[rsyslog-notify] Forum Thread: Re: demolish the syslog system - (Mode 'reply')
noreply at adiscon.com
noreply at adiscon.com
Tue Dec 1 10:52:19 CET 2015
User: venember
Forumlink: http://kb.monitorware.com/viewtopic.php?p=26213#p26213
Message:
----------
journal
Dec 01 10:18:24 mysystem sshd[4702]: error: PAM: Authentication failure for
root from 59.45.79.51
Dec 01 10:18:30 sshd[4748]: error: PAM: Authentication
failure for root from 59.45.79.51
Dec 01 10:18:33 sshd[4748]: error: PAM: Authentication
failure for root from 59.45.79.51
Dec 01 10:18:36 sshd[4748]: error: PAM: Authentication
failure for root from 59.45.79.51
Dec 01 10:18:38 sshd[4748]: error: PAM: Authentication
failure for root from 59.45.79.51
Dec 01 10:18:41 sshd[4748]: error: PAM: Authentication
failure for root from 59.45.79.51
Dec 01 10:18:45 sshd[4748]: error: PAM: Authentication
failure for root from 59.45.79.51
The kern, firewall, syslog, and btmp contain relevant records but not sshd
not exists.
rsyslog.conf
##
## === When you're using remote logging, enable on-disk queues ===
## === in rsyslog.d/remote.conf. When neccesary also set the ===
## === SYSLOG_REQUIRES_NETWORK=yes in /etc/sysconfig/syslog, ===
## === e.g. when rsyslog has to receive on a specific IP only. ===
##
## Note, that when the MYSQL, PGSQL, GSSAPI, GnuTLS or SNMP modules
## (provided in separate rsyslog-module-* packages) are enabled, the
## configuration can't be used on a system with /usr on a remote
## filesystem, except on newer systems where initrd mounts /usr.
## [The modules are linked against libraries installed bellow of
## /usr thus also installed in /usr/lib*/rsyslog because of this.]
##
#
# if you experience problems, check
#
# and report them at
#
# since rsyslog v3: load input modules
# If you do not load inputs, nothing happens!
# provides --MARK-- message capability (every 1 hour)
$ModLoad immark.so
$ModLoad imudp.so
$ModLoad imtcp.so
$MarkMessagePeriod 3600
# provides support for local system logging (e.g. via logger command)
$ModLoad imuxsock.so
# reduce dupplicate log messages (last message repeated n times)
$RepeatedMsgReduction on
# kernel logging (may be also provided by /sbin/klogd)
# see also <!-- m --><a class="postlink"
href="xxxx://www.rsyslog.com/doc-imklog.html">xxxx://www.rsyslog.com/doc-imklog.html</a><!--
m -->.
$ModLoad imklog.so
# set log level 1 (same as in /etc/sysconfig/syslog).
$klogConsoleLogLevel 5
# Use rsyslog native, rfc5424 conform log format as default
# ($ActionFileDefaultTemplate RSYSLOG_FileFormat).
#
# To change a single file to use obsolete BSD syslog format
# (rfc 3164, no high-precision timestamps), set the variable
# bellow or append ";RSYSLOG_FileFormat" to the filename.
# See
#
# for more informations.
#
#$ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat
#
# Include config generated by /etc/init.d/syslog script
# using the SYSLOGD_ADDITIONAL_SOCKET* variables in the
# /etc/sysconfig/syslog file.
#
$IncludeConfig /run/rsyslog/additional-log-sockets.conf
#
# Include config files, that the admin provided? :
#
$IncludeConfig /etc/rsyslog.d/*.conf
###
# print most important on tty10 and on the xconsole pipe
#
if ( \
/* kernel up to warning except of firewall */ \
($syslogfacility-text == 'kern') and \
($syslogseverity <= 4 /* warning */ ) and not \
($msg contains 'IN=' and $msg contains 'OUT=') \
) or ( \
/* up to errors except of facility authpriv */ \
($syslogseverity <= 3 /* errors */ ) and not \
($syslogfacility-text == 'authpriv') \
) \
then {
/dev/tty10
|/dev/xconsole
}
if $programname == 'fail2ban' then /var/log/fail2ban.log
& stop
# Emergency messages to everyone logged on (wall)
*.emerg :omusrmsg:*
# enable this, if you want that root is informed
# immediately, e.g. of logins
#*.alert root
auth,authpriv.* /var/log/auth
*.*;auth,authpriv.none -/var/log/syslog
daemon.* -/var/log/daemon
kern.* -/var/log/kern
lpr.* -/var/log/lpr
mail.* -/var/log/mail
user.* -/var/log/user
*.=debug;\
auth,authpriv.none;\
news.none;mail.none -/var/log/debug
#
# firewall messages into separate file and stop their further processing
#
if ($syslogfacility-text == 'kern') and \
($msg contains 'IN=' and $msg contains 'OUT=') \
then {
-/var/log/firewall
stop
}
#
# acpid messages into separate file and stop their further processing
#
# => all acpid messages for debuging (uncomment if needed):
#if ($programname == 'acpid' or $syslogtag == '[acpid]:') then \
# -/var/log/acpid
#
# => up to notice (skip info and debug)
if ($programname == 'acpid' or $syslogtag == '[acpid]:') and \
($syslogseverity <= 5 /* notice */) \
then {
-/var/log/acpid
stop
}
#
# NetworkManager into separate file and stop their further processing
#
if ($programname == 'NetworkManager') or \
($programname startswith 'nm-') \
then {
-/var/log/NetworkManager
stop
}
#
# email-messages
#
mail.* -/var/log/mail
mail.info -/var/log/mail.info
mail.warning -/var/log/mail.warn
mail.err /var/log/mail.err
#
# news-messages
#
#news.crit -/var/log/news/news.crit
#news.err -/var/log/news/news.err
#news.notice -/var/log/news/news.notice
# enable this, if you want to keep all news messages
# in one file
#news.* -/var/log/news.all
#
# Warnings in one file
#
*.=warning;*.=err -/var/log/warn
*.crit /var/log/warn
#
# the rest in one file
#
*.*;mail.none;news.none -/var/log/messages
#
# enable this, if you want to keep all messages
# in one file
#*.* -/var/log/allmessages
#
# Some foreign boot scripts require local7
#
local0.*;local1.* -/var/log/localmessages
local2.*;local3.* -/var/log/localmessages
local4.*;local5.* -/var/log/localmessages
local6.*;local7.* -/var/log/localmessages
###
More information about the rsyslog-notify
mailing list