LinuxQuestions.org
Register a domain and help support LQ
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 04-06-2011, 04:58 PM   #1
Ani
LQ Newbie
 
Registered: Oct 2002
Posts: 27

Rep: Reputation: 0
Syslog.conf Exclude


Slackware 13.1

Hi, I am trying to setup syslog via the syslog.conf file to log everything to /var/log/messages except for specific daemons but it is not working.

I have this in the /etc/syslog.conf file
------------
*.emerg;*.alert;*.crit;*.warning;*.notice;*.info;kern.*;syslog.*;daemon.* -/var/log/messages

This logs everything to messages, but I want to exclude the sshd, crond, and internal-sftp daemons

How would I do this?




I have this
 
Old 04-06-2011, 05:09 PM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1974Reputation: 1974Reputation: 1974Reputation: 1974Reputation: 1974Reputation: 1974Reputation: 1974Reputation: 1974Reputation: 1974Reputation: 1974Reputation: 1974
in standard syslog you can't as there is no concept of a specific daemon within the syslog protocol, only 3 bits of priority (0-7) and 5 bits of facility (0-31). You can use more advanced services like syslog-ng to do pattern matching on the text strings but I'd really wonder why you're doing this. What's wrong with the defaults?
 
Old 04-07-2011, 10:56 AM   #3
Ani
LQ Newbie
 
Registered: Oct 2002
Posts: 27

Original Poster
Rep: Reputation: 0
Thank you for the reply.

I want to segregate out the logs so that stuff related to sshd (etc other daemons) goes to the sshd.log file rather than filling up the messages log.

But I also want the messages log to catch everything else that I don't specify.

So the entry I listed catches everything in the messages log. I need a way to say everything "except" the following.

Last edited by Ani; 04-07-2011 at 10:58 AM.
 
Old 04-07-2011, 11:37 AM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,331
Blog Entries: 55

Rep: Reputation: 3529Reputation: 3529Reputation: 3529Reputation: 3529Reputation: 3529Reputation: 3529Reputation: 3529Reputation: 3529Reputation: 3529Reputation: 3529Reputation: 3529
'man sshd_config', see "SyslogFacility". Set it to any LOCAL.* and reconfigure your syslog.conf to output your chosen facility / priority pair it to a separate log file.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Apache .htaccess - Permission denied. Exclude from httpd.conf ?? SmurfGGM Linux - Server 2 01-14-2011 01:52 AM
Exclude IP address from caching in squid.conf cccc Linux - Server 0 08-07-2010 12:06 PM
Question about syslog.conf. How can I exclude local7.notice from /var/log/messages? huntkey Linux - Server 2 04-25-2009 11:00 AM
exclude certain modules from syslog-ng obijan Linux - General 2 12-06-2007 06:31 PM
syslog.conf s0n|k Linux - Newbie 1 02-27-2006 08:09 PM


All times are GMT -5. The time now is 01:28 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration