Syslog: Difference between revisions

From Leo's Notes
This page was last edited on 6 April 2015, at 19:59.
Created page with " <syntaxhighlight lang="text"> [root@leo-archer log]# systemctl start rsyslog A dependency job for rsyslog.service failed. See 'journalctl -xe' for details. journalctl -xe -..."
 
No edit summary
Line 1: Line 1:
== Configuration ==
<syntaxhighlight lang="text">
# Log all kernel messages to the console.
# Logging much else clutters up the screen.
#kern.*                                                /dev/console
# Log anything (except mail) of level info or higher.
# Don't log private authentication messages!
*.info;mail.none;authpriv.none;cron.none                /var/log/messages
# The authpriv file has restricted access.
authpriv.*                                              /var/log/secure
# Log all the mail messages in one place.
mail.*                                                  -/var/log/maillog
# Log cron stuff
cron.*                                                  /var/log/cron
# Everybody gets emergency messages
*.emerg                                                *
# Save news errors of level crit and higher in a special file.
uucp,news.crit                                          /var/log/spooler
# Save boot messages also to boot.log
local7.*                                                /var/log/boot.log
# Log to the logstash server
*.* @@logstash.cs.ucalgary.ca:5544
# Log to the old loghost server
*.* @loghost
</syntaxhighlight>
== Troubleshooting ==


<syntaxhighlight lang="text">
<syntaxhighlight lang="text">

Revision as of 19:59, 6 April 2015

Configuration

# Log all kernel messages to the console.
# Logging much else clutters up the screen.
#kern.*                                                 /dev/console

# Log anything (except mail) of level info or higher.
# Don't log private authentication messages!
*.info;mail.none;authpriv.none;cron.none                /var/log/messages

# The authpriv file has restricted access.
authpriv.*                                              /var/log/secure

# Log all the mail messages in one place.
mail.*                                                  -/var/log/maillog


# Log cron stuff
cron.*                                                  /var/log/cron

# Everybody gets emergency messages
*.emerg                                                 *

# Save news errors of level crit and higher in a special file.
uucp,news.crit                                          /var/log/spooler

# Save boot messages also to boot.log
local7.*                                                /var/log/boot.log

# Log to the logstash server
*.* @@logstash.cs.ucalgary.ca:5544

# Log to the old loghost server
*.* @loghost

Troubleshooting

[root@leo-archer log]# systemctl start rsyslog
A dependency job for rsyslog.service failed. See 'journalctl -xe' for details.

journalctl -xe

-- The result is failed.
Apr 06 13:55:27 leo-archer systemd[1]: Dependency failed for System Logging Service.
-- Subject: Unit rsyslog.service has failed
-- Defined-By: systemd
-- Support: http://lists.freedesktop.org/mailman/listinfo/systemd-devel
-- 
-- Unit rsyslog.service has failed.
-- 


systemctl enable rsyslog
systemctl start rsyslog