Location and name of SYSLOG in SUSE Linux

Thread Tools Search this Thread
# 1  
Old 03-09-2015
Location and name of SYSLOG in SUSE Linux

Esteemed listers,

Where is the location of SYSLOG file?

In etc/auditd.conf script, the log_file location is '/var/log/audit/audit.log' as below. Is this the location where SYSLOG is stored?

Thank you in advance,

log_file = /var/log/audit/audit.log
log_format = RAW
priority_boost = 3
freq = 20
num_logs = 4
dispatcher = /usr/sbin/audispd
disp_qos = lossy
max_log_file = 5
max_log_file_action = ROTATE
space_left = 75
space_left_action = SYSLOG
action_mail_acct = root
admin_space_left = 50
admin_space_left_action = SUSPEND
disk_full_action = SUSPEND
disk_error_action = SUSPEND
# 2  
Old 03-09-2015
Have a look into /etc/*syslog.conf; name dependig on the syslog version used. Here, or in the included files, the log files are identified, like
*.notice;authpriv.none;kern.debug;lpr.info;mail.crit;news.err   /var/log/messages
security.*                                      /var/log/security
auth.info;authpriv.info                         /var/log/auth.log
mail.info                                       /var/log/maillog

# 3  
Old 03-09-2015
On newer SUSE and openSUSE systems, they use systemd. You can install rsyslog and get a /var/log/messages file (for example) and/or the ability to send logs to a remote syslogger, etc...

It's one of the bigger gripes against systemd. It uses its own binary database to house logs. So normally you run a command, journalctl, (if you don't have rsyslog installed) to see the logs.
This User Gave Thanks to cjcox For This Post:
JDBA (03-10-2015)
# 4  
Old 03-11-2015
In /etc/auditd.conf script
  1. Does this option 'space_left_action = SYSLOG' send log messages to SYSLOG?

  2. Does this option 'space_left_action = EMAIL' send log messages to SYSLOG and email accounts specified?

---------- Post updated at 03:09 PM ---------- Previous update was at 02:56 PM ----------

I think I got the answers for these 2 questions.

---------- Post updated 03-11-15 at 12:19 PM ---------- Previous update was 03-10-15 at 03:09 PM ----------

When I restarted auditd I get a message saying 'exit status of parent...' as below. I expected to see 'Starting auditd' only. Is this normal?

 XXXXX:/#/etc/init.d/auditd restart
 Shutting down auditd
 Starting auditd startproc; exit status of parent of /sbin/auditd: 6

---------- Post updated at 03:09 PM ---------- Previous update was at 12:19 PM ----------

Found the answer.

Last edited by rbatte1; 03-11-2015 at 03:02 PM..

Thread Tools Search this Thread
Search this Thread:
Advanced Search

More UNIX and Linux Forum Topics You Might Find Helpful
SUSE Linux coolboys Linux 2 03-06-2012 10:44 AM
Suse Linux CLP 10 Arun.Kakarla UNIX for Dummies Questions & Answers 0 08-18-2010 05:21 AM
SYSLOG Source code location jockey007 UNIX for Advanced & Expert Users 3 11-06-2007 05:04 PM
Raid With Suse Linux Vaughan Filesystems, Disks and Memory 0 10-21-2006 10:35 PM
Suse Linux 9.0 can't login suseli UNIX for Dummies Questions & Answers 0 03-10-2005 06:31 AM
Suse LINUX hassan2 SuSE 1 06-24-2004 10:38 AM
suse linux 6.4-8.1 norsk hedensk UNIX for Dummies Questions & Answers 3 12-04-2002 09:29 AM