ÏÂÃæÎÒ¸ø´ó¼Ò½éÉÜÒ»ÏÂLinuxÀïÃæµÄÈÕÖ¾Îļþ£º
ÈÕÖ¾Ò»°ãµÄ·þÎñ¶¼°üÀ¨£º·ÃÎÊÈÕÖ¾ºÍ´íÎóָʾ£»·ÃÎÊÈÕÖ¾Ò»°ã¼Ç¼·þÎñµÄÔËÐÐ״̬£¬·þÎñÖ´ÐÐÁËʲô²Ù×÷£¬¶¼¼Ç¼ÔÚ·ÃÎÊÈÕÖ¾ÖУ»¶ø´íÎóÈÕ־ͨ¹ýÃû×ÖÒ²¿ÉÀí½â£¬µ½·þÎñÓöµ½´íÎóʱ£¬¾Í»á°Ñ´íÎóµÄÈÕÖ¾¼Ç¼ÔÚ´íÎóÈÕÖ¾ÖС£
Windows
ÏñÔÚWindowsÀïÃæÎÒÃÇÐèÒª²é¿´ÈÕÖ¾ÐèÒª´Ó£¬¡°¹ÜÀí¡±Ä¿Â¼ÏÂÃæÕÒµ½Ê¼þ²é¿´Æ÷£¬¶øÕâЩ¶¼ÊôÓÚÔÚWindowÈÕÖ¾²é¿´Æ÷
Linux
Ê×ÏÈÎÒÃÇÒª²é¿´ÎÒÃǵÄLinux ÀïÃæÊÇ·ñ´æÔÚsysklogd-1.4.1-44.e15
Õâ¸öÈí¼þ°ü£¬Ò²¾ÍÊÇһЩ¹ØÓÚÈÕÖ¾µÄһЩÎļþ£¬È»ºóÎÒÃǽøÐв鿴Õâ¸öÈí¼þ°ü
ÏñһЩÈí¼þ°üÀïÃæ´øÓÐd¶¼ÊÇһЩ·þÎñÈí¼þµÄ°ü¡°sysklogd¡±
ÆäÖÐÀïÃæÓÐÕâÁ½¸öÈí¼þ°ü£¨1£©/sbin/klogd ÊÇÕë¶ÔÄں˲úÉúÈÕÖ¾ÐÅÏ¢
dmesg Õâ¸öÖ¸Áî¿ÉÒԲ鿴Õë¶ÔÄÚºËÓ²¼þµÄÐÅÏ¢
dmesg | grep -i cpu ¿ÉÒԲ鿴cpuµÄÐÅÏ¢
dmesg | grep -imem ¿ÉÒԲ鿴ÄÚ´æµÄÐÅÏ¢
dmesg | grep -ietho ¿ÉÒÔ²é¿´Íø¿¨µÄÐÅÏ¢
£¨2£©/sbin/syslogd ÊÇÕë¶ÔϵͳµÄ·þÎñÈÕÖ¾ÐÅÏ¢
ϵͳ°üÀ¨£ºÎÒÃÇÆ½Ê±°²×°µÄijЩÈí¼þ£¬ÍøÂçÉ豸µÈ
/sbin/syslogd»á²úÉúÒ»¸ö·ÖÀàµÄÎļþ¶øÕâ¸ö·ÖÀàµÄÎļþ¾ÍÊÇ/etc/syslong.confÎÒÃÇ´ò¿ªÕâ¸öÎļþ»á¿´µ½·ÖÀàÎļþ
ÿһÐбíʾһ¸ö¹æÔò£¬Ç°Ò»¸öÊÇÒ»¸öÑ¡ÔñÓòºóÒ»¸öÊǶ¯×÷Óò *±íʾÊÇÿ¸öÈË£¬¶¯×÷Óò¾Í±íʾÎÒÃÇÐèÒª°ÑÕâЩµÄÐÅÏ¢·¢µ½ÄÄÀïÈ¥
Ñ¡ÔñÀïÃæ°üÀ¨Ó¦Óúͼ¶±ð¶ø¶¯×÷°üÀ¨Îļþÿ¸öÈË@Ö÷»úÃû³Æ»òµØÖ·
Ç°Ãæ´ø£¨#£©¶¼ÊÇ×¢Ê͵ÄÒâ˼
²»´ø×¢Ê͵ÄÿһÐÐÇ°ÃæµÄ±íʾһÖÖÓ¦Ó÷þÎñ£¬ºóÃæ¿ÉÒÔ¸úËüµÄ¼¶±ð£¬¶øÔÚÓ¦ÓÃÀïÃæÓÐÉí·ÝÑéÖ¤¼Æ»®ÈÎÎñijһÖÖÓ¦·þÎñÄں˴òÓ¡Óʼþ±êÖ¾ÐÂÎŰ²È«Óû§ÔÚ°²È«µÄÇé¿öÏÂÎÒÃÇÒ»°ã²»ÓõÄ
.ºóÃæ¸ú׿¶±ð×îµÍdebug info£¨ÌáÐÑ£© notice£¨×¢Ò⣩£¬warning warn err error crit (ÑÏÖØ)alert emerg panic Óɵ͵½¸ß¼¶±ð
ÎÒÃÇÏÈ´ÓµÚ7ÐпªÊ¼¸ø´ó¼Ò˵Ã÷һϣºËùÓÐÓ¦ÓÃÈí¼þµÄ´óÓÚµÈÓÚinfo¶¼Òª±»¼Ç¼ÏÂÀ´£¬³ýÁ˹ØÓÚmail ÑéÖ¤¼Æ»®ÈÎÎñÏà¹ØµÄ¶¼Òª¼Äµ½Õâ¸öÎļþÀïÃæ /var/log/messages
µÚ10ÐÐ authpriv.*ÑéÖ¤ÕâЩÑéÖ¤µÄÐÅÏ¢¶¼¼Ç¼µ½/var/log/secure
Àý£ºÎÒ´ÓµÚËĸöÖն˽øÈ¥£¬¹ÊÒâÊä´íÃÜÂ룬ÕâÊÇÔٲ鿴ÈÕÖ¾ÎļþÌáʾ
µÚ13ÐÐÓʼþÏà¹Ø¡®-¡¯±íʾÒì²½£¬±íʾµÈϵͳ¿ÕÏÐÁËÔÙ°ÑÐÅϢдµ½Õâ¸öÎļþÀïÃæÈ¥
µÚ17Ðмƻ®ÈÎÎñ
µÚ20ÐÐËùÓÐÑÏÖØµÄÐÅÏ¢·¢¸öÿһ¸öÈË
µÚ23ÐÐ UUcp ÐÂÎŵĴóÓÚcrit´óÓÚÕâ¸ö¼¶±ðµÄ¶¼»á´æ·Åµ½
ÈÕÖ¾Îļþ»¹ÓÐÐí¶àµÄÇ¿´ó¹¦ÄÜÎÒ¸ø´ó¼ÒÁоÙÁËһЩ£º
The facility is one of the followingkeywords: auth, authpriv, cron, daemon, kern, lpr, mail, mark, news, security
(same as auth), syslog, user, uucp and local0 through local7. The keyword security should not be usedanymore and mark
is only for internal use and therefore should not be used inapplications. Anyway, you may want tospecify and redi-
rect these messages here. The facility specifies the subsystem thatproduced the message, i.e. all mail programs log
with the mail facility (LOG_MAIL) if they log using syslog.
# Store critical stuff incritical
#
*.=crit;kern.none /var/adm/critical
ËùÓеijýÁËÄÚºËÏà¹ØµÄcritÕâ¸ö¼¶±ðµÄ¶¼»á¼Äµ½/var/adm/critical
This will store all messages with the priority crit in the file/var/adm/critical, except for any kernel message.
# Kernel messages are first, storedin the kernel
# file, critical messages andhigher ones also go
# to another host and to theconsole
#
kern.* /var/adm/kernel
kern.crit @finlandia
kern.crit /dev/console
kern.info;kern.!err /var/adm/kernel-info
̾ºÅÊÇÈ¡·´,Ò²¾ÍÊÇinfoµ½warning¼¶±ðµÄ»á¼Äµ½
The first rule direct any message that has the kernel facility to thefile /var/adm/kernel.
The second statement directs all kernel messages of the priority critand higher to the remote host finlandia. This is
useful, because if the hostcrashes and the disks get irreparable errors you might not be able to read thestored mes-
sages. If they're on a remotehost, too, you still can try to find out the reason for the crash.
The third rule directs these messages to the actual console, so theperson who works on the machine will get them, too.
The fourth line tells the syslogdto save all kernel messages that come with priorities from info up to warningin the
file /var/adm/kernel-info. Everything from err and higher is excluded.
# The tcp wrapper loggs withmail.info, we display
# all the connections on tty12
#
mail.=info /dev/tty12
This directs all messages that uses mail.info (in source LOG_MAIL |LOG_INFO) to /dev/tty12, the 12th console. For
example the tcpwrapper tcpd(8) uses this as it's default.
# Store all mail concerning stuffin a file
#
mail.*;mail.!=info /var/adm/mail
This pattern matches all messages that come with the mail facility,except for the info priority. These willbe stored
in the file /var/adm/mail.
# Log all mail.info and news.infomessages to info
#
mail,news.=info /var/adm/info
This will extract all messages that come either with mail.info or with news.info and store them in the file
/var/adm/info.
×÷Õߣºwqianyniaionly

