at remote host "@hostname"
ainselybAuthor Commented:
So one more question - does this assume that my applications are configured for logging?
ainselybAuthor Commented:

If I have this line, *.info;mail.none;authpriv.none;cron.none , and then at the end I enter the *.* syslog server, is this saying log  *.info;mail.none;authpriv.none;cron.none  to /var/log/messages and also to send all facilities all severity to my syslog server at the same time? Just want to ensure that I am getting this. Thanks,
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now