Today's Posts

SUSE Linux is a major operating system. The developer rights are owned by Novell, Inc.

Location and name of SYSLOG in SUSE Linux

Login to Reply

Thread Tools Search this Thread
# 1  
Old 03-09-2015
Location and name of SYSLOG in SUSE Linux

Esteemed listers,

Where is the location of SYSLOG file?

In etc/auditd.conf script, the log_file location is '/var/log/audit/audit.log' as below. Is this the location where SYSLOG is stored?

Thank you in advance,

log_file = /var/log/audit/audit.log
log_format = RAW
priority_boost = 3
freq = 20
num_logs = 4
dispatcher = /usr/sbin/audispd
disp_qos = lossy
max_log_file = 5
max_log_file_action = ROTATE
space_left = 75
space_left_action = SYSLOG
action_mail_acct = root
admin_space_left = 50
admin_space_left_action = SUSPEND
disk_full_action = SUSPEND
disk_error_action = SUSPEND
# 2  
Old 03-09-2015
Have a look into /etc/*syslog.conf; name dependig on the syslog version used. Here, or in the included files, the log files are identified, like
*.notice;authpriv.none;kern.debug;lpr.info;mail.crit;news.err   /var/log/messages
security.*                                      /var/log/security
auth.info;authpriv.info                         /var/log/auth.log
mail.info                                       /var/log/maillog

# 3  
Old 03-09-2015
On newer SUSE and openSUSE systems, they use systemd. You can install rsyslog and get a /var/log/messages file (for example) and/or the ability to send logs to a remote syslogger, etc...

It's one of the bigger gripes against systemd. It uses its own binary database to house logs. So normally you run a command, journalctl, (if you don't have rsyslog installed) to see the logs.
The Following User Says Thank You to cjcox For This Useful Post:
JDBA (03-10-2015)
# 4  
Old 03-11-2015
In /etc/auditd.conf script
  1. Does this option 'space_left_action = SYSLOG' send log messages to SYSLOG?

  2. Does this option 'space_left_action = EMAIL' send log messages to SYSLOG and email accounts specified?

---------- Post updated at 03:09 PM ---------- Previous update was at 02:56 PM ----------

I think I got the answers for these 2 questions.

---------- Post updated 03-11-15 at 12:19 PM ---------- Previous update was 03-10-15 at 03:09 PM ----------

When I restarted auditd I get a message saying 'exit status of parent...' as below. I expected to see 'Starting auditd' only. Is this normal?

 XXXXX:/#/etc/init.d/auditd restart
 Shutting down auditd
 Starting auditd startproc; exit status of parent of /sbin/auditd: 6

---------- Post updated at 03:09 PM ---------- Previous update was at 12:19 PM ----------

Found the answer.

Last edited by rbatte1; 03-11-2015 at 03:02 PM..
Login to Reply

« Previous Thread | Next Thread »
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Suse Linux CLP 10 Arun.Kakarla UNIX for Dummies Questions & Answers 0 08-18-2010 05:21 AM
Linux suse for AMD hkoolivand SuSE 2 12-05-2006 06:36 AM
Suse LINUX hassan2 SuSE 1 06-24-2004 10:38 AM
suse linux 6.4-8.1 norsk hedensk UNIX for Dummies Questions & Answers 3 12-04-2002 09:29 AM

All times are GMT -4. The time now is 09:24 AM.

Unix & Linux Forums Content Copyright 1993-2018. All Rights Reserved.
Show Password