All Questions
19
questions
0
votes
1
answer
7k
views
Getting logger to log to rsyslog in alpine
I installed rsyslog on my Alpine-based system to replace busybox syslogd. After completely disabling syslogd in openrc, enabling ryslog at boot and rebooting, all services correctly started logging to ...
0
votes
1
answer
286
views
How to append host IP address and host MAC addres to every log message?
I have several log agents with iptables logging rules and default rsyslog config. Rsyslog sends the logs to the central server.
Iptables rule:
iptables -A INPUT -j LOG --log-prefix "INPUT:DROP:" --...
0
votes
0
answers
1k
views
rsyslogd vs auditd? Are they alternatives or complement each other?
I see that both auditd and rsyslogd services are running (on my OpenSuse Leap 15 box). A quick google didn't give a good answer.
Are these services doing the same job? i.e. Could i get rid of one of ...
0
votes
1
answer
4k
views
Log messages containing a specific string to another file in rsyslogd
I want to save my log messages generated by iptables to another file via rsyslogd.
Currently I use this code from /etc/rsyslog.d/20-custom.conf:
# Log cron to cron.log and not to syslog
*.*;cron,...
2
votes
0
answers
561
views
MacOS - How to change syslogd's log level for a specific process/program?
I am new to MacOS and I would like to get a better of view of what's going on with a system process when my computer is starting up. I can see in the log that a process is changing settings, but the ...
0
votes
0
answers
216
views
Redirecting messages from syslogd
I'm currently using a CentOS 6 cluster which is having some issues on one node that is triggering a syslogd message:
Message from syslogd@node005 at Sep 7 14:23:04 ...
kernel: Uhhuh. NMI received ...
0
votes
1
answer
2k
views
What is the purpose of a "-" prefix to the log file path in /etc/rsyslog.d/50-default.conf and similar files?
Among others these lines appear in the file:
auth,authpriv.* /var/log/auth.log
*.*;auth,authpriv.none -/var/log/syslog
#cron.* /var/log/cron.log
#...
1
vote
2
answers
5k
views
Stop syslog messages from being sent to all open terminals
We have a hardware problem on one of our servers, and the kernel is continuously spitting out messages like this:
kernel: EDAC MC0: UE row 0, channel-a= 0 channel-b= 1 labels "-": NON-FATAL ...
1
vote
0
answers
2k
views
Syslogd: hardware error
The machine has been sending these messages to the terminal, paired with beeps from the speaker on the motherboard. These messages appear every 5 minutes, sometimes naming CPU2, sometimes CPU3.
...
1
vote
1
answer
516
views
What does the - mean in this syslog configuration
news.crit /var/log/news/news.crit
news.err /var/log/news/news.err
news.notice -/var/log/news/news.notice
So the docs indicate:
The ...
0
votes
1
answer
1k
views
Syslog cannot start
I run rsyslog on Ubuntu server.
after rsyslog starts, it restarts in a loop.
here is a piece of /var/log/syslog:
Aug 13 16:05:50 ip-10-92-237-215 rsyslogd: rsyslogd's groupid changed to 103
Aug 13 ...
1
vote
1
answer
3k
views
How to capture the remote [ rsh/rcp ] login events and information using syslog.conf
I am exploring ways to capture the remote login events in my Linux server [ Oracle Linux 5x ].
Many users are connecting to the server using rcp and rsh protocols , I wish to capture the events [ such ...
3
votes
2
answers
9k
views
Redirecting output from syslog to own log
I'm following this tutorial: Using Fail2ban To Block Wrong ISPConfig Logins, but rsyslog won't redirect the output from a file to another:
/etc/rsyslog.d/12-ispconfig.conf:
if $programname == '...
0
votes
1
answer
353
views
syslog facilities
I have an application (in java) running in a Windows PC and I want to send logging messages to a syslog server running in a Linux box somewhere in the network.
The problem I have is, that it is not ...
5
votes
1
answer
4k
views
"Supervising" syslog-ng in htop
I was working at my server, when in htop I just noticed something unusual.
The syslog-ng process was listed as follows
supervising syslog-ng
/sbin/syslog-ng
I don't know what it means. I tried to ...