Monitoring Local Logs

When properly configured, log files are stored in the /var/log/ directory or subdirectories. There are two services associated with Linux operating system logs: the system log (syslog) and kernel log services. You may find different implementations of the syslog function installed by the distribution you have chosen. Newer systems use the newer rsyslog service by default, which supports secure tunneled connections and database management.

The System and Kernel Log Services

The system and kernel log services originated as two different services. However, their functionality has been combined in a single package on most systems. On both Red Hat and Ubuntu systems, the package is named sysklogd and is configured in the /etc/syslog.conf ...

Get Security Strategies in Linux Platforms and Applications, 3rd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.