# /etc/rsyslog.conf Configuration file for rsyslog v3. # # For more information see # /usr/share/doc/rsyslog-doc/html/rsyslog_conf.html ################# #### MODULES #### ################# $ModLoad imuxsock # provides support for local system logging $ModLoad imklog # provides kernel logging support (previously done by rklogd) $ModLoad immark # provides --MARK-- message capability $MarkMessagePeriod 900 # mark messages appear every 15 Minutes ########################### #### GLOBAL DIRECTIVES #### ########################### # # Use traditional timestamp format. # To enable high precision timestamps, comment out the following line. # $ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat # # Set the default permissions for all log files. # $FileOwner root $FileGroup adm $FileCreateMode 0640 $DirCreateMode 0755 # # Include all config files in /etc/rsyslog.d/ # $IncludeConfig /etc/rsyslog.d/*.conf ############### #### RULES #### ############### # # Log each facility into its own log auth,authpriv.* /var/log/auth.log cron.* -/var/log/user.log daemon.* -/var/log/daemon.log kern.* -/var/log/kern.log lpr.* -/var/log/lpr.log mail.* -/var/log/mail.log user.* -/var/log/user.log local0,local1,local2,\ local3,local4,local5,\ local6,local7.* -/var/log/local.log # Omitted facilities: syslog, news, uucp, ftp # All logs end up in syslog as weel as the corresponding facility log above # (except for auth, mail which only end up in the facility log for privacy # reasons and debug which only ends up in the debug log below to prevent # flooding). *.*;\ *.!=debug;\ auth,authpriv.none;\ mail.none -/var/log/syslog # Debug entries end up in debug.log as well as the corresponding facility log # above (except for auth and mail, which only end up in the facility logs for # privacy reasons). *.=debug;\ auth,authpriv.none;\ news.none;mail.none -/var/log/debug.log # # Emergencies are sent to everybody logged in. # *.emerg *