Rev 192 | Go to most recent revision | Blame | Compare with Previous | Last modification | View Log | RSS feed
# rsyslog configuration file# For more information see /usr/share/doc/rsyslog-*/rsyslog_conf.html# or latest version online at http://www.rsyslog.com/doc/rsyslog_conf.html# If you experience problems, see http://www.rsyslog.com/doc/troubleshoot.html#### MODULES ####module(load="imuxsock" # provides support for local system logging (e.g. via logger command)SysSock.Use="off") # Turn off message reception via local log socket;# local messages are retrieved through imjournal now.module(load="imjournal" # provides access to the systemd journalStateFile="imjournal.state") # File to store the position in the journal#module(load="imklog") # reads kernel messages (the same are read from journald)#module(load="immark") # provides --MARK-- message capability# Provides UDP syslog reception# for parameters see http://www.rsyslog.com/doc/imudp.htmlmodule(load="imudp") # needs to be done just onceinput(type="imudp" port="514")# Provides TCP syslog reception# for parameters see http://www.rsyslog.com/doc/imtcp.htmlmodule(load="imtcp") # needs to be done just onceinput(type="imtcp" port="514")#### GLOBAL DIRECTIVES ##### Where to place auxiliary filesglobal(workDirectory="/var/lib/rsyslog")# Use default timestamp formatmodule(load="builtin:omfile" Template="RSYSLOG_TraditionalFileFormat")# Include all config files in /etc/rsyslog.d/include(file="/etc/rsyslog.d/*.conf" mode="optional")#### RULES ##### Log all kernel messages to the console.# Logging much else clutters up the screen.#kern.* /dev/console# Log anything (except mail) of level info or higher.# Don't log private authentication messages!*.info;mail.none;authpriv.none;cron.none /var/log/messages# The authpriv file has restricted access.authpriv.* /var/log/secure# Log all the mail messages in one place.mail.* -/var/log/maillog# Log cron stuffcron.* /var/log/cron# Everybody gets emergency messages*.emerg :omusrmsg:*# Save news errors of level crit and higher in a special file.uucp,news.crit /var/log/spooler# Save boot messages also to boot.loglocal7.* /var/log/boot.log# ### sample forwarding rule ####action(type="omfwd"# An on-disk queue is created for this action. If the remote host is# down, messages are spooled to disk and sent when it is up again.#queue.filename="fwdRule1" # unique name prefix for spool files#queue.maxdiskspace="1g" # 1gb space limit (use as much as possible)#queue.saveonshutdown="on" # save messages to disk on shutdown#queue.type="LinkedList" # run asynchronously#action.resumeRetryCount="-1" # infinite retries if host is down# Remote Logging (we use TCP for reliable delivery)# remote_host is: name/ip, e.g. 192.168.0.1, port optional e.g. 10514#Target="remote_host" Port="XXX" Protocol="tcp")$ModLoad ommysql*.* :ommysql:127.0.0.1,Syslog,rsyslog,rsyslog