简介:
任务一:rsyslog 系统日志管理:关心问题:哪类程序—》产生的什么日志----》放到什么地方
任务二:logrotate日志轮转:将大量的日志,分割管理,删除旧日志。
任务一详解
一、处理日志的进程:第一类
rsyslogd: 系统专职日志程序。
处理绝大部分日志记录,系统操作有关的信息,如登录信息,程序启动关闭信息,错误信息
第二类:
httpd/nginx/mysql: 各类应用程序,可以以自己的方式记录日志.
讲解对应程序时会逐步介绍
观察 rsyslogd程序
[root@localhost ~]# ps aux | grep rsyslogd
root 1836 0.0 0.2 226904 2932 ? Ssl 03:19 0:04 /usr/sbin/rsyslogd -n
root 7217 0.0 0.0 112808 968 pts/0 R+ 12:55 0:00 grep --color=auto rsyslogd
You have new mail in /var/spool/mail/root
[root@localhost ~]#
二、常见的日志文件
查看系统日志文件
[root@localhost log]# tail messages
Aug 7 18:49:01 localhost NetworkManager[770]: <info> [1596797341.1099] dhcp4 (ens33): state changed bound -> bound
Aug 7 18:49:01 localhost dbus[710]: [system] Activating via systemd: service name='org.freedesktop.nm_dispatcher' unit='dbus-org.freedesktop.nm-dispatcher.service'
Aug 7 18:49:01 localhost systemd: Starting Network Manager Script Dispatcher Service...
Aug 7 18:49:01 localhost dhclient[8316]: bound to 192.168.87.132 -- renewal in 873 seconds.
Aug 7 18:49:01 localhost dbus[710]: [system] Successfully activated service 'org.freedesktop.nm_dispatcher'
Aug 7 18:49:01 localhost systemd: Started Network Manager Script Dispatcher Service.
Aug 7 18:49:01 localhost nm-dispatcher: req:1 'dhcp4-change' [ens33]: new request (2 scripts)
Aug 7 18:49:01 localhost nm-dispatcher: req:1 'dhcp4-change' [ens33]: start running ordered scripts...
Aug 7 18:55:34 localhost systemd: Started Session 782 of user root.
Aug 7 18:55:34 localhost systemd-logind: New session 782 of user root.
[root@localhost log]#
//动态查看日志文件的尾部
[root@localhost log]# tailf messages
Aug 7 18:49:01 localhost NetworkManager[770]: <info> [1596797341.1099] dhcp4 (ens33): state changed bound -> bound
Aug 7 18:49:01 localhost dbus[710]: [system] Activating via systemd: service name='org.freedesktop.nm_dispatcher' unit='dbus-org.freedesktop.nm-dispatcher.service'
Aug 7 18:49:01 localhost systemd: Starting Network Manager Script Dispatcher Service...
Aug 7 18:49:01 localhost dhclient[8316]: bound to 192.168.87.132 -- renewal in 873 seconds.
Aug 7 18:49:01 localhost dbus[710]: [system] Successfully activated service 'org.freedesktop.nm_dispatcher'
Aug 7 18:49:01 localhost systemd: Started Network Manager Script Dispatcher Service.
Aug 7 18:49:01 localhost nm-dispatcher: req:1 'dhcp4-change' [ens33]: new request (2 scripts)
Aug 7 18:49:01 localhost nm-dispatcher: req:1 'dhcp4-change' [ens33]: start running ordered scripts...
Aug 7 18:55:34 localhost systemd: Started Session 782 of user root.
Aug 7 18:55:34 localhost systemd-logind: New session 782 of user root.
//认证、安全
[root@localhost log]# tail secure
Aug 6 15:01:04 localhost polkitd[700]: Registered Authentication Agent for unix-process:1865:344098 (system bus name :1.142 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale en_US.UTF-8)
Aug 6 15:01:04 localhost polkitd[700]: Unregistered Authentication Agent for unix-process:1865:344098 (system bus name :1.142, object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale en_US.UTF-8) (disconnected from bus)
Aug 6 15:01:10 localhost polkitd[700]: Registered Authentication Agent for unix-process:1871:344692 (system bus name :1.143 [/usr/bin/pkttyagent --notify-fd 5 --fallback], object path /org/freedesktop/PolicyKit1/AuthenticationAgent, locale en_US.