Difference between revisions of "Rsyslog Client"

From The Linux Source
Jump to: navigation, search
(Created page with "=== Client rsyslog Setup === 1. /etc/rsyslog.conf, add @sys.log.server.ip lines to logging section, ex; # Log all kernel messages to the console. # Logging much else clutte...")
 
m (Support moved page Rsyslog client to Rsyslog Client without leaving a redirect)
 
(5 intermediate revisions by the same user not shown)
Line 1: Line 1:
===  Client rsyslog Setup ===
+
PARENT PAGE LINK: [[Syslog]]
1. /etc/rsyslog.conf, add @sys.log.server.ip lines to logging section, ex;
+
 
# Log all kernel messages to the console.
+
 
  # Logging much else clutters up the screen.
+
1. See generic [[Rsyslog]] page for other config options
  #kern.*                                                /dev/console
+
 
   
+
2. /etc/rsyslog.conf, add @sys.log.server.ip lines to the bottom of the file (optionally add logging rules, example lines are commented out at the bottom of a default rsyslog.conf file)
# Log anything (except mail) of level info or higher.
+
  UDP:
# Don't log private authentication messages!
+
  # centralized logging
*.info;mail.none;authpriv.none;cron.none                /var/log/messages
+
  *.* @172.160.135.160:514
   
+
  OR TCP:
  # The authpriv file has restricted access.
+
  # centralized logging
  authpriv.*                                             /var/log/secure
+
  *.* @@172.160.135.160:514
+
 
# Log all the mail messages in one place.
+
3. Restart rsyslog service
  mail.*                                                  -/var/log/maillog
+
  ENT 7
+
  # systemctl restart rsyslog
  # Log cron stuff
+
  BEFORE Ent 7
cron.*                                                  /var/log/cron
+
  # service rsyslog restart
   
+
  # Everybody gets emergency messages
+
*.emerg                                                *
+

Latest revision as of 15:55, 22 May 2017

PARENT PAGE LINK: Syslog


1. See generic Rsyslog page for other config options

2. /etc/rsyslog.conf, add @sys.log.server.ip lines to the bottom of the file (optionally add logging rules, example lines are commented out at the bottom of a default rsyslog.conf file)

UDP:
# centralized logging
*.* @172.160.135.160:514
OR TCP:
# centralized logging
*.* @@172.160.135.160:514

3. Restart rsyslog service

ENT 7
# systemctl restart rsyslog
BEFORE Ent 7
# service rsyslog restart