Exercise
Logging authpriv.info Messages Exercise
Task
Send authentication messages to a file of your own by adding a rule to rsyslog, then confirm which priorities that one rule catches.
- Host
servera- Facility
authpriv- Priority
info- Log location
/var/log/authpriv-info
-
Add a rule for
authpriv.infoBecome
root, then create a drop-in file. Files in/etc/rsyslog.d/are read alongside/etc/rsyslog.conf, so you never edit the main file.sudo -i vim /etc/rsyslog.d/authpriv-info.confPress i and write one rule: the facility and priority on the left, the destination file on the right.
authpriv.info /var/log/authpriv-infoLeave insert mode with Esc, save with
:wq, and read it back.cat /etc/rsyslog.d/authpriv-info.conf -
Restart rsyslog
rsyslog reads its configuration when it starts, so a new rule does nothing until you restart the service.
systemctl restart rsyslog systemctl status rsyslog --no-pagerLook for
active (running)and asincetime of a moment ago, which is how you know the restart took. -
Send a test message
loggerwrites a message to syslog.-pchooses the facility and priority, which is what decides where the message lands.logger -p authpriv.info "Houston, we have a problem." cat /var/log/authpriv-info -
Confirm higher priorities land in the same file
A rule naming
infocatchesinfoand everything more severe. Send two messages well above it, then read back all three you have sent.logger -p authpriv.alert "Houston, we have an alert!" logger -p authpriv.emerg "Houston, we have an EMERGENCY!" tail -n3 /var/log/authpriv-infoSep 15 12:18:59 servera root[12652]: Houston, we have a problem. Sep 15 12:18:59 servera root[12655]: Houston, we have an alert! Sep 15 12:18:59 servera root[12656]: Houston, we have an EMERGENCY! -
Clean up
Remove the rule and the file it created, then restart rsyslog so it forgets them.
rm -f /etc/rsyslog.d/authpriv-info.conf /var/log/authpriv-info systemctl restart rsyslog ls /etc/rsyslog.d/