Sunday, January 16, 2011

Linux OS management--log management and analysis

◆ Ⅲ S y s l o n g g-Syslog-ng applications is enhanced traditional syslogdaemon porting.

It provides many standard syslogdaemon same characteristics, but also includes some additional features, such as content-based filtering, advanced messaging over UDP or TCP remote log record, the log written into like MySQL or PostgreSQL database. Many recent system based on SUSE SLES10, as have been changed to syslog-ng as default syslog service. ◆ Ⅳ V I e w I n g l o g s Linux system on most log files are stored as plain text, this means that you can use many different command-line tools for viewing and analysis. A typical command such as head, tail, grep, cat, more, less, sed, awk, sed and more, you can use these commands from the command line to view log information. There are many tools through GUI graphical interface or a web browser to resolve and view the log file. Some tools can even handle special log format, such as those by LinuxNetfilter firewall subsystem generated log files. GNOMESystemLogViewer GNOME system includes a GTK-based system log monitoring program that exhibited through GUI graphical interface to the system log. YaSTSystemLogModule SUSE-based systems use contains ViewSystemLog module (also called view_anymsg) of YaST, and similar to YaST module GNOMESystemLogviewer allows system administrators do not use the command line you can observe many different kinds of system log w A L o g Ⅴ n a l y s I s LogWatc Logwatch tool used to resolve the system log, locate any potential safety problems may indicate or system error data, send an email to the specified address. Logwatch released in conjunction with RetHatEnterpriseLinux system. The following is a summary from the PRM describes "LogWatch is a customizable set of log analysis system. LogWatch can parse the given time period in the system log, and create a detailed report of your specified area. LogWatch is easy to use, and claims that it can work on any system. It is important to note that Samba log LogWatch analysis now. "LogWatch run primarily through cron cyclic. LogCheck: Logcheck tool is part of the project, SentryTools SentryTools project also includes the portsentry — one for monitoring port scanning tools. And LogWatch tool similar to Logcheck used to resolve the system log and found that may indicate security problems, send an email to the specified address. Logcheck is like LogWatch, rely on periodic cron tool.

No comments:

Post a Comment