LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Debian
User Name
Password
Debian This forum is for the discussion of Debian Linux.

Notices


Reply
  Search this Thread
Old 01-23-2023, 09:09 PM   #1
tmick
Member
 
Registered: Jun 2005
Location: North Dakota
Distribution: Debian Testing
Posts: 247

Rep: Reputation: 20
Question Is there a way to get all of your log files in one report


Hi All,
I currently use Logwatch but I can't seem to get it to send me errors from Journald or dmesg.
I've tried installing SIEMs but they need to be a dedicated server and since this is just for my one machine; it's not feasible to do that.

What I'm trying to get is any errors, segfaults, failures from everything in /var/log,journalctl, core dumps and Suricata in one place.
Does anyone know of such a program?
This is for a single home user machine. Nothing fancy just my daily driver.
I've tried to install Prometheus and Prelude and both require a dedicated server.
Thanks for any suggestions or tips in advance.
 
Old 01-24-2023, 12:40 AM   #2
mrmazda
LQ Guru
 
Registered: Aug 2016
Location: SE USA
Distribution: openSUSE 24/7; Debian, Knoppix, Mageia, Fedora, others
Posts: 5,813
Blog Entries: 1

Rep: Reputation: 2068Reputation: 2068Reputation: 2068Reputation: 2068Reputation: 2068Reputation: 2068Reputation: 2068Reputation: 2068Reputation: 2068Reputation: 2068Reputation: 2068
What logging are you looking for that the systemd journal doesn't provide?
Quote:
systemd-journald is a system service that collects and stores logging data. It creates and maintains structured, indexed journals based on logging information that is received from a variety of sources:
  • Kernel log messages, via kmsg
  • Simple system log messages, via the libc syslog(3) call
  • Structured system log messages via the native Journal API, see sd_journal_print(3) and Native Journal Protocol
  • Standard output and standard error of service units....
  • Audit records, originating from the kernel audit subsystem
The daemon will implicitly collect numerous metadata fields for each log messages in a secure and unfakeable way. See systemd.journal-fields(7) for more information about the collected metadata....
https://www.freedesktop.org/software...d.service.html
 
Old 01-24-2023, 12:28 PM   #3
tmick
Member
 
Registered: Jun 2005
Location: North Dakota
Distribution: Debian Testing
Posts: 247

Original Poster
Rep: Reputation: 20
What journal doesn't provide is an interface to Logwatch. (Maybe I'm missing something or not understanding how to get it to send correctly)
I want to get some type of report that will "auto-magically" list errors/alerts in the system.
So if a program starts to segfault or goes to a zombie process etc. I get an email.
I'm kind of surprised nobody has created something like this already. If I didn't suck at programming I'd create my own.
It would be a "log file aggregator" that alerts if certain "keywords" are found. For example Segfault, fail, failure, error etc.
It would contain the Program, number of times the problem occurs, and the messages thrown.
Example"
Program FOO_BAR segfaulted 3 times
Segfault report follows the above line.

Program Suricata found suspicious activity on interface WiFi1
Martian logged from 10.2.0.5 on WiFi1 192.18.1.126
That sort of thing, make sense??
 
Old 01-24-2023, 08:20 PM   #4
syg00
LQ Veteran
 
Registered: Aug 2003
Location: Australia
Distribution: Lots ...
Posts: 21,130

Rep: Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121
Quote:
Originally Posted by tmick View Post
What journal doesn't provide is an interface to Logwatch. (Maybe I'm missing something or not understanding how to get it to send correctly)
Quite possibly - I see a few references to a *journalctl keyword, but no obvious doco online. Maybe in the files shipped with the product.

Not a user of logwatch.
 
1 members found this post helpful.
Old 01-26-2023, 06:43 AM   #5
Jan K.
Member
 
Registered: Apr 2019
Location: Esbjerg
Distribution: Windows 7...
Posts: 773

Rep: Reputation: 489Reputation: 489Reputation: 489Reputation: 489Reputation: 489
Searched for a logfile handler long time ago, lost interest in logs but just had a search...


Nice collection here https://www.ubuntupit.com/best-linux...agement-tools/

I like the look of Graylog. And LogWatch! Nagios?

They should all have what you requested.
 
1 members found this post helpful.
Old 01-27-2023, 03:11 PM   #6
tmick
Member
 
Registered: Jun 2005
Location: North Dakota
Distribution: Debian Testing
Posts: 247

Original Poster
Rep: Reputation: 20
Sad thing is I'm currently using Logwatch. Maybe I need to reread the documentation, but I can't figure out how to pull in things like systemd-coredump and Suricata.
I just want to be alerted if something starts to break.
PS Gray log or Nagios looks like options as well.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to log internal-sftp chroot jailed users access log to /var/log/sftp.log file LittleMaster Linux - Server 0 09-04-2018 03:45 PM
Is there any way to get all dependencies of a software in one package or any alterna RAJD Linux - Newbie 7 02-19-2012 06:46 PM
Kubuntu - Is there a way to install all necessary lib files in one shot? zion_rulz Linux - Distributions 2 05-29-2009 07:21 AM
Lire (log analysis, log report) no report in Mandriva 2005 LE (desktop usage) Emmanuel_uk Mandriva 0 01-16-2006 02:11 AM
Is there a way to get log files emailed? Pcghost Linux - General 2 02-20-2003 01:03 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Debian

All times are GMT -5. The time now is 09:00 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration