Solved

Linux Logging

Posted on 2009-07-02
5
472 Views
Last Modified: 2013-12-06
I am new to Linux. I need to ensure that I have my system setup to log everything correctly to my central syslog server. Right now, I have the following in my syslog.conf. Now, I just want to ask, will this log everything? I cannot find any documentation on how to actually configure a level of logging for these logs. It almost seems to me that they are logged by default and your just tell it what level to log and I am logging everything. Is that correct?

# Log all kernel messages to the console.
# Logging much else clutters up the screen.
#kern.*                                                 /dev/console

# Log anything (except mail) of level info or higher.
# Don't log private authentication messages!
*.info;mail.none;authpriv.none;cron.none                /var/log/messages

# The authpriv file has restricted access.
authpriv.*                                              /var/log/secure

# Log all the mail messages in one place.
mail.*                                                  -/var/log/maillog


# Log cron stuff
cron.*                                                  /var/log/cron

# Everybody gets emergency messages
*.emerg                                              
0
Comment
Question by:ainselyb
  • 2
  • 2
5 Comments
 
LVL 1

Accepted Solution

by:
krishna_babu5 earned 250 total points
ID: 24769912
Insert the below syntax into syslog.conf to log alerts remotely.
*.*                 @hostname
The hostname shall be your remote server and once it is done restart the syslog daemon as follows.
service syslog restart
Use "man syslogd" for more detail information on configuring syslog.conf.
0
 
LVL 4

Assisted Solution

by:colinvann
colinvann earned 250 total points
ID: 24771517
just so you know what the *.* is for...

The left * tells syslog that you want all log facilities to be logged.
The right * tells syslog to log all levels of logging for whatever facility is to the left of the '.' (In this case - all facilities)

0
 
LVL 1

Expert Comment

by:krishna_babu5
ID: 24771735
yep all facilities and all levels of the logging should be logged at remote host "@hostname"
0
 

Author Comment

by:ainselyb
ID: 25327268
So one more question - does this assume that my applications are configured for logging?
0
 

Author Comment

by:ainselyb
ID: 25327428
Also,

If I have this line, *.info;mail.none;authpriv.none;cron.none , and then at the end I enter the *.* syslog server, is this saying log  *.info;mail.none;authpriv.none;cron.none  to /var/log/messages and also to send all facilities all severity to my syslog server at the same time? Just want to ensure that I am getting this. Thanks,
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In order for businesses to be compliant with certain information security laws in some countries, you need to be able to prove that a user (which user it was becomes important to the business to take action against the user after an event has occurr…
This document is written for Red Hat Enterprise Linux AS release 4 and ORACLE 10g.  Earlier releases can be installed using this document as well however there are some additional steps for packages to be installed see Metalink. Disclaimer: I hav…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question