Difference between revisions of "Linux Logging"

From wikieduonline
Jump to navigation Jump to search
Line 37: Line 37:
 
* {{logging}}
 
* {{logging}}
 
* {{audit}}
 
* {{audit}}
* [[AWS Cloudtrail]]
 
 
* [[Netflow]] for network logging
 
* [[Netflow]] for network logging
 
* Message Brokers for routing messages: [[NSQ]], [[RabbitMQ]], [[Apache Kafka]], [[AWS Kinesis]] and [[NATS Messaging]]
 
* Message Brokers for routing messages: [[NSQ]], [[RabbitMQ]], [[Apache Kafka]], [[AWS Kinesis]] and [[NATS Messaging]]
 
* [[fluentd]]
 
* [[fluentd]]
 
* {{ELK}}
 
* {{ELK}}
* {{logging}}
 
 
* {{stdin}}
 
* {{stdin}}
 
* [[Cisco IOS]]: <code>[[show logging]]</code>
 
* [[Cisco IOS]]: <code>[[show logging]]</code>

Revision as of 05:31, 14 January 2020

Linux logs are save usually in /var/log folder. Most linux distribution uses syslog, syslog-ng or rsyslog software for logging or sending them to remote servers. Analytics and visualisation software such a Elasticsearch and Kibana can be used for log inspection.

Usage by Distribution:

  • Debian/Ubuntu: rsyslog
  • RHEL/Fedora:

Standard logs:

  • Debian/Ubuntu: /var/log/syslog
  • RHEL/Fedora: /var/log/message

SSH sessions logging:

  • Debian/Ubuntu: /var/log/auth.log
  • RHEL/Fedora: /var/log/secure

Rsyslog

Rsyslogd supports queued operations to handle offline outputs. Official documentation: https://www.rsyslog.com/doc/v8-stable/configuration/index.html

Rsyslog Configuration

Default configuration files by Distribution:

Container logging: Docker

See also https://stackoverflow.com/questions/30969435/where-is-the-docker-daemon-log/30970134#30970134 for further information about docker logs.

Activities

See also

Text is available under the Creative Commons Attribution-ShareAlike License; additional terms may apply. By using this site, you agree to the Terms of Use and Privacy Policy. Original source: https://en.wikiversity.org/wiki/Linux/logging

Advertising: