14.12 Logging (Syslog)
The kernel, various administration tools (PAM, APT, dpkg) and most network services log events and errors to countless files in /var/log. These logging files are extremely useful during the startup of a new service to find configuration errors. When a server is running, logging files can provide clues to security issues.
To avoid the need for each program to implement its own logging functions, the kernel and a number of admin tools and server services make use of central logging functions, usually referred to as syslog. There are various implementations of syslog; the most popular one currently is rsyslogd.
However, not all network services use syslog. In particular, the “big” server services, such as Apache, CUPS, ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access