linux 启动rsyslog服务_linux服务之rsyslog

本文介绍了Linux系统下如何启动和管理rsyslog服务,结合具体的日志片段展示了系统和服务的日志信息,包括内核模块、kvm虚拟化、系统服务状态等。同时,讲解了日志文件如wtmp、utmp的作用,以及如何通过last、lastlog等命令查看登录记录。此外,还提到了日志轮转工具logrotate的使用,以及在rsyslog与logrotate配合中防止日志丢失的策略。
摘要由CSDN通过智能技术生成

日志片断分析

systemd:服务报出来的信息

kvm:内核模块kvm报出来的信息

kernel: tun: 内核的tun模块报出来的信息

kernel: br0: 内核的br0模块报出来的信息

kernel: kvm [1437] kvm进程为pid1437报出来的信息

Jul 31 11:00:01 localhost systemd: Starting Session 4 of user root.

Jul 31 11:01:01 localhost systemd: Started Session 5 of user root.

Jul 31 11:01:01 localhost systemd: Starting Session 5 of user root.

Jul 31 11:01:55 localhost kvm: 1 guest now active

Jul 31 11:01:55 localhost kernel: tun: Universal TUN/TAP device driver, 1.6

Jul 31 11:01:55 localhost kernel: tun: (C) 1999-2004 Max Krasnyansky

Jul 31 11:01:55 localhost kernel: device tap0 entered promiscuous mode

Jul 31 11:01:55 localhost kernel: br0: port 2(tap0) entered forwarding state

Jul 31 11:01:55 localhost kernel: br0: port 2(tap0) entered forwarding state

Jul 31 11:01:57 localhost kernel: kvm [1437]: vcpu0 disabled perfctr wrmsr: 0xc2 data 0xffff

Jul 31 11:01:57 localhost kernel: kvm [1437]: vcpu0 unhandled rdmsr: 0x570

Jul 31 11:02:10 localhost kernel: br0: port 2(tap0) entered forwarding state

Jul 31 11:02:17 localhost kernel: br0: port 2(tap0) entered disabled state

Jul 31 11:02:17 localhost kernel: device tap0 left promiscuous mode

Jul 31 11:02:17 localhost kernel: br0: port 2(tap0) entered disabled state

Jul 31 11:02:17 localhost kvm: 0 guests now active

Jul 31 11:02:33 localhost kvm: 1 guest now active

Jul 31 11:02:33 localhost kernel: device tap0 entered promiscuous mode

Jul 31 11:02:33 localhost kernel: br0: port 2(tap0) entered forwarding state

Jul 31 11:02:33 localhost kernel: br0: port 2(tap0) entered forwarding state

Jul 31 11:02:48 localhost kernel: br0: port 2(tap0) entered forwarding state

Jul 31 11:02:59 localhost kernel: kvm [1463]: vcpu0 disabled perfctr wrmsr: 0xc2 data 0xffff

Jul 31 11:02:59 localhost kernel: kvm [1463]: vcpu0 unhandled rdmsr: 0x570

Jul 31 11:03:36 localhost systemd: getty@tty1.service has no holdoff time, scheduling restart.

Jul 31 11:03:36 localhost systemd: Started Getty on tty1.

Jul 31 11:03:36 localhost systemd: Starting Getty on tty1...

Jul 31 11:03:58 localhost systemd-logind: New session 6 of user root.

Jul 31 11:03:58 localhost systemd: Started Session 6 of user root.

Jul 31 11:03:58 localhost systemd: Starting Session 6 of user root.

Jul 31 11:10:01 localhost systemd: Started Session 7 of user root.

Jul 31 11:10:01 localhost systemd: Starting Session 7 of user root.

Jul 31 11:11:46 localhost yum[1599]: Installed: pciutils-3.2.1-4.el7.x86_64

http://blog.csdn.net/hxh129/article/details/8089474

格式

日志设备(类型).(连接符号)日志级别   日志处理方式(action)  其中连接符号有.|.=|.!三种

日志设备

注释

日志级别

注释

动作

注释

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值