Difference between revisions of "Rsyslog Client"

From The Linux Source
Jump to: navigation, search
Line 1: Line 1:
1. /etc/rsyslog.conf, add @sys.log.server.ip lines to logging section, ex;
+
1. /etc/rsyslog.conf, add @sys.log.server.ip lines to the bottom of the file (optionally add logging rules, example lines are commented out at the bottom of a default rsyslog.conf file)
# Log all kernel messages to the console.
+
  UDP:
# Logging much else clutters up the screen.
+
#kern.*                                                /dev/console
+
+
# Log anything (except mail) of level info or higher.
+
# Don't log private authentication messages!
+
*.info;mail.none;authpriv.none;cron.none                /var/log/messages
+
+
# The authpriv file has restricted access.
+
authpriv.*                                              /var/log/secure
+
+
# Log all the mail messages in one place.
+
mail.*                                                  -/var/log/maillog
+
+
# Log cron stuff
+
cron.*                                                  /var/log/cron
+
+
# Everybody gets emergency messages
+
*.emerg                                                *
+
+
# Save news errors of level crit and higher in a special file.
+
uucp,news.crit                                          /var/log/spooler
+
+
# Save boot messages also to boot.log
+
local7.*                                                /var/log/boot.log
+
   
+
 
  # centralized logging
 
  # centralized logging
 
  *.* @172.160.135.160:514
 
  *.* @172.160.135.160:514
 +
OR TCP:
 +
# centralized logging
 +
*.* @@172.160.135.160:514
  
 
2. Restart rsyslog service
 
2. Restart rsyslog service

Revision as of 16:37, 22 May 2017

1. /etc/rsyslog.conf, add @sys.log.server.ip lines to the bottom of the file (optionally add logging rules, example lines are commented out at the bottom of a default rsyslog.conf file)

UDP:
# centralized logging
*.* @172.160.135.160:514
OR TCP:
# centralized logging
*.* @@172.160.135.160:514

2. Restart rsyslog service

ENT 7
# systemctl restart rsyslog
BEFORE Ent 7
# service rsyslog restart