Solved

Linux Logging

Posted on 2009-07-02
5
462 Views
Last Modified: 2013-12-06
I am new to Linux. I need to ensure that I have my system setup to log everything correctly to my central syslog server. Right now, I have the following in my syslog.conf. Now, I just want to ask, will this log everything? I cannot find any documentation on how to actually configure a level of logging for these logs. It almost seems to me that they are logged by default and your just tell it what level to log and I am logging everything. Is that correct?

# Log all kernel messages to the console.
# Logging much else clutters up the screen.
#kern.*                                                 /dev/console

# Log anything (except mail) of level info or higher.
# Don't log private authentication messages!
*.info;mail.none;authpriv.none;cron.none                /var/log/messages

# The authpriv file has restricted access.
authpriv.*                                              /var/log/secure

# Log all the mail messages in one place.
mail.*                                                  -/var/log/maillog


# Log cron stuff
cron.*                                                  /var/log/cron

# Everybody gets emergency messages
*.emerg                                              
0
Comment
Question by:ainselyb
  • 2
  • 2
5 Comments
 
LVL 1

Accepted Solution

by:
krishna_babu5 earned 250 total points
ID: 24769912
Insert the below syntax into syslog.conf to log alerts remotely.
*.*                 @hostname
The hostname shall be your remote server and once it is done restart the syslog daemon as follows.
service syslog restart
Use "man syslogd" for more detail information on configuring syslog.conf.
0
 
LVL 4

Assisted Solution

by:colinvann
colinvann earned 250 total points
ID: 24771517
just so you know what the *.* is for...

The left * tells syslog that you want all log facilities to be logged.
The right * tells syslog to log all levels of logging for whatever facility is to the left of the '.' (In this case - all facilities)

0
 
LVL 1

Expert Comment

by:krishna_babu5
ID: 24771735
yep all facilities and all levels of the logging should be logged at remote host "@hostname"
0
 

Author Comment

by:ainselyb
ID: 25327268
So one more question - does this assume that my applications are configured for logging?
0
 

Author Comment

by:ainselyb
ID: 25327428
Also,

If I have this line, *.info;mail.none;authpriv.none;cron.none , and then at the end I enter the *.* syslog server, is this saying log  *.info;mail.none;authpriv.none;cron.none  to /var/log/messages and also to send all facilities all severity to my syslog server at the same time? Just want to ensure that I am getting this. Thanks,
0

Featured Post

Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

Join & Write a Comment

Users are often faced with high disk consumption without really knowing where the largest amount of data resides. Disk Usage Analyzer (aka Baobab) is is a graphical, menu-driven application to analyse disk usage in any Gnome environment and can e…
1. Introduction As many people are interested in Linux but not as many are interested or knowledgeable (enough) to install Linux on their system, here is a safe way to try out Linux on your existing (Windows) system. The idea is that you insta…
It is a freely distributed piece of software for such tasks as photo retouching, image composition and image authoring. It works on many operating systems, in many languages.
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now