加入收藏 | 设为首页 | 会员中心 | 我要投稿 济南站长网 (https://www.0531zz.com/)- 科技、建站、经验、云计算、5G、大数据,站长网!
当前位置: 首页 > 服务器 > 搭建环境 > Linux > 正文

Common Linux log files name and usage--reference

发布时间:2021-01-24 03:29:30 所属栏目:Linux 来源:网络整理
导读:副标题#e# div id="post-body-7256318887016413630" class="post-single-body post-body" div dir="ltr"If you spend lot of time in Linux environment,it is essential that you know where the log files are located,and what is contained in each and
副标题[/!--empirenews.page--]

<div id="post-body-7256318887016413630" class="post-single-body post-body">
<div dir="ltr">If you spend lot of time in Linux environment,it is essential that you know where the log files are located,and what is contained in each and every log file.When your system is running smoothly,take some time to learn and understand the content of various log files,which will help you when there is a crisis and you have to look though the log files to identify the issue./etc/rsyslog.conf controls what goes inside some of the log files. For example,following is the entry in rsyslog.conf for /var/log/messages.<div class="block-panel">
$ grep "/var/log/messages" /etc/rsyslog.conf*.info;mail.none;authpriv.none;cron.none?/var/log/messages?

In the above output,.info indicates that all logs with type INFO will be logged.mail.none,authpriv.none,cron.none indicates that those error messages should not be logged into the /var/log/messages file.You can also specify .none,which indicates that none of the log messages will be logged.The following are the 20 different log files that are located under /var/log/ directory. Some of these log files are distribution specific. For example,you’ll see dpkg.log on Debian based systems (for example,on Ubuntu)./var/log/messages– Contains global system messages,including the messages that are logged during system startup. There are several things that are logged in /var/log/messages including mail,cron,daemon,kern,auth,etc./var/log/dmesg– Contains kernel ring buffer information. When the system boots up,it prints number of messages on the screen that displays information about the hardware devices that the kernel detects during boot process. These messages are available in kernel ring buffer and whenever the new message comes the old message gets overwritten. You can also view the content of this file using the dmesg command./var/log/auth.log?– Contains system authorization information,including user logins and authentication machinsm that were used./var/log/boot.log?– Contains information that are logged when the system boots/var/log/daemon.log?– Contains information logged by the various background daemons that runs on the system/var/log/dpkg.log?– Contains information that are logged when a package is installed or removed using dpkg command/var/log/kern.log?– Contains information logged by the kernel. Helpful for you to troubleshoot a custom-built kernel./var/log/lastlog– Displays the recent login information for all the users. This is not an ascii file. You should use lastlog command to view the content of this file./var/log/maillog?/var/log/mail.log?– Contains the log information from the mail server that is running on the system. For example,sendmail logs information about all the sent items to this file/var/log/user.log?– Contains information about all user level logs/var/log/Xorg.x.log?– Log messages from the X/var/log/alternatives.log?– Information by the update-alternatives are logged into this log file. On Ubuntu,update-alternatives maintains symbolic links determining default commands./var/log/btmp?(lastb command; shows all bad login attempts) /var/log/wtmp (displays all users logged in and out since the file is created...last command;login attempts)– This file contains information about failed login attemps. Use the last command to view the btmp file. For example,“last -f /var/log/btmp | more”/var/log/cups– All printer and printing related log messages/var/log/anaconda.log?– When you install Linux,all installation related messages are stored in this log file/var/log/yum.log?– Contains information that are logged when a package is installed using yum/var/log/cron– Whenever cron daemon(or anacron) starts a cron job,it logs the information about the cron job in this file/var/log/secure– Contains information related to authentication and authorization privileges. For example,sshd logs all the messages here,including unsuccessful login./var/log/wtmp or /var/log/utmp– Contains login records. Using wtmp you can find out who is logged into the system. who command uses this file to display the information./var/log/faillog– Contains user failed login attemps. Use faillog command to display the content of this file.Apart from the above log files,/var/log directory may also contain the following sub-directories depending on the application that is running on your system./var/log/httpd/ (or) /var/log/apache2– Contains the apache web server access_log and error_log/var/log/lighttpd/– Contains light HTTPD access_log and error_log/var/log/conman/– Log files for ConMan client. conman connects remote consoles that are managed by conmand daemon./var/log/mail/– This subdirectory contains additional logs from your mail server. For example,sendmail stores the collected mail statistics in /var/log/mail/statistics file/var/log/prelink/– prelink program modifies shared libraries and linked binaries to speed up the startup process./var/log/prelink/prelink.log?contains the information about the .so file that was modified by the prelink./var/log/audit/– Contains logs information stored by the Linux audit daemon (auditd)./var/log/setroubleshoot/– SELinux uses setroubleshootd (SE Trouble Shoot Daemon) to notify about issues in the security context of files,and logs those information in this log file./var/log/samba/– Contains log information stored by samba,which is used to connect Windows to Linux./var/log/sa/– Contains the daily sar files that are collected by the sysstat package./var/log/sssd/– Use by system security services daemon that manage access to remote directories and authentication mechanisms.Viewing huge log files for trouble shooting is a mundane routine tasks for sysadmins and programmers. In this article,let us review how to effectively view and manipulate huge log files using 10 awesome examples.Example 1: Display specific lines (based on line number) of a file using sed commandView only the specific lines mentioned by line numbers.<div class="block-panel">
Syntax:?$ sed -n -e Xp -e Yp FILENAMEsed : sed command,which will print all the lines by default.-n : Suppresses output.-e CMD : Command to be executedXp: Print line number XYp: Print line number YFILENAME : name of the file to be processed.The example mentioned below will print the lines 120,145,1050 from the syslog.$ sed -n -e 120p -e 145p -e 1050p /var/log/syslog

(编辑:济南站长网)

【声明】本站内容均来自网络,其相关言论仅代表作者个人观点,不代表本站立场。若无意侵犯到您的权利,请及时与联系站长删除相关内容!

热点阅读