• 博客访问: 730965
  • 博文数量: 85
  • 博客积分: 2104
  • 博客等级: 大尉
  • 技术积分: 2311
  • 用 户 组: 普通用户
  • 注册时间: 2008-03-19 13:21
个人简介

关注于系统高可用、网站架构

文章分类

全部博文(85)

文章存档

2017年(1)

2015年(4)

2014年(10)

2013年(7)

2012年(14)

2011年(18)

2010年(31)

微信关注

IT168企业级官微



微信号:IT168qiye



系统架构师大会



微信号:SACC2013

订阅
热词专题

分类: 网络与安全

<div style="background-color:#FFFFFF;font-family:微软雅黑;font-size:14px;line-height:21px;white-space:normal;"> <span style="color:#666666;font-family:宋体, Arial;font-size:16px;">rsyslog 是一个 syslogd 的多线程增强版。</span><br style="color:#666666;font-family:宋体, Arial;font-size:16px;" /> <span style="color:#666666;font-family:宋体, Arial;font-size:16px;">rsyslog日志服务器的优势:</span><br style="color:#666666;font-family:宋体, Arial;font-size:16px;" /> <span style="color:#666666;font-family:宋体, Arial;font-size:16px;">1、日志统一,集中式管理</span><br style="color:#666666;font-family:宋体, Arial;font-size:16px;" /> <span style="color:#666666;font-family:宋体, Arial;font-size:16px;">2、日志实时传送到一个更加安全的远端服务器上,真正记录用户行为,使日志的2次更改可能性大大降低,从而能够对日志进行真实回放,便于问题追踪。</span><br style="color:#666666;font-family:宋体, Arial;font-size:16px;" /> <br style="color:#666666;font-family:宋体, Arial;font-size:16px;" /> <strong style="color:#666666;font-family:宋体, Arial;font-size:16px;">客户端机器(发送用户操作记录)</strong><br style="color:#666666;font-family:宋体, Arial;font-size:16px;" /> <span style="color:#666666;font-family:宋体, Arial;font-size:16px;">/etc/profile.d 增加cmd.sh脚本,内容如下</span><br style="color:#666666;font-family:宋体, Arial;font-size:16px;" /> <span style="color:#666666;font-family:宋体, Arial;font-size:16px;">export PROMPT_COMMAND='{ msg=$(history 1 | { read x y; echo $y; });logger &nbsp;-p &nbsp;local3.debug "{euid=$(whoami)]":$(who am i):[`pwd`]"$msg"; }'</span><br style="color:#666666;font-family:宋体, Arial;font-size:16px;" /> <span style="color:#666666;font-family:宋体, Arial;font-size:16px;">注:logger 命令用于产生日志,-p指定日志级别</span><br style="color:#666666;font-family:宋体, Arial;font-size:16px;" /> <span style="color:#666666;font-family:宋体, Arial;font-size:16px;">/etc/rsyslog.conf 增加如下配置</span><br style="color:#666666;font-family:宋体, Arial;font-size:16px;" /> <span style="color:#666666;font-family:宋体, Arial;font-size:16px;">local3.* @@10.160.65.91</span><br style="color:#666666;font-family:宋体, Arial;font-size:16px;" /> <span style="color:#666666;font-family:宋体, Arial;font-size:16px;">authpriv.* &nbsp;@@10.160.65.91</span><br style="color:#666666;font-family:宋体, Arial;font-size:16px;" /> <span style="color:#666666;font-family:宋体, Arial;font-size:16px;">@@表示tcp @表示udp</span><br style="color:#666666;font-family:宋体, Arial;font-size:16px;" /> <span style="color:#666666;font-family:宋体, Arial;font-size:16px;">service rsyslog restart</span><br style="color:#666666;font-family:宋体, Arial;font-size:16px;" /> <br style="color:#666666;font-family:宋体, Arial;font-size:16px;" /> <strong style="color:#666666;font-family:宋体, Arial;font-size:16px;">服务端机器(接收)</strong><br style="color:#666666;font-family:宋体, Arial;font-size:16px;" /> <span style="color:#666666;font-family:宋体, Arial;font-size:16px;">$ModLoad imudp</span><br style="color:#666666;font-family:宋体, Arial;font-size:16px;" /> <span style="color:#666666;font-family:宋体, Arial;font-size:16px;">$UDPServerRun 514</span><br style="color:#666666;font-family:宋体, Arial;font-size:16px;" /> <span style="color:#666666;font-family:宋体, Arial;font-size:16px;">$ModLoad imtcp.so &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;# needs to be done just once #使用tcp方式</span><br style="color:#666666;font-family:宋体, Arial;font-size:16px;" /> <span style="color:#666666;font-family:宋体, Arial;font-size:16px;">$InputTCPServerRun 514 &nbsp; &nbsp; &nbsp;# tcp接收信息的端口</span><br style="color:#666666;font-family:宋体, Arial;font-size:16px;" /> <span style="color:#666666;font-family:宋体, Arial;font-size:16px;">authpriv.* &nbsp;@@serverip</span><br style="color:#666666;font-family:宋体, Arial;font-size:16px;" /> <span style="color:#666666;font-family:宋体, Arial;font-size:16px;">local3.* &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;/var/log/all.log</span><br style="color:#666666;font-family:宋体, Arial;font-size:16px;" /> <span style="color:#666666;font-family:宋体, Arial;font-size:16px;">service rsyslog restart</span><br style="color:#666666;font-family:宋体, Arial;font-size:16px;" /> <br style="color:#666666;font-family:宋体, Arial;font-size:16px;" /> <span style="color:#666666;font-family:宋体, Arial;font-size:16px;">采用logrotate做日志轮转</span><br style="background-color:inherit;" /> </div> <div style="background-color:#FFFFFF;font-family:微软雅黑;font-size:14px;line-height:21px;white-space:normal;"> <span style="color:#666666;font-family:宋体, Arial;font-size:16px;">/etc/logrotate.d/syslog 增加</span> </div> <div style="background-color:#FFFFFF;font-family:微软雅黑;font-size:14px;line-height:21px;white-space:normal;"> <span style="color:#666666;font-family:宋体, Arial;font-size:16px;">/var/log/all.log</span> </div> <div style="background-color:#FFFFFF;font-family:微软雅黑;font-size:14px;line-height:21px;white-space:normal;"> <span style="color:#666666;font-family:宋体, Arial;font-size:16px;">查看轮转过程</span> </div> <div style="background-color:#FFFFFF;font-family:微软雅黑;font-size:14px;line-height:21px;white-space:normal;"> <span style="color:#666666;font-family:宋体, Arial;font-size:16px;">logrotate -vf /etc/logrotate.conf</span> </div> <div> <br /> </div>
阅读(1249) | 评论(0) | 转发(0) |
0

上一篇:centos6下部署django环境

下一篇:ganglia 安装

给主人留下些什么吧!~~
评论热议
请登录后评论。

登录 注册