Linux Logging

From wikieduonline
Jump to navigation Jump to search

Linux logs are save usually in /var/log folder. Most linux distribution uses syslog, syslog-ng or rsyslog software for logging or sending them to remote servers. Analytics and visualisation software such a Elasticsearch and Kibana can be used for log inspection.

Usage by Distribution:

  • Debian/Ubuntu: rsyslog
  • RHEL/Fedora:

Standard logs:

  • Debian/Ubuntu: /var/log/syslog
  • RHEL/Fedora: /var/log/message

SSH sessions logging:

  • Debian/Ubuntu: /var/log/auth.log
  • RHEL/Fedora: /var/log/secure

Ubuntu:

Rsyslog

Rsyslogd supports queued operations to handle offline outputs. Official documentation: https://www.rsyslog.com/doc/v8-stable/configuration/index.html

Log checkers


Rsyslog Configuration

Default configuration files by Distribution:

Container logging: Docker

Activities

See also

Advertising: