Difference between revisions of "Rsyslog Client"

From The Linux Source
Jump to: navigation, search
m (Support moved page Rsyslog client to Rsyslog Client without leaving a redirect)
 
(4 intermediate revisions by the same user not shown)
Line 1: Line 1:
1. /etc/rsyslog.conf, add @sys.log.server.ip lines to logging section, ex;
+
PARENT PAGE LINK: [[Syslog]]
# Log all kernel messages to the console.
+
 
# Logging much else clutters up the screen.
+
 
#kern.*                                                /dev/console
+
1. See generic [[Rsyslog]] page for other config options
+
 
# Log anything (except mail) of level info or higher.
+
2. /etc/rsyslog.conf, add @sys.log.server.ip lines to the bottom of the file (optionally add logging rules, example lines are commented out at the bottom of a default rsyslog.conf file)
# Don't log private authentication messages!
+
  UDP:
*.info;mail.none;authpriv.none;cron.none                /var/log/messages
+
+
# The authpriv file has restricted access.
+
authpriv.*                                              /var/log/secure
+
+
# Log all the mail messages in one place.
+
mail.*                                                  -/var/log/maillog
+
+
# Log cron stuff
+
cron.*                                                  /var/log/cron
+
+
# Everybody gets emergency messages
+
*.emerg                                                *
+
+
# Save news errors of level crit and higher in a special file.
+
uucp,news.crit                                          /var/log/spooler
+
+
# Save boot messages also to boot.log
+
local7.*                                                /var/log/boot.log
+
   
+
 
  # centralized logging
 
  # centralized logging
 
  *.* @172.160.135.160:514
 
  *.* @172.160.135.160:514
 +
OR TCP:
 +
# centralized logging
 +
*.* @@172.160.135.160:514
  
2. Restart rsyslog service
+
3. Restart rsyslog service
 
  ENT 7
 
  ENT 7
 
  # systemctl restart rsyslog
 
  # systemctl restart rsyslog
 
  BEFORE Ent 7
 
  BEFORE Ent 7
 
  # service rsyslog restart
 
  # service rsyslog restart

Latest revision as of 16:55, 22 May 2017

PARENT PAGE LINK: Syslog


1. See generic Rsyslog page for other config options

2. /etc/rsyslog.conf, add @sys.log.server.ip lines to the bottom of the file (optionally add logging rules, example lines are commented out at the bottom of a default rsyslog.conf file)

UDP:
# centralized logging
*.* @172.160.135.160:514
OR TCP:
# centralized logging
*.* @@172.160.135.160:514

3. Restart rsyslog service

ENT 7
# systemctl restart rsyslog
BEFORE Ent 7
# service rsyslog restart