ºìÁªLinuxÃÅ»§
Linux°ïÖú

ÉîÈëÀí½âLinuxϵͳµÄÈÕÖ¾

·¢²¼Ê±¼ä:2006-08-22 10:39:27À´Ô´:ºìÁª×÷Õß:flycocoon
1. ÈÕÖ¾¼ò½é
ÔÚLinuxϵͳÖУ¬ÓÐÈý¸öÖ÷ÒªµÄÈÕÖ¾×Óϵͳ£º
Á¬½Óʱ¼äÈÕÖ¾--Óɶà¸ö³ÌÐòÖ´ÐУ¬°Ñ¼Í¼дÈëµ½/var/log/wtmpºÍ/var/run/utmp£¬loginµÈ³ÌÐò¸üÐÂwtmpºÍutmpÎļþ£¬Ê¹ÏµÍ³¹ÜÀíÔ±Äܹ»¸ú×ÙË­ÔÚºÎʱµÇ¼µ½ÏµÍ³¡£
½ø³Ìͳ¼Æ--ÓÉϵͳÄÚºËÖ´ÐС£µ±Ò»¸ö½ø³ÌÖÕֹʱ£¬ÎªÃ¿¸ö½ø³ÌÍù½ø³Ìͳ¼ÆÎļþ£¨pacct»òacct£©ÖÐдһ¸ö¼Í¼¡£½ø³Ìͳ¼ÆµÄÄ¿µÄÊÇΪϵͳÖеĻù±¾·þÎñÌṩÃüÁîʹÓÃͳ¼Æ¡£
´íÎóÈÕÖ¾--ÓÉsyslogd£¨8£©Ö´ÐС£¸÷ÖÖÏµÍ³ÊØ»¤½ø³Ì¡¢Óû§³ÌÐòºÍÄÚºËͨ¹ýsyslog£¨3£©ÏòÎļþ/var/log/messages±¨¸æÖµµÃ×¢ÒâµÄʼþ¡£ÁíÍâÓÐÐí¶àUNIX³ÌÐò´´½¨ÈÕÖ¾¡£ÏñHTTPºÍFTPÕâÑùÌá¹©ÍøÂç·þÎñµÄ·þÎñÆ÷Ò²±£³ÖÏêϸµÄÈÕÖ¾¡£
³£ÓõÄÈÕÖ¾ÎļþÈçÏ£º

access-log ¼Í¼HTTP/webµÄ´«Êä
acct/pacct ¼Í¼Óû§ÃüÁî
aculog ¼Í¼MODEMµÄ»î¶¯
btmp ¼Í¼ʧ°ÜµÄ¼Í¼
lastlog ¼Í¼×î½ü¼¸´Î³É¹¦µÇ¼µÄʼþºÍ×îºóÒ»´Î²»³É¹¦µÄµÇ¼
messages ´ÓsyslogÖмǼÐÅÏ¢£¨ÓеÄÁ´½Óµ½syslogÎļþ£©
sudolog ¼Í¼ʹÓÃsudo·¢³öµÄÃüÁî
sulog ¼Í¼ʹÓÃsuÃüÁîµÄʹÓÃ
syslog ´ÓsyslogÖмǼÐÅÏ¢£¨Í¨³£Á´½Óµ½messagesÎļþ£©
utmp ¼Í¼µ±Ç°µÇ¼µÄÿ¸öÓû§
wtmp Ò»¸öÓû§Ã¿´ÎµÇ¼½øÈëºÍÍ˳öʱ¼äµÄÓÀ¾Ã¼Í¼
xferlog ¼Í¼FTP»á»°

utmp¡¢wtmpºÍlastlogÈÕÖ¾ÎļþÊǶàÊýÖØÓÃUNIXÈÕÖ¾×ÓϵͳµÄ¹Ø¼ü--±£³ÖÓû§µÇ¼½øÈëºÍÍ˳öµÄ¼Í¼¡£Óйص±Ç°µÇ¼Óû§µÄÐÅÏ¢¼Ç¼ÔÚÎļþutmpÖУ»µÇ¼½øÈëºÍÍ˳ö¼Í¼ÔÚÎļþwtmpÖУ»×îºóÒ»´ÎµÇ¼Îļþ¿ÉÒÔÓÃlastlogÃüÁî²ì¿´¡£Êý¾Ý½»»»¡¢¹Ø»úºÍÖØÆðÒ²¼Ç¼ÔÚwtmpÎļþÖС£ËùÓеļͼ¶¼°üº¬Ê±¼ä´Á¡£ÕâЩÎļþ£¨lastlogͨ³£²»´ó£©ÔÚ¾ßÓдóÁ¿Óû§µÄϵͳÖÐÔö³¤Ê®·ÖѸËÙ¡£ÀýÈçwtmpÎļþ¿ÉÒÔÎÞÏÞÔö³¤£¬³ý·Ç¶¨ÆÚ½ØÈ¡¡£Ðí¶àϵͳÒÔÒ»Ìì»òÕßÒ»ÖÜΪµ¥Î»°ÑwtmpÅäÖóÉÑ­»·Ê¹Óá£Ëüͨ³£ÓÉcronÔËÐеĽű¾À´Ð޸ġ£ÕâЩ½Å±¾ÖØÐÂÃüÃû²¢Ñ­»·Ê¹ÓÃwtmpÎļþ¡£Í¨³££¬wtmpÔÚµÚÒ»Ìì½áÊøºóÃüÃûΪwtmp.1£»µÚ¶þÌìºówtmp
.1±äΪwtmp.2µÈµÈ£¬Ö±µ½wtmp.7¡£

ÿ´ÎÓÐÒ»¸öÓû§µÇ¼ʱ£¬login³ÌÐòÔÚÎļþlastlogÖв쿴Óû§µÄUID¡£Èç¹ûÕÒµ½ÁË£¬Ôò°ÑÓû§ÉϴεǼ¡¢Í˳öʱ¼äºÍÖ÷»úÃûдµ½±ê×¼Êä³öÖУ¬È»ºólogin³ÌÐòÔÚlastlogÖмͼеĵǼʱ¼ä¡£ÔÚеÄlastlog¼Í¼дÈëºó£¬utmpÎļþ´ò¿ª²¢²åÈëÓû§µÄutmp¼Í¼¡£¸Ã¼Í¼һֱÓõ½Óû§µÇ¼Í˳öʱɾ³ý¡£utmpÎļþ±»¸÷ÖÖÃüÁîÎļþʹÓ㬰üÀ¨who¡¢w¡¢usersºÍfinger¡£
ÏÂÒ»²½£¬login³ÌÐò´ò¿ªÎļþwtmp¸½¼ÓÓû§µÄutmp¼Í¼¡£µ±Óû§µÇ¼Í˳öʱ£¬¾ßÓиüÐÂʱ¼ä´ÁµÄͬһutmp¼Í¼¸½¼Óµ½ÎļþÖС£wtmpÎļþ±»³ÌÐòlastºÍacʹÓá£

2. ¾ßÌåÃüÁî
wtmpºÍutmpÎļþ¶¼ÊǶþ½øÖÆÎļþ£¬ËûÃDz»Äܱ»ÖîÈçtailÃüÁî¼ôÌù»òºÏ²¢£¨Ê¹ÓÃcatÃüÁ¡£Óû§ÐèҪʹÓÃwho¡¢w¡¢users¡¢lastºÍacÀ´Ê¹ÓÃÕâÁ½¸öÎļþ°üº¬µÄÐÅÏ¢¡£
who£ºwhoÃüÁî²éѯutmpÎļþ²¢±¨¸æµ±Ç°µÇ¼µÄÿ¸öÓû§¡£WhoµÄȱʡÊä³ö°üÀ¨Óû§Ãû¡¢ÖÕ¶ËÀàÐÍ¡¢µÇ¼ÈÕÆÚ¼°Ô¶³ÌÖ÷»ú¡£ÀýÈ磺who£¨»Ø³µ£©ÏÔʾ

chyang pts/0 Aug 18 15:06
ynguo pts/2 Aug 18 15:32
ynguo pts/3 Aug 18 13:55
lewis pts/4 Aug 18 13:35
ynguo pts/7 Aug 18 14:12
ylou pts/8 Aug 18 14:15

Èç¹ûÖ¸Ã÷ÁËwtmpÎļþÃû£¬ÔòwhoÃüÁî²éѯËùÓÐÒÔǰµÄ¼Í¼¡£ÃüÁîwho /var/log/wtmp½«±¨¸æ×Ô´ÓwtmpÎļþ´´½¨»òɾ¸ÄÒÔÀ´µÄÿһ´ÎµÇ¼¡£
w£ºwÃüÁî²éѯutmpÎļþ²¢ÏÔʾµ±Ç°ÏµÍ³ÖÐÿ¸öÓû§ºÍËüËùÔËÐеĽø³ÌÐÅÏ¢¡£
ÀýÈ磺w£¨»Ø³µ£©ÏÔʾ£º

3:36pm up 1 day, 22:34, 6 users, load average: 0.23, 0.29, 0.27
USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT
chyang pts/0 202.38.68.242 3:06pm 2:04 0.08s 0.04s -bash
ynguo pts/2 202.38.79.47 3:32pm 0.00s 0.14s 0.05s w
lewis pts/3 202.38.64.233 1:55pm 30:39 0.27s 0.22s -bash
lewis pts/4 202.38.64.233 1:35pm 6.00s 4.03s 0.01s sh /home/users/
ynguo pts/7 simba.nic.ustc.e 2:12pm 0.00s 0.47s 0.24s telnet mail
ylou pts/8 202.38.64.235 2:15pm 1:09m 0.10s 0.04s -bash

users£ºusersÓõ¥¶ÀµÄÒ»ÐдòÓ¡³öµ±Ç°µÇ¼µÄÓû§£¬Ã¿¸öÏÔʾµÄÓû§Ãû¶ÔÓ¦Ò»¸öµÇ¼»á»°¡£Èç¹ûÒ»¸öÓû§Óв»Ö¹Ò»¸öµÇ¼»á»°£¬ÄÇËûµÄÓû§Ãû½«ÏÔʾÏàͬµÄ´ÎÊý¡£
ÀýÈ磺user s£¨»Ø³µ£©ÏÔʾ£º

chyang lewis lewis ylou ynguo ynguo
last£ºlastÃüÁîÍù»ØËÑË÷wtmpÀ´ÏÔʾ×Ô´ÓÎļþµÚÒ»´Î´´½¨ÒÔÀ´µÇ¼¹ýµÄÓû§¡£

ÀýÈ磺
chyang pts/9 202.38.68.242 Tue Aug 1 08:34 - 11:23 (02:49)
cfan pts/6 202.38.64.224 Tue Aug 1 08:33 - 08:48 (00:14)
chyang pts/4 202.38.68.242 Tue Aug 1 08:32 - 12:13 (03:40)
lewis pts/3 202.38.64.233 Tue Aug 1 08:06 - 11:09 (03:03)
lewis pts/2 202.38.64.233 Tue Aug 1 07:56 - 11:09 (03:12)

Èç¹ûÖ¸Ã÷ÁËÓû§£¬ÄÇôlastÖ»±¨¸æ¸ÃÓû§µÄ½üÆÚ»î¶¯£¬
ÀýÈ磺last ynguo£¨»Ø³µ£©ÏÔʾ £º

ynguo pts/4 simba.nic.ustc.e Fri Aug 4 16:50 - 08:20 (15:30)
ynguo pts/4 simba.nic.ustc.e Thu Aug 3 23:55 - 04:40 (04:44)
ynguo pts/11 simba.nic.ustc.e Thu Aug 3 20:45 - 22:02 (01:16)
ynguo pts/0 simba.nic.ustc.e Thu Aug 3 03:17 - 05:42 (02:25)
ynguo pts/0 simba.nic.ustc.e Wed Aug 2 01:04 - 03:16 1+02:12)
ynguo pts/0 simba.nic.ustc.e Wed Aug 2 00:43 - 00:54 (00:11)
ynguo pts/9 simba.nic.ustc.e Thu Aug 1 20:30 - 21:26 (00:55)

ac£ºacÃüÁî¸ù¾Ýµ±Ç°µÄ/var/log/wtmpÎļþÖеĵǼ½øÈëºÍÍ˳öÀ´±¨¸æÓû§Á¬½áµÄʱ¼ä£¨Ð¡Ê±£©£¬Èç¹û²»Ê¹ÓñêÖ¾£¬Ôò±¨¸æ×ܵÄʱ¼ä¡£
ÀýÈ磺ac£¨»Ø³µ£©ÏÔʾ£ºtotal 5177.47 ac -d£¨»Ø³µ£©ÏÔʾÿÌìµÄ×ܵÄÁ¬½áʱ¼ä

Aug 12 total 261.87
Aug 13 total 351.39
Aug 14 total 396.09
Aug 15 total 462.63
Aug 16 total 270.45
Aug 17 total 104.29
Today total 179.02

ac -p £¨»Ø³µ£©ÏÔʾÿ¸öÓû§µÄ×ܵÄÁ¬½Óʱ¼ä
ynguo 193.23
yucao 3.35
rong 133.40
hdai 10.52
zjzhu 52.87
zqzhou 13.14
liangliu 24.34
total 5178.24

lastlog£ºlastlogÎļþÔÚÿ´ÎÓÐÓû§µÇ¼ʱ±»²éѯ¡£¿ÉÒÔʹÓÃlastlogÃüÁîÀ´¼ì²éÄ³ÌØ¶¨Óû§ÉϴεǼµÄʱ¼ä£¬²¢¸ñʽ»¯Êä³öÉϴεǼÈÕÖ¾/var/log/lastlogµÄÄÚÈÝ¡£Ëü¸ù¾ÝUIDÅÅÐòÏÔʾµÇ¼Ãû¡¢¶Ë¿ÚºÅ£¨tty£©ºÍÉϴεǼʱ¼ä¡£Èç¹ûÒ»¸öÓû§´ÓδµÇ¼¹ý£¬lastlogÏÔʾ"**Never logged**¡£×¢ÒâÐèÒªÒÔrootÔËÐиÃÃüÁ
ÀýÈ磺
rong 5 202.38.64.187 Fri Aug 18 15:57:01 +0800 2000
dbb **Never logged in**
xinchen **Never logged in**
pb9511 **Never logged in**
xchen 0 202.38.64.190 Sun Aug 13 10:01:22 +0800 2000

ÁíÍ⣬¿ÉÒ»¼ÓһЩ²ÎÊý£¬ÀýÈ磬last -u 102½«±¨¸æUIDΪ102µÄÓû§£»last -t 7±íʾÏÞÖÆÉÏÒ»Öܵı¨¸æ¡£

3. ½ø³Ìͳ¼Æ
UNIX¿ÉÒÔ¸ú×Ùÿ¸öÓû§ÔËÐеÄÿÌõÃüÁÈç¹ûÏëÖªµÀ×òÍíŪÂÒÁËÄÄÐ©ÖØÒªµÄÎļþ£¬½ø³Ìͳ¼Æ×Óϵͳ¿ÉÒÔ¸æËßÄã¡£Ëü¶Ô»¹¸ú×ÙÒ»¸öÇÖÈëÕßÓаïÖú¡£ÓëÁ¬½Óʱ¼äÈÕÖ¾²»Í¬£¬½ø³Ìͳ¼Æ×Óϵͳȱʡ²»¼¤»î£¬Ëü±ØÐëÆô¶¯¡£ÔÚLinuxϵͳÖÐÆô¶¯½ø³Ìͳ¼ÆÊ¹ÓÃacctonÃüÁ±ØÐëÓÃrootÉí·ÝÀ´ÔËÐС£AcctonÃüÁîµÄÐÎʽaccton file£¬file±ØÐëÏÈ´æÔÚ¡£ÏÈʹÓÃtouchÃüÁîÀ´´´½¨pacctÎļþ£ºtouch /var/log/pacct£¬È»ºóÔËÐÐaccton£º accton /var/log/pacct¡£Ò»µ©accton±»¼¤»î£¬¾Í¿ÉÒÔʹÓÃlastcommÃüÁî¼à²âϵͳÖÐÈκÎʱºòÖ´ÐеÄÃüÁî¡£ÈôÒª¹Ø±Õͳ¼Æ£¬¿ÉÒÔʹÓò»´øÈκβÎÊýµÄacctonÃüÁî¡£

lastcommÃüÁ¸æÒÔǰִÐеÄÎļþ¡£²»´ø²ÎÊýʱ£¬lastcommÃüÁîÏÔʾµ±Ç°Í³¼ÆÎļþÉúÃüÖÜÆÚÄڼͼµÄËùÓÐÃüÁîµÄÓйØÐÅÏ¢¡£°üÀ¨ÃüÁîÃû¡¢Óû§¡¢tty¡¢ÃüÁ·ÑµÄCPUʱ¼äºÍÒ»¸öʱ¼ä´Á¡£Èç¹ûϵͳÓÐÐí¶àÓû§£¬ÊäÈëÔò¿ÉÄܺܳ¤¡£ÏÂÃæµÄÀý×Ó£º

crond F root ?? 0.00 secs Sun Aug 20 00:16
promisc_check.s S root ?? 0.04 secs Sun Aug 20 00:16
promisc_check root ?? 0.01 secs Sun Aug 20 00:16
grep root ?? 0.02 secs Sun Aug 20 00:16
tail root ?? 0.01 secs Sun Aug 20 00:16
sh root ?? 0.01 secs Sun Aug 20 00:15
ping S root ?? 0.01 secs Sun Aug 20 00:15
ping6.pl F root ?? 0.01 secs Sun Aug 20 00:15
sh root ?? 0.01 secs Sun Aug 20 00:15
ping S root ?? 0.02 secs Sun Aug 20 00:15
ping6.pl F root ?? 0.02 secs Sun Aug 20 00:15
sh root ?? 0.02 secs Sun Aug 20 00:15
ping S root ?? 0.00 secs Sun Aug 20 00:15
ping6.pl F root ?? 0.01 secs Sun Aug 20 00:15
sh root ?? 0.01 secs Sun Aug 20 00:15
ping S root ?? 0.01 secs Sun Aug 20 00:15
sh root ?? 0.02 secs Sun Aug 20 00:15
ping S root ?? 1.34 secs Sun Aug 20 00:15
locate root ttyp0 1.34 secs Sun Aug 20 00:15
accton S root ttyp0 0.00 secs Sun Aug 20 00:15

½ø³Ìͳ¼ÆµÄÒ»¸öÎÊÌâÊÇpacctÎļþ¿ÉÄÜÔö³¤µÄÊ®·ÖѸËÙ¡£ÕâʱÐèÒª½»»¥Ê½µÄ»ò¾­¹ýcron»úÖÆÔËÐÐsaÃüÁîÀ´±£³ÖÈÕÖ¾Êý¾ÝÔÚϵͳ¿ØÖÆÄÚ¡£saÃüÁ¸æ¡¢ÇåÀí²¢Î¬»¤½ø³Ìͳ¼ÆÎļþ¡£
ËüÄܰÑ/var/log/pacctÖеÄÐÅϢѹËõµ½ÕªÒªÎļþ/var/log/savacctºÍ/var/log/usracctÖС£ÕâЩժҪ°üº¬°´ÃüÁîÃûºÍÓû§Ãû·ÖÀàµÄϵͳͳ¼ÆÊý¾Ý¡£saȱʡÇé¿öÏÂÏȶÁËüÃÇ£¬È»ºó¶ÁpacctÎļþ£¬Ê¹±¨¸æÄܰüº¬ËùÓеĿÉÓÃÐÅÏ¢¡£saµÄÊä³öÓÐÏÂÃæÒ»Ð©±ê¼ÇÏ

avio--ÿ´ÎÖ´ÐÐµÄÆ½¾ùI/O²Ù×÷´ÎÊý
cp--Óû§ºÍϵͳʱ¼ä×ܺͣ¬ÒÔ·ÖÖÓ¼Æ
cpu--ºÍcpÒ»Ñù
k--ÄÚºËʹÓÃµÄÆ½¾ùCPUʱ¼ä£¬ÒÔ1kΪµ¥Î»
k*sec--CPU´æ´¢ÍêÕûÐÔ£¬ÒÔ1k-coreÃë
re--ʵʱʱ¼ä£¬ÒÔ·ÖÖÓ¼Æ
s--ϵͳʱ¼ä£¬ÒÔ·ÖÖÓ¼Æ
tio--I/O²Ù×÷µÄ×ÜÊý
u--Óû§Ê±¼ä£¬ÒÔ·ÖÖÓ¼Æ
ÀýÈ磺
842 173.26re 4.30cp 0avio 358k
2 10.98re 4.06cp 0avio 299k find
9 24.80re 0.05cp 0avio 291k ***other
105 30.44re 0.03cp 0avio 302k ping
104 30.55re 0.03cp 0avio 394k sh
162 0.11re 0.03cp 0avio 413k security.sh*
154 0.03re 0.02cp 0avio 273k ls
56 31.61re 0.02cp 0avio 823k ping6.pl*
2 3.23re 0.02cp 0avio 822k ping6.pl
35 0.02re 0.01cp 0avio 257k md5sum
97 0.02re 0.01cp 0avio 263k initlog
12 0.19re 0.01cp 0avio 399k promisc_check.s
15 0.09re 0.00cp 0avio 288k grep
11 0.08re 0.00cp 0avio 332k awk

Óû§»¹¿ÉÒÔ¸ù¾ÝÓû§¶ø²»ÊÇÃüÁîÀ´Ìṩһ¸öÕªÒª±¨¸æ¡£
ÀýÈç:sa -mÏÔʾÈçÏ£º

885 173.28re 4.31cp 0avk
root 879 173.23re 4.31cp 0avk
alias 3 0.05re 0.00cp 0avk
qmailp 3 0.01re 0.00cp 0avk

4. SyslogÉ豸
SyslogÒѱ»Ðí¶àÈÕÖ¾º¯Êý²ÉÄÉ£¬ËüÓÃÔÚÐí¶à±£»¤´ëÊ©ÖÐ--ÈκγÌÐò¶¼¿ÉÒÔͨ¹ýsyslog ¼Í¼Ê¼þ¡£Syslog¿ÉÒԼͼϵͳʼþ£¬¿ÉÒÔдµ½Ò»¸öÎļþ»òÉ豸ÖУ¬»ò¸øÓû§·¢ËÍÒ»¸öÐÅÏ¢¡£ËüÄܼͼ±¾µØÊ¼þ»òͨ¹ýÍøÂç¼Í¼ÁíÒ»¸öÖ÷»úÉϵÄʼþ¡£

SyslogÉ豸ÒÀ¾ÝÁ½¸öÖØÒªµÄÎļþ£º/etc/syslogd£¨ÊØ»¤½ø³Ì£©ºÍ/etc/syslog.confÅäÖÃÎļþ£¬Ï°¹ßÉÏ£¬¶àÊýsyslogÐÅÏ¢±»Ð´µ½/var/adm»ò/var/logĿ¼ÏµÄÐÅÏ¢ÎļþÖУ¨messages.*£©¡£Ò»¸öµäÐ͵Äsyslog¼Í¼°üÀ¨Éú³É³ÌÐòµÄÃû×ÖºÍÒ»¸öÎı¾ÐÅÏ¢¡£Ëü»¹°üÀ¨Ò»¸öÉ豸ºÍÒ»¸öÓÅÏȼ¶·¶Î§£¨µ«²»ÔÚÈÕÖ®ÖгöÏÖ£©¡£
ÿ¸ösyslogÏûÏ¢±»¸³ÓèÏÂÃæµÄÖ÷ÒªÉ豸֮һ£º

LOG_AUTH--ÈÏ֤ϵͳ£ºlogin¡¢su¡¢gettyµÈ
LOG_AUTHPRIV--ͬLOG_AUTH£¬µ«Ö»µÇ¼µ½ËùÑ¡ÔñµÄµ¥¸öÓû§¿É¶ÁµÄÎļþÖÐ
LOG_CRON--cronÊØ»¤½ø³Ì
LOG_DAEMON--ÆäËûÏµÍ³ÊØ»¤½ø³Ì£¬Èçrouted
LOG_FTP--Îļþ´«ÊäЭÒ飺ftpd¡¢tftpd
LOG_KERN--Äں˲úÉúµÄÏûÏ¢
LOG_LPR--ϵͳ´òÓ¡»ú»º³å³Ø£ºlpr¡¢lpd
LOG_MAIL--µç×ÓÓʼþϵͳ
LOG_NEWS--ÍøÂçÐÂÎÅϵͳ
LOG_SYSLOG--ÓÉsyslogd£¨8£©²úÉúµÄÄÚ²¿ÏûÏ¢
LOG_USER--Ëæ»úÓû§½ø³Ì²úÉúµÄÏûÏ¢
LOG_UUCP--UUCP×Óϵͳ
LOG_LOCAL0~LOG_LOCAL7--Ϊ±¾µØÊ¹Óñ£Áô

SyslogΪÿ¸öʼþ¸³Ó輸¸ö²»Í¬µÄÓÅÏȼ¶£º
LOG_EMERG--½ô¼±Çé¿ö
LOG_ALERT--Ó¦¸Ã±»Á¢¼´¸ÄÕýµÄÎÊÌ⣬ÈçϵͳÊý¾Ý¿âÆÆ»µ
LOG_CRIT--ÖØÒªÇé¿ö£¬ÈçÓ²ÅÌ´íÎó
LOG_ERR--´íÎó
LOG_WARNING--¾¯¸æÐÅÏ¢
LOG_NOTICE--²»ÊÇ´íÎóÇé¿ö£¬µ«ÊÇ¿ÉÄÜÐèÒª´¦Àí
LOG_INFO--Ç鱨ÐÅÏ¢
LOG_DEBUG--°üº¬Ç鱨µÄÐÅÏ¢£¬Í¨³£Ö¼ÔÚµ÷ÊÔÒ»¸ö³ÌÐòʱʹÓÃ

syslog.confÎļþÖ¸Ã÷syslogd³ÌÐò¼Í¼ÈÕÖ¾µÄÐÐΪ£¬¸Ã³ÌÐòÔÚÆô¶¯Ê±²éѯÅäÖÃÎļþ¡£¸ÃÎļþÓɲ»Í¬³ÌÐò»òÏûÏ¢·ÖÀàµÄµ¥¸öÌõÄ¿×é³É£¬Ã¿¸öÕ¼Ò»ÐС£¶ÔÿÀàÏûÏ¢Ìṩһ¸öÑ¡ÔñÓòºÍÒ»¸ö¶¯×÷Óò¡£ÕâЩÓòÓÉtab¸ô¿ª£ºÑ¡ÔñÓòÖ¸Ã÷ÏûÏ¢µÄÀàÐͺÍÓÅÏȼ¶£»¶¯×÷ÓòÖ¸Ã÷syslogd½ÓÊÕµ½Ò»¸öÓëÑ¡Ôñ±ê×¼ÏàÆ¥ÅäµÄÏûϢʱËùÖ´Ðе͝×÷¡£Ã¿¸öÑ¡ÏîÊÇÓÉÉ豸ºÍÓÅÏȼ¶×é³É¡£µ±Ö¸Ã÷Ò»¸öÓÅÏȼ¶Ê±£¬syslogd½«¼Í¼һ¸öÓµÓÐÏàͬ»ò¸ü¸ßÓÅÏȼ¶µÄÏûÏ¢¡£ËùÒÔÈç¹ûÖ¸Ã÷"crit"£¬ÄÇËùÓбêΪcrit¡¢alertºÍemergµÄÏûÏ¢½«±»¼Í¼¡£Ã¿ÐеÄÐж¯ÓòÖ¸Ã÷µ±Ñ¡ÔñÓòÑ¡ÔñÁËÒ»¸ö¸ø¶¨ÏûÏ¢ºóÓ¦¸Ã°ÑËû·¢Ë͵½ÄĶù¡£ÀýÈ磬Èç¹ûÏë°ÑËùÓÐÓʼþÏûÏ¢¼Í¼µ½Ò»¸öÎļþÖУ¬ÈçÏ£º

#Log all the mail messages in one place
mail.* /var/log/maillog
ÆäËûÉ豸ҲÓÐ×Ô¼ºµÄÈÕÖ¾¡£UUCPºÍnewsÉ豸ÄܲúÉúÐí¶àÍⲿÏûÏ¢¡£Ëü°ÑÕâЩÏûÏ¢´æµ½×Ô¼ºµÄÈÕÖ¾£¨/var/log/spooler£©Öв¢°Ñ¼¶±ðÏÞΪ"err"»ò¸ü¸ß¡£ÀýÈ磺
# Save mail and news errors of level err and higher in aspecial file.
uucp,news.crit /var/log/spooler
µ±Ò»¸ö½ô¼±ÏûÏ¢µ½À´Ê±£¬¿ÉÄÜÏëÈÃËùÓеÄÓû§¶¼µÃµ½¡£Ò²¿ÉÄÜÏëÈÃ×Ô¼ºµÄÈÕÖ¾½ÓÊÕ²¢±£´æ¡£
#Everybody gets emergency messages£¬ plus log them on anther machine
*.emerge *
*.emerge @linuxaid.com.cn
alertÏûÏ¢Ó¦¸Ãдµ½rootºÍtigerµÄ¸öÈËÕ˺ÅÖУº
#Root and Tiger get alert and higher messages
*.alert root,tiger

ÓÐʱsyslogd½«²úÉú´óÁ¿µÄÏûÏ¢¡£ÀýÈçÄںˣ¨"kern"É豸£©¿ÉÄܺÜÈß³¤¡£Óû§¿ÉÄÜÏë°ÑÄÚºËÏûÏ¢¼Í¼µ½/dev/consoleÖС£ÏÂÃæµÄÀý×Ó±íÃ÷ÄÚºËÈÕÖ¾¼Í¼±»×¢Ê͵ôÁË£º

#Log all kernel messages to the console
#Logging much else clutters up the screen
#kern.* /dev/console

Óû§¿ÉÒÔÔÚÒ»ÐÐÖÐÖ¸Ã÷ËùÓеÄÉ豸¡£ÏÂÃæµÄÀý×Ó°Ñinfo»ò¸ü¸ß¼¶±ðµÄÏûÏ¢Ë͵½/var/log/messages£¬³ýÁËmailÒÔÍâ¡£¼¶±ð"none"½ûÖ¹Ò»¸öÉ豸£º

#Log anything£¨except mail£©of level info or higher
#Don log private authentication messages!
*.info:mail.none;authpriv.none /var/log/messages

ÔÚÓÐЩÇé¿öÏ£¬¿ÉÒÔ°ÑÈÕÖ¾Ë͵½´òÓ¡»ú£¬ÕâÑùÍøÂçÈëÇÖÕßÔõôÐÞ¸ÄÈÕÖ¾¶¼Ã»ÓÐÓÃÁË¡£Í¨³£Òª¹ã·º¼Í¼ÈÕÖ¾¡£SyslogÉ豸ÊÇÒ»¸ö¹¥»÷ÕßµÄÏÔÖøÄ¿±ê¡£Ò»¸öΪÆäËûÖ÷»úά»¤ÈÕÖ¾µÄϵͳ¶ÔÓÚ·À·¶·þÎñÆ÷¹¥»÷ÌØ±ð´àÈõ£¬Òò´ËÒªÌØ±ð×¢Òâ¡£

ÓиöСÃüÁîloggerΪsyslog£¨3£©ÏµÍ³ÈÕÖ¾ÎļþÌṩһ¸öshellÃüÁî½Ó¿Ú£¬Ê¹Óû§ÄÜ´´½¨ÈÕÖ¾ÎļþÖеÄÌõÄ¿¡£Ó÷¨£ºlogger ÀýÈ磺logger This is a test£¡
Ëü½«²úÉúÒ»¸öÈçϵÄsyslog¼Í¼£ºAug 19 22:22:34 tiger: This is a test!
×¢Òâ²»ÒªÍêÈ«ÏàÐÅÈÕÖ¾£¬ÒòΪ¹¥»÷ÕߺÜÈÝÒ×ÐÞ¸ÄËüµÄ¡£

5. ³ÌÐòÈÕÖ¾
Ðí¶à³ÌÐòͨ¹ýά»¤ÈÕÖ¾À´·´Ó³ÏµÍ³µÄ°²È«×´Ì¬¡£suÃüÁîÔÊÐíÓû§»ñµÃÁíÒ»¸öÓû§µÄȨÏÞ£¬ËùÒÔËüµÄ°²È«ºÜÖØÒª£¬ËüµÄÎļþΪsulog¡£Í¬ÑùµÄ»¹ÓÐsudolog¡£ÁíÍ⣬ÏëApacheÓÐÁ½¸öÈÕÖ¾£ºaccess_logºÍerror_log¡£
ÎÄÕÂÆÀÂÛ

¹²ÓÐ 2 ÌõÆÀÂÛ

  1. ÓÚ 2006-08-22 19:14:05·¢±í:

    ллÁË

  2. yinzelei ÓÚ 2006-08-22 12:49:16·¢±í:

    ³¤ÖªÊ¶ÁË