Implementing Logging Services
Christine Bresnahan, Richard A. Blum · 2019
This chapter explores the two most popular logging methods used in Linux distributions, rsyslog and systemd-journald. First, the chapter explains Linux logging principles to help give you an idea of what logging is all about. Then the chapter discusses both the rsyslogd and the systemd-journald methods of generating logs. All Linux distributions implement some method of logging. Logging directs short messages that indicate what events happen, and when they happen, to users, files, or even remote hosts for storage. If something goes wrong, the Linux administrator can review the log entries to help determine the cause of the problem. The rsyslog package uses the rsyslogd program to monitor events and log them as directed, using the /etc/rsyslog.conf confi guration fi le to define what events to listen for and how to handle them. Many Linux distributions also use a /etc/rsyslog.d directory to store individual configuration files that are included as part of the rsyslog.conf configuration.