<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://beardedmaker.com/wiki/index.php?action=history&amp;feed=atom&amp;title=Rsyslog</id>
		<title>Rsyslog - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://beardedmaker.com/wiki/index.php?action=history&amp;feed=atom&amp;title=Rsyslog"/>
		<link rel="alternate" type="text/html" href="https://beardedmaker.com/wiki/index.php?title=Rsyslog&amp;action=history"/>
		<updated>2026-05-13T08:34:38Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.27.4</generator>

	<entry>
		<id>https://beardedmaker.com/wiki/index.php?title=Rsyslog&amp;diff=158&amp;oldid=prev</id>
		<title>Beard: Created page with &quot;&lt;pre&gt; packages: 	rsyslog  daemons: 	rsyslogd  other: 	rsyslogd creates the socket /dev/log  logfiles: 	boot.log - daemon startup during system init 	cron - cron and atd daemon...&quot;</title>
		<link rel="alternate" type="text/html" href="https://beardedmaker.com/wiki/index.php?title=Rsyslog&amp;diff=158&amp;oldid=prev"/>
				<updated>2016-02-29T21:36:49Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;&amp;lt;pre&amp;gt; packages: 	rsyslog  daemons: 	rsyslogd  other: 	rsyslogd creates the socket /dev/log  logfiles: 	boot.log - daemon startup during system init 	cron - cron and atd daemon...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;lt;pre&amp;gt;&lt;br /&gt;
packages:&lt;br /&gt;
	rsyslog&lt;br /&gt;
&lt;br /&gt;
daemons:&lt;br /&gt;
	rsyslogd&lt;br /&gt;
&lt;br /&gt;
other:&lt;br /&gt;
	rsyslogd creates the socket /dev/log&lt;br /&gt;
&lt;br /&gt;
logfiles:&lt;br /&gt;
	boot.log - daemon startup during system init&lt;br /&gt;
	cron - cron and atd daemons&lt;br /&gt;
	dmesg - system hardware detection&lt;br /&gt;
	maillog - sendmail&lt;br /&gt;
	secure - network access such as sshd and xinetd&lt;br /&gt;
	wtmp - history of all login sessions&lt;br /&gt;
	rpmpkgs,yum.log - list of packages installed by rpm&lt;br /&gt;
	xferlog - ftp log&lt;br /&gt;
	Xorg.0.log,XFree86 - X windows&lt;br /&gt;
	lastlog - list of users and the time they last logged in. must use the 'lastlog' command&lt;br /&gt;
	messages - important messages generated during and after system init&lt;br /&gt;
&lt;br /&gt;
configs:&lt;br /&gt;
	/etc/rsyslog.conf - config file&lt;br /&gt;
	/etc/rsyslog.d/ - contains extra configs&lt;br /&gt;
&lt;br /&gt;
args:&lt;br /&gt;
	* = wildcard&lt;br /&gt;
	; = separator&lt;br /&gt;
	&amp;lt;facility&amp;gt;.&amp;lt;priority&amp;gt; /path/logfile - logs the specified item(s) into logfile. path can be a file or a socket via @host:port (default port 514)&lt;br /&gt;
		facility - where rsyslog should listen. can be comma separated.&lt;br /&gt;
			kern - listen to kernel messages&lt;br /&gt;
			news - listen to news daemon&lt;br /&gt;
			auth - login, getty, su, etc.&lt;br /&gt;
			security - same as auth&lt;br /&gt;
			authpriv - network login&lt;br /&gt;
			cron&lt;br /&gt;
			daemon - system daemons such as ftp&lt;br /&gt;
			lpr - printing system&lt;br /&gt;
			mail - sendmail&lt;br /&gt;
			mark - timestamps used my rsyslog. internal only&lt;br /&gt;
			syslog&lt;br /&gt;
			user - messages from user processes&lt;br /&gt;
			uucp - Unix to Unix Copy daemon&lt;br /&gt;
			local&amp;lt;0-7&amp;gt; - can be customized&lt;br /&gt;
		priority (in order of seriousness)&lt;br /&gt;
			debug - all messages&lt;br /&gt;
			info - normal messages&lt;br /&gt;
			notice - notice messages. not an error&lt;br /&gt;
			warning,warn - warning messages. might be error, but not system critical&lt;br /&gt;
			error,err - error messages. generic&lt;br /&gt;
			crit - critical messages. such as disk failure.&lt;br /&gt;
			alert - alert messages. must be dealt with immediately such as system database corruption&lt;br /&gt;
			emerg,panic - serious messages. things normally broadcast to all users.&lt;br /&gt;
		format&lt;br /&gt;
			=warning - only warning&lt;br /&gt;
			!=warn - not warning&lt;br /&gt;
&lt;br /&gt;
log server:&lt;br /&gt;
	on the server open /etc/rsyslog.conf and uncomment all lines with:&lt;br /&gt;
		$ModLoad&lt;br /&gt;
		$UDPServerRun&lt;br /&gt;
		$InputTCPServerRun&lt;br /&gt;
	on the client open /etc/rsyslog.conf and add a line similar to:&lt;br /&gt;
		auth.info @server:514&lt;br /&gt;
&lt;br /&gt;
log management:&lt;br /&gt;
	clear a log by writing to it via &amp;quot;&amp;gt;/log/file&amp;quot; with nothing before it. do not delete the file, permissions may get screwed up.&lt;br /&gt;
	it's best to save a backup of logs before clearing.&lt;br /&gt;
&lt;br /&gt;
logrotate:&lt;br /&gt;
	/etc/logrotate.conf - config file&lt;br /&gt;
	/etc/logrotate.d/ - contains extra config files&lt;br /&gt;
	logrotate would rename test.log to test.log.YYYMMDD&lt;br /&gt;
&lt;br /&gt;
	args:&lt;br /&gt;
		rotate 4 - keep 4 weeks worth of backlogs&lt;br /&gt;
		postrotate - starts a script&lt;br /&gt;
			[script]&lt;br /&gt;
		endscript&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Beard</name></author>	</entry>

	</feed>