"우분투 rsyslog.conf"의 두 판 사이의 차이

 
(사용자 2명의 중간 판 19개는 보이지 않습니다)
1번째 줄: 1번째 줄:
==개요==
==개요==
;/etc/rsyslog.conf
;/etc/rsyslog.conf
;rsyslog.conf
* [[rsyslog]] 설정 파일
*[[rsyslog]]설정 파일


==내용==
==우분투 16==
<source lang='bash'>
<syntaxhighlight lang='aconf'>
# rsyslog v5 configuration file
# /etc/rsyslog.conf Configuration file for rsyslog.
#
# For more information see
# /usr/share/doc/rsyslog-doc/html/rsyslog_conf.html
#
#  Default logging rules can be found in /etc/rsyslog.d/50-default.conf


# For more information see /usr/share/doc/rsyslog-*/rsyslog_conf.html
# If you experience problems, see http://www.rsyslog.com/doc/troubleshoot.html


#################
#### MODULES ####
#### MODULES ####
#################


$ModLoad imuxsock # provides support for local system logging (e.g. via logger command)
module(load="imuxsock") # provides support for local system logging
$ModLoad imklog   # provides kernel logging support (previously done by rklogd)
module(load="imklog")  # provides kernel logging support
#$ModLoad immark  # provides --MARK-- message capability
#module(load="immark") # provides --MARK-- message capability


# Provides UDP syslog reception
# provides UDP syslog reception
#$ModLoad imudp
#module(load="imudp")
#$UDPServerRun 514
#input(type="imudp" port="514")


# Provides TCP syslog reception
# provides TCP syslog reception
#$ModLoad imtcp
#module(load="imtcp")
#$InputTCPServerRun 514
#input(type="imtcp" port="514")


# Enable non-kernel facility klog messages
$KLogPermitNonKernelFacility on


###########################
#### GLOBAL DIRECTIVES ####
#### GLOBAL DIRECTIVES ####
###########################


# Use default timestamp format
#
# Use traditional timestamp format.
# To enable high precision timestamps, comment out the following line.
#
$ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat
$ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat


# File syncing capability is disabled by default. This feature is usually not required,
# Filter duplicated messages
# not useful and an extreme performance hit
$RepeatedMsgReduction on
#$ActionFileEnableSync on


#
# Set the default permissions for all log files.
#
$FileOwner syslog
$FileGroup adm
$FileCreateMode 0640
$DirCreateMode 0755
$Umask 0022
$PrivDropToUser syslog
$PrivDropToGroup syslog
#
# Where to place spool and state files
#
$WorkDirectory /var/spool/rsyslog
#
# Include all config files in /etc/rsyslog.d/
# Include all config files in /etc/rsyslog.d/
#
$IncludeConfig /etc/rsyslog.d/*.conf
$IncludeConfig /etc/rsyslog.d/*.conf
</syntaxhighlight>


==우분투 14==
<syntaxhighlight lang='aconf'>
#  /etc/rsyslog.conf Configuration file for rsyslog.
#
# For more information see
# /usr/share/doc/rsyslog-doc/html/rsyslog_conf.html
#
#  Default logging rules can be found in /etc/rsyslog.d/50-default.conf


#### RULES ####


# Log all kernel messages to the console.
#################
# Logging much else clutters up the screen.
#### MODULES ####
#kern.*                                                /dev/console
#################


# Log anything (except mail) of level info or higher.
$ModLoad imuxsock # provides support for local system logging
# Don't log private authentication messages!
$ModLoad imklog  # provides kernel logging support
*.info;mail.none;authpriv.none;cron.none                /var/log/messages
#$ModLoad immark  # provides --MARK-- message capability


# The authpriv file has restricted access.
# provides UDP syslog reception
authpriv.*                                              /var/log/secure
#$ModLoad imudp
#$UDPServerRun 514


# Log all the mail messages in one place.
# provides TCP syslog reception
mail.*                                                  -/var/log/maillog
#$ModLoad imtcp
#$InputTCPServerRun 514


# Enable non-kernel facility klog messages
$KLogPermitNonKernelFacility on


# Log cron stuff
###########################
cron.*                                                  /var/log/cron
#### GLOBAL DIRECTIVES ####
###########################


# Everybody gets emergency messages
#
*.emerg                                                *
# Use traditional timestamp format.
# To enable high precision timestamps, comment out the following line.
#
$ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat


# Save news errors of level crit and higher in a special file.
# Filter duplicated messages
uucp,news.crit                                          /var/log/spooler
$RepeatedMsgReduction on


# Save boot messages also to boot.log
#
local7.*                                                /var/log/boot.log
# Set the default permissions for all log files.
#
$FileOwner syslog
$FileGroup adm
$FileCreateMode 0640
$DirCreateMode 0755
$Umask 0022
$PrivDropToUser syslog
$PrivDropToGroup syslog


#
# Where to place spool and state files
#
$WorkDirectory /var/spool/rsyslog


# ### begin forwarding rule ###
# The statement between the begin ... end define a SINGLE forwarding
# rule. They belong together, do NOT split them. If you create multiple
# forwarding rules, duplicate the whole block!
# Remote Logging (we use TCP for reliable delivery)
#
#
# An on-disk queue is created for this action. If the remote host is
# Include all config files in /etc/rsyslog.d/
# down, messages are spooled to disk and sent when it is up again.
#
#$WorkDirectory /var/lib/rsyslog # where to place spool files
$IncludeConfig /etc/rsyslog.d/*.conf
#$ActionQueueFileName fwdRule1 # unique name prefix for spool files
</syntaxhighlight>
#$ActionQueueMaxDiskSpace 1g  # 1gb space limit (use as much as possible)
#$ActionQueueSaveOnShutdown on # save messages to disk on shutdown
#$ActionQueueType LinkedList  # run asynchronously
#$ActionResumeRetryCount -1    # infinite retries if host is down
# remote host is: name/ip:port, e.g. 192.168.0.1:514, port optional
#*.* @@remote-host:514
# ### end of the forwarding rule ###
</source>


==같이 보기==
==같이 보기==
*[[rsyslog]]
* [[CentOS rsyslog.conf]]
*[[/var/log/messages]]
* [[우분투 rsyslog 서버 설정]]
*[[/var/log/secure]]
* [[rsyslog]]
*[[/var/log/maillog]]
* [[syslog.conf, rsyslog.conf]]
*[[/var/log/cron]]
*[[/var/log/spooler]]
*[[/var/log/boot.log]]


[[분류: rsyslog]]
[[분류: /etc]]
[[분류: /etc]]
[[분류: .conf]]

2021년 10월 19일 (화) 15:17 기준 최신판

1 개요[ | ]

/etc/rsyslog.conf

2 우분투 16[ | ]

#  /etc/rsyslog.conf	Configuration file for rsyslog.
#
#			For more information see
#			/usr/share/doc/rsyslog-doc/html/rsyslog_conf.html
#
#  Default logging rules can be found in /etc/rsyslog.d/50-default.conf


#################
#### MODULES ####
#################

module(load="imuxsock") # provides support for local system logging
module(load="imklog")   # provides kernel logging support
#module(load="immark")  # provides --MARK-- message capability

# provides UDP syslog reception
#module(load="imudp")
#input(type="imudp" port="514")

# provides TCP syslog reception
#module(load="imtcp")
#input(type="imtcp" port="514")

# Enable non-kernel facility klog messages
$KLogPermitNonKernelFacility on

###########################
#### GLOBAL DIRECTIVES ####
###########################

#
# Use traditional timestamp format.
# To enable high precision timestamps, comment out the following line.
#
$ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat

# Filter duplicated messages
$RepeatedMsgReduction on

#
# Set the default permissions for all log files.
#
$FileOwner syslog
$FileGroup adm
$FileCreateMode 0640
$DirCreateMode 0755
$Umask 0022
$PrivDropToUser syslog
$PrivDropToGroup syslog

#
# Where to place spool and state files
#
$WorkDirectory /var/spool/rsyslog

#
# Include all config files in /etc/rsyslog.d/
#
$IncludeConfig /etc/rsyslog.d/*.conf

3 우분투 14[ | ]

#  /etc/rsyslog.conf	Configuration file for rsyslog.
#
#			For more information see
#			/usr/share/doc/rsyslog-doc/html/rsyslog_conf.html
#
#  Default logging rules can be found in /etc/rsyslog.d/50-default.conf


#################
#### MODULES ####
#################

$ModLoad imuxsock # provides support for local system logging
$ModLoad imklog   # provides kernel logging support
#$ModLoad immark  # provides --MARK-- message capability

# provides UDP syslog reception
#$ModLoad imudp
#$UDPServerRun 514

# provides TCP syslog reception
#$ModLoad imtcp
#$InputTCPServerRun 514

# Enable non-kernel facility klog messages
$KLogPermitNonKernelFacility on

###########################
#### GLOBAL DIRECTIVES ####
###########################

#
# Use traditional timestamp format.
# To enable high precision timestamps, comment out the following line.
#
$ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat

# Filter duplicated messages
$RepeatedMsgReduction on

#
# Set the default permissions for all log files.
#
$FileOwner syslog
$FileGroup adm
$FileCreateMode 0640
$DirCreateMode 0755
$Umask 0022
$PrivDropToUser syslog
$PrivDropToGroup syslog

#
# Where to place spool and state files
#
$WorkDirectory /var/spool/rsyslog

#
# Include all config files in /etc/rsyslog.d/
#
$IncludeConfig /etc/rsyslog.d/*.conf

4 같이 보기[ | ]

문서 댓글 ({{ doc_comments.length }})
{{ comment.name }} {{ comment.created | snstime }}