Exercise

Logging authpriv.info Messages Exercise

Task

Send authentication messages to a file of your own by adding a rule to rsyslog, then confirm which priorities that one rule catches.

Host
servera
Facility
authpriv
Priority
info
Log location
/var/log/authpriv-info
  1. Add a rule for authpriv.info

    Become root, then create a drop-in file. Files in /etc/rsyslog.d/ are read alongside /etc/rsyslog.conf, so you never edit the main file.

    sudo -i
    vim /etc/rsyslog.d/authpriv-info.conf

    Press i and write one rule: the facility and priority on the left, the destination file on the right.

    authpriv.info /var/log/authpriv-info

    Leave insert mode with Esc, save with :wq, and read it back.

    cat /etc/rsyslog.d/authpriv-info.conf
  2. Restart rsyslog

    rsyslog reads its configuration when it starts, so a new rule does nothing until you restart the service.

    systemctl restart rsyslog
    systemctl status rsyslog --no-pager

    Look for active (running) and a since time of a moment ago, which is how you know the restart took.

  3. Send a test message

    logger writes a message to syslog. -p chooses the facility and priority, which is what decides where the message lands.

    logger -p authpriv.info "Houston, we have a problem."
    cat /var/log/authpriv-info
  4. Confirm higher priorities land in the same file

    A rule naming info catches info and everything more severe. Send two messages well above it, then read back all three you have sent.

    logger -p authpriv.alert "Houston, we have an alert!"
    logger -p authpriv.emerg "Houston, we have an EMERGENCY!"
    tail -n3 /var/log/authpriv-info
    Sep 15 12:18:59 servera root[12652]: Houston, we have a problem.
    Sep 15 12:18:59 servera root[12655]: Houston, we have an alert!
    Sep 15 12:18:59 servera root[12656]: Houston, we have an EMERGENCY!
  5. Clean up

    Remove the rule and the file it created, then restart rsyslog so it forgets them.

    rm -f /etc/rsyslog.d/authpriv-info.conf /var/log/authpriv-info
    systemctl restart rsyslog
    ls /etc/rsyslog.d/