0.备份、编辑配置文件
cp /etc/rsyslog.conf /etc/rsyslog.conf.bak20210427
vi /etc/rsyslog.conf
1.修改服务端配置,打开服务监听端口:
#### MODULES ####
# The imjournal module bellow is now used as a message source instead of imuxsock.
$ModLoad imuxsock # provides support for local system logging (e.g. via logger command)
$ModLoad imjournal # provides access to the systemd journal
#$ModLoad imklog # reads kernel messages (the same are read from journald)
#$ModLoad immark # provides --MARK-- message capability
# Provides UDP syslog reception
$ModLoad imudp //取消注释
$UDPServerRun 514 //取消注释
# Provides TCP syslog reception
$ModLoad imtcp //取消注释
$InputTCPServerRun 514 //取消注释
2.在客户端的配置中,定义将日志发往服务端:
#### RULES ####
*.* @A.B.C.D //A.B.C.D填写你需要发送的日志服务器的IP,请注意*号与@之间是一个Tab而不是空格,这里“*.*”是将所有日志发送到日志服务器,如果日志服务器空间不够大,可以只发送一些比较重要的日志,如下
*.err @A.B.C.D
*.debug @A.B.C.D
# Log all kernel messages to the console.
# Logging much else clutters up the screen.
#kern.*
3.重启rsyslog服务
/bin/systemctl restart rsyslog.service //个别系统重启命令为service rsyslog restart