收集网络设备日志

Linux7的rsyslog服务

如果没有,yum安装一个,我的环境不是最小化安装的Linux系统。

[root@mo ~]# systemctl status rsyslog
● rsyslog.service - System Logging Service
   Loaded: loaded (/usr/lib/systemd/system/rsyslog.service; enabled; vendor preset: enabled)
   Active: active (running) since Tue 2020-07-07 13:49:49 CST; 3 weeks 3 days ago
     Docs: man:rsyslogd(8)
           http://www.rsyslog.com/doc/
 Main PID: 1089 (rsyslogd)
    Tasks: 9
   Memory: 7.4M
   CGroup: /system.slice/rsyslog.service
           └─1089 /usr/sbin/rsyslogd -n

Jul 15 21:46:01 mo rsyslogd[1089]: imjournal: journal reloaded... [v8.24.0-52.el7 try http://www.rsyslog.com/e/0 ]
Jul 18 01:56:01 mo rsyslogd[1089]: imjournal: journal reloaded... [v8.24.0-52.el7 try http://www.rsyslog.com/e/0 ]
Jul 19 03:36:01 mo rsyslogd[1089]:  [origin software="rsyslogd" swVersion="8.24.0-52.el7" x-pid="1089" x-info="http://www.rsyslog.com"] rsyslogd was HUPed
Jul 20 06:01:01 mo rsyslogd[1089]: imjournal: journal reloaded... [v8.24.0-52.el7 try http://www.rsyslog.com/e/0 ]
Jul 22 10:11:01 mo rsyslogd[1089]: imjournal: journal reloaded... [v8.24.0-52.el7 try http://www.rsyslog.com/e/0 ]
Jul 24 14:28:01 mo rsyslogd[1089]: imjournal: journal reloaded... [v8.24.0-52.el7 try http://www.rsyslog.com/e/0 ]
Jul 26 03:08:01 mo rsyslogd[1089]:  [origin software="rsyslogd" swVersion="8.24.0-52.el7" x-pid="1089" x-info="http://www.rsyslog.com"] rsyslogd was HUPed
Jul 26 18:16:01 mo rsyslogd[1089]: imjournal: journal reloaded... [v8.24.0-52.el7 try http://www.rsyslog.com/e/0 ]
Jul 28 22:31:01 mo rsyslogd[1089]: imjournal: journal reloaded... [v8.24.0-52.el7 try http://www.rsyslog.com/e/0 ]
Jul 31 02:39:01 mo rsyslogd[1089]: imjournal: journal reloaded... [v8.24.0-52.el7 try http://www.rsyslog.com/e/0 ]

rsyslog配置设置

1、
需要开启514端口
$ModLoad imtcp
$InputTCPServerRun 514
2、
需要将产生的日志设置规则、并存放在对应的路径下
$template IpTemplate,"/var/log/complogs/switch/%FROMHOST-IP%.log"
:fromhost-ip,isequal,“192.168.40.2” ?IpTemplate
3、
重启rsyslog服务

[root@mo switch]# cat /etc/rsyslog.conf
# rsyslog configuration file

# For more information see /usr/share/doc/rsyslog-*/rsyslog_conf.html
# If you experience problems, see http://www.rsyslog.com/doc/troubleshoot.html

#### MODULES ####

# The imjournal module bellow is now used as a message source instead of imuxsock.
$ModLoad imuxsock # provides support for local system logging (e.g. via logger command)
$ModLoad imjournal # provides access to the systemd journal
#$ModLoad imklog # reads kernel messages (the same are read from journald)
#$ModLoad immark  # provides --MARK-- message capability

# Provides UDP syslog reception
$ModLoad imudp
$UDPServerRun 514

# Provides TCP syslog reception
$ModLoad imtcp
$InputTCPServerRun 514

$template IpTemplate,"/var/log/complogs/switch/%FROMHOST-IP%.log"
  • 0
    点赞
  • 1
    收藏
    觉得还不错? 一键收藏
  • 1
    评论
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值