User Tools

Site Tools


build:logging

This is an old revision of the document!


Logging

what is logged, to where, reports, and to whom

Access

Installation

syslog.conf

# /etc/syslog.conf Configuration file for syslogd. # # For more information see syslog.conf(5) # manpage.

# # First some standard logfiles. Log by facility. #

auth,authpriv.* /var/log/auth.log *.*;auth,authpriv.none -/var/log/syslog #cron.* /var/log/cron.log daemon.* -/var/log/daemon.log kern.* -/var/log/kern.log lpr.* -/var/log/lpr.log mail.* -/var/log/mail.log user.* -/var/log/user.log uucp.* /var/log/uucp.log

# # Logging for the mail system. Split it up so that # it is easy to write scripts to parse these files. # mail.info -/var/log/mail.info mail.warn -/var/log/mail.warn mail.err /var/log/mail.err

# Logging for INN news system # news.crit /var/log/news/news.crit news.err /var/log/news/news.err news.notice -/var/log/news/news.notice

# # Some `catch-all' logfiles. # *.=debug;\

auth,authpriv.none;\
news.none;mail.none	-/var/log/debug

*.=info;*.=notice;*.=warn;\

auth,authpriv.none;\
cron,daemon.none;\
mail,news.none		-/var/log/messages

# # Emergencies are sent to everybody logged in. # *.emerg *

# # I like to have messages displayed on the console, but only on a virtual # console I usually leave idle. # #daemon,mail.*;\ # news.=crit;news.=err;news.=notice;\ # *.=debug;*.=info;\ # *.=notice;*.=warn /dev/tty8

# The named pipe /dev/xconsole is for the `xconsole' utility. To use it, # you must invoke `xconsole' with the `-file' option: # # $ xconsole -file /dev/xconsole […] # # NOTE: adjust the list below, or you'll go crazy if you have a reasonably # busy site.. # daemon.*;mail.*;\

news.crit;news.err;news.notice;\
*.=debug;*.=info;\
*.=notice;*.=warn	|/dev/xconsole

System Changes

Please post changes here in the format of: [H4] date|your name [/H4] [CR]description of chages made

Feburary 19 2005 | Install Group

Initial instalation of default Debian logging.

TODO

  • Setup daily system checks such as Root Kit Hunter
  • Enable tripwire
  • Determine what admins are to recieve daily log reports

Credits

build/logging.1109949098.txt.gz · Last modified: 2005/03/04 09:20 (external edit)