IzzyMenu.com

SYSTEM(LINUX BSD MYSQL MSSQL etc)°ü·Ã ÀÚ·á¹× ÀÚü °­ÀÇ ÀÚ·á

 ·Î±×ÀÎ  È¸¿ø°¡ÀÔ

/etc/syslog.conf ÀÛ¼º
ANTON  2009-07-31 15:26:30, Á¶È¸ : 171, Ãßõ : 38

  ###############################################################################
# /etc/syslog.conf ³»¿ëÀ¸·Î ¾Æ·¡¿¡´Â kldp.orgÀÇ ¹®¼­°¡ ÷ºÎµÇ¾î ÀÖ´Ù.
###############################################################################
# Log all kernel messages to the console.
# Logging much else clutters up the screen.
#kern.* /dev/console

# Log anything (except mail) of level info or higher.
# Don't log private authentication messages!
*.info;mail.none;news.none;authpriv.none;cron.none /var/log/messages

# The authpriv file has restricted access.
authpriv.* /var/log/secure


# Log all the mail messages in one place.
mail.* /var/log/maillog


# Log cron stuff
cron.* /var/log/cron

# Everybody gets emergency messages
*.emerg *

# Save news errors of level crit and higher in a special file.
uucp,news.crit /var/log/spooler

# Save boot messages also to boot.log
local7.* /var/log/boot.log

#
# INN
#
news.=crit /var/log/news/news.crit
news.=err /var/log/news/news.err
news.notice /var/log/news/news.notice
###############################################################################
# Ãß°¡ÇÏ´Â Ç׸ñÀÓ
###############################################################################

# kernel¿¡ °ü·ÃµÈ ¸ðµç Ç׸ñÀº µû·Î ±â·Ï
kern.* /var/log/kernel.log

# ¸ðµç ¿¡·¯Áß warn¿¡¼­ err±îÁö¸¸ ±â·Ï
*.warn;*.err /var/log/warnerr.log

# auth´Â ¼­ºñ½ºÀÎÁõ ½ÇÆÐ. authpriv´Â »ç¿ëÀÚ ...
auth.*;authpriv.*;user.* /var/log/login.log

# kilo¶ó´Â ¿ÜºÎ È£½ºÆ®¿¡ ·Î±×ÆÄÀÏÀ» ±â·ÏÇÑ´Ù
# À̶§ Á¤È®È÷ ¾Ë¼ö ÀÖµµ·Ï /etc/hosts¿¡ ±â·Ï½ÃÄÑ µÎÀÚ.
# À̶§ log°¡ ±â·ÏµÇ´Â ÄÄÇ»ÅÍ¿¡ syslog±¸µ¿½Ã
# /etc/rc.d/init/syslog ÆÄÀÏ¿¡¼­ -r ¿É¼ÇÀ» Ãß°¡ÇÏ¸é µÈ´Ù.
#################### ÁÖÀÇ ##################################
# /etc/rc.d/init/syslog ½ºÅ©¸³Æ® ÆÄÀÏÀ» º¸¸é
# /etc/sysconfig/syslog¸¦ ¸ÕÀú ÀоîµéÀÌ°Ô µÇ¾îÀÖ´Ù. ±×·¯´Ï ÀÌ ÆÄÀÏÀ»
# ¸ÕÀú º¯°æÇÏ¿©¾ß ÇÑ´Ù.
auth.*;authpriv.*;user.* @kilo

###############################################################################
awk -F" " '{ if($4=="leoncw.barammail.net") print }' /var/log/secure
À§ÀÇ ¸í·ÉÀ¸·Î Àü¼ÛµÇ¾î ¿À´Â ·Î±×ÆÄÀÏÀ» °£´ÜÈ÷ È®ÀÎÇÏÀÚ.
###############################################################################

###############################################################################
# kldp.orgÀÇ ³»¿ë
###############################################################################
syslogd.conf

man sysklogd
man logrotate
20¸¸ÅëÀÇ ÀüÀÚ¸ÞÀÏ°ú sendmail(¸¶¼Ò 99³â 5¿ù)Áß ·Î±× ÆÄÀÏ °ü¸®ºÎºÐ
±âŸ ¸®´ª½º ¹× À¯´Ð½º ½Ã½ºÅÛ °ü¸® °ü·Ã ¼­Àû


0. µé¾î°¡¸ç
½Ã½ºÅÛ¿¡´Â »ç¿ëÀÚ ·Î±×ÀÎ, ¸ÞÀÏµî ¸ðµç ½Ã½ºÅÛ È°µ¿¿¡ ´ëÇÑ ·Î±×¸¦ ±â·Ï
ÇÏ°í À̸¦ °¡Áö°í ½Ã½ºÅÛÀÇ ¹®Á¦¿¡ ´ëÇؼ­ ºÐ¼®ÇÒ ¼ö ÀÖ´Ù.
½Ã½ºÅÛÀÇ ·Î±×°¡ ¾î¶² ½ÄÀ¸·Î ±â·ÏµÇ°í ¾î¶² Àǹ̸¦ °¡Áö°í ÀÖ´ÂÁö,
À̸¦ ¾î¶»°Ô È°¿ëÇؾßÇÒÁö ½Ã½ºÅÛ °ü¸®ÀÚ¶ó¸é ¹Ýµå½Ã ¼÷ÁöÇÏ°í ÀÖ¾î¾ß
ÇÒ °ÍÀÌ´Ù.


¼Ò±Ô¸ð·Î ¼­¹ö¸¦ ¿î¿µÇÏ´Â °æ¿ì ·Î±×ÆÄÀÏ¿¡ ±×´ÙÁö ½Å°æÀ» ¾²´Â ÀÏÀÌ ¾ø´Ù.
±×·¸Áö¸¸ Á¦°øÇÏ´Â ¼­ºñ½º°¡ ¸¹¾ÆÁö°í ±Ô¸ð°¡ Ä¿Áú °æ¿ì ¿¹»óÄ¡ ¸øÇÑ °÷¿¡
¼­ ¹®Á¦°¡ »ý±â´Â ÀÏÀÌ ¸¹´Ù. ±×Áß Çϳª°¡ ¾öû³ª°Ô Áõ°¡ÇÏ´Â ·Î±×ÆÄÀϹ®Á¦
ÀÌ´Ù.

¿¹¸¦ µé¾îº¸ÀÚ. ÇÏ·ç¿¡ 10¸¸ÅëÀÇ ÀüÀÚ¸ÞÀÏÀ» ó¸®ÇÏ´Â °æ¿ì¸¦ »ý°¢Çغ¸ÀÚ.
sendmailÀº ÀüÀÚ¸ÞÀÏÀ» Àü¼ÛÇϸ鼭 ±× °á°ú ¸Þ½ÃÁö¸¥ syslogd¸¦ ÀÌ¿ë
/var/log/maillog¿¡ ÀúÀåÇÑ´Ù. (ÀÌ´Â ¼³Á¤¿¡ µû¶ó ´Ù¸¦ ¼ö ÀÖ´Ù) ¶ÇÇÑ
¿©±â¿¡ pop3¸¦ »ç¿ëÇØ ¸ÞÀÏÀ» °¡Á®°£ ±â·Ï°ú ¸ÞÀÏÀ» Àü¼ÛÇÑ ±â·Ï±îÁö
ÀúÀåµÇ¾î¾ßÇÑ´Ù.

Á¤»óÀûÀ¸·Î ÀüÀÚ¸ÞÀÏÀÌ Àü¼ÛµÇ´Â °æ¿ì ±â·ÏµÇ´Â ¸Þ½ÃÁö´Â 560 ¹ÙÀÌÆ®Á¤µµ
ÀÌ´Ù. ±×·¸Áö¸¸ Àü¼Û½Ã ¿¡·¯°¡ ³ª´Â °æ¿ì¿¡´Â ±× ¿¡·¯ Ƚ¼ö¿¡ µû¶ó ¿¡·¯
¸Þ½ÃÁö°¡ Ãß°¡µÈ´Ù. Æò±Õ ÇϳªÀÇ ÀüÀÚ¸ÞÀÏÀÌ 1KB Á¤µµÀÇ ·Î±×¸¦ ±â·ÏÇÑ´Ù
°í Çغ¸ÀÚ. ÇÏ·ç¿¡ 10¸¸°³ÀÇ ¸ÞÀÏÀ» Àü¼ÛÇÑ´Ù¸é ÇÏ·íµ¿¾È ·Î±×ÀÇ Å©±â¸¸
100M ÀÌ°í ÀÏÁÖÀÏÀ̸é 700MBÀÌ´Ù.
¿©±â¿¡ ¸ÞÀÏ°èÁ¤ÀÌ 1000¸íÀÌ°í °¢ »ç¿ëÀÚ°¡ 5ºÐ¸¶´Ù pop3·Î ¸ÞÀÏÀ» È®ÀÎ
ÇÑ´Ù°í ÇßÀ» °æ¿ì¸¦ Ãß°¡ÇؾßÇÑ´Ù. Çѹø¿¡ ¾à 0.2KBÀÇ ·Î±×°¡ ½×À̸é
½Ã°£´ç 12¹ø(5ºÐ¿¡ Çѹø¾¿ È®ÀÎÇÏ´Â °æ¿ì), ÇÏ·ç 8½Ã°£ ±Ù¹«½Ã 96¹øÀÌ°í
96*0.2KB = 192kbÀÌ´Ù. 1000¸íÀ̹ǷΠ192MB°¡ µÇ°í ÀÏÁÖÀÏÀ̸é ÀÏ¿äÀÏÀ»
Á¦¿ÜÇÏ´õ¶óµµ 1.15GÁ¤µµ°¡ µÈ´Ù.
ÇÑ »ç¶÷´ç ¸ÞÀÏ¿ë·®À» 10M¾¿ ÇÒ´çÇϸé ÀüÀÚ¸ÞÀÏÀ» ÀúÀåÇÒ ¿ë·®¸¸À¸·Î
10G°¡ ÇÊ¿äÇÏ°í ·Î±×¸¦ À§ÇØ 2G ÀÌ»óÀÌ ÇÊ¿äÇÏ´Ù. ¿©±â¼­ ±×³É 2G·Î
³¡³ª´Â °ÍÀÌ ¾Æ´Ï¶ó rotate °ªÀÌ 4¶ó¸é 8G°¡ µÈ´Ù. °¡È÷ ²ûÂïÇÑ »óȲÀÌ
¿¹»óµÇÁö ¾Ê´Â°¡?

¿©±â¼­¸¸ ³¡³ª´Â °ÍÀÌ ¾Æ´Ï´Ù. syslogd´Â maillog¸¦ ¿­¾î³õ°í °è¼Ó ·Î±×
¸¦ ±â·ÏÇϴµ¥ ·Î±×ÆÄÀÏÀÌ 1MÀÌ»ó ³Ñ¾î°¡¸é ÇϳªÀÇ ¸Þ½ÃÁö¸¦ ó¸®Çϱâ
À§ÇØ ½Ã½ºÅÛ ÀÚ¿øÀ» 10% ÀÌ»ó »ç¿ëÇÑ´Ù°í Çϸç 10M°¡ ³ÑÀ¸¸é 40% ÀÌ»ó,
100M°¡ ³ÑÀ¸¸é 80% ÀÌ»óÀÇ ½Ã½ºÅÛ ÀÚ¿øÀ» »ç¿ëÇÑ´Ù°í ÇÑ´Ù. (¹°·Ð ÀÌ´Â
ÀÚ½ÅÀÇ ½Ã½ºÅÛ »óȲÀ» ²÷ÀÓ¾øÀÌ ¸ð´ÏÅ͸µÇؼ­ Àڽſ¡ ¸ÂÃß¾î¾ß ÇÒ °ÍÀÌ
´Ù) °á±¹ ¼­ºñ½º¸¦ Á¦°øÇϴµ¥ ÀÚ¿øÀ» »ç¿ëÇؾßÇϴµ¥ ¾öû³ª°Ô Ä¿Áø
·Î±×ÆÄÀ϶§¹®¿¡ ½Ã½ºÅÛÀÇ ÀÚ¿øÀÌ ¾ø¾îÁ®¼­ ³ªÁß¿¡´Â ÀüÀÚ¸ÞÀÏ Àü¼ÛÀÌ
¾Æ´Ï¶ó ·Î±× ±â·Ï¿¡ ¸ðµç cpu ½Ã°£À» »ç¿ëÇؾßÇÑ´Ù. ÇÏµå µð½ºÅ©¸¦
ºó¹øÇÏ°Ô »ç¿ëÇÏ´Â ÀÛ¾÷ÀÌ ¸¹À¸¸é ½Ã½ºÅÛÀÇ ¼º´ÉÀº ±Þ°ÝÇÏ°Ô ¶³¾îÁø´Ù.

ÀÌÁ¦ À¥¼­¹ö·Î±× ±â·ÏÀ» »ìÆ캸ÀÚ. ÀÌ¿ëÀÚ°¡ Á¢¼ÓÇÒ ¶§¸¶´Ù ±â·ÏµÇ´Â
access_log´Â Çѹø Á¢¼Ó´ç ¾à 85Byte°¡ Áõ°¡ÇÑ´Ù. ÇÏ·ç 10¸¸¹ø Á¢¼Ó
Çϸé 8.5MÀÌ´Ù. ÀÏÁÖÀÏÀ̸é 59.5MÀÌ´Ù. ÇÑ´ÞÀ̸é 255MÀÌ´Ù. ¼­ºñ½ºÇÏ
´Â ±Ô¸ð°¡ ´õ Å©´Ù¸é ·Î±×ÆÄÀÌÀ» ¾×¼¼½ºÇÏ°í °»½ÅÇϴµ¥´Â ´õ ¸¹Àº
½Ã½ºÅÛ ÀÚ¿øÀ» »ç¿ëÇÒ °ÍÀÌ´Ù.


¼­·ÐÀ» ÀÌ·¸°Ô ÀåȲÇÏ°Ô À̾߱âÇÑ°ÍÀº °ü¸®ÀÚ°¡ ·Î±× ±â·Ï¿¡ ½Å°æÀ»
¾²Áö ¾Ê´Â´Ù¸é ´ë±Ô¸ð ¼­ºñ½º¸¦ Á¦°øÇϸ鼭 ¾ó¸¶³ª Å« ¹®Á¦°¡ »ý±æ¼ö
ÀÖ´ÂÁö¸¦ ¾Ë·ÁÁÖ°íÀÚ Çϱâ À§ÇÔÀÌ´Ù. ÇÊÀÚÀÇ °³ÀΠȨÆäÀÌÁö¿¡¼­¾ß
±×·± ¹®Á¦°¡ »ý±âÁö´Â ¾Ê°ÚÁö¸¸....

·Î±× ±â·ÏÀ» ¾î¶² ½ÄÀ¸·Î ¼³Á¤ÇÒ °ÍÀΰ¡? Á¤Ã¥¿¡ °üÇÑ °ÍÀº °ü¸®ÀÚ°¡
ÇØ¾ß ÇÒ ¸òÀ̶ó »ý°¢ÇÏ¸ç ¿©±â¿¡¼­´Â ·Î±× ÆÄÀÏÀÇ ¼³Á¤ ¹× ·ÎÅ×À̼Ç
¿¡ ´ëÇؼ­ ¼³¸íÀ» ÇÑ´Ù. ÇÊÀÚ°¡ Ã¥À» ±×´ÙÁö µÚÁ®º¸Áö ¾Ê¾Æ¼­ ±×·±Áö
´Â ¸ð¸£°Ú´Âµ¥ À¯´Ð½º ¼­¹ö °ü¸® ¼­Àû¿¡µµ ÀÌ¿¡ ´ëÇؼ­´Â ±×¸® ÀÚ¼¼È÷
³ª¿ÍÀÖÁö ¾Ê¾Æ¼­ À̹ø ±âȸ¸¦ ÀÌ¿ëÇØ Á¤¸®Çغ¸°íÀÚ ÇÑ´Ù.



1. ½Ã½ºÅÛ ·Î±× ±â·Ï (syslog)
ÀϹÝÀûÀ¸·Î ¹èÆ÷ÆÇ ¼³Ä¡½Ã ·Î±×ÆÄÀÏÀ» ±â·ÏÇÏ´Â ÆÐÅ°Áö°¡ ÀÚµ¿À¸·Î
¼³Ä¡µÈ´Ù.

# rpm -qa | grep log

logrotate-3.3-1 --->> ·Î±× ·ÎÅ×ÀÌÆ®(¼øȯ)
sysklogd-1.3.31-12 --->> ½Ã½ºÅÛ ·Î±× ±â·Ï


# rpm -ql sysklogd
/etc/logrotate.d/syslog
/etc/rc.d/init.d/syslog
/etc/rc.d/rc0.d/K99syslog
/etc/rc.d/rc1.d/K99syslog
/etc/rc.d/rc2.d/S30syslog
/etc/rc.d/rc3.d/S30syslog
/etc/rc.d/rc5.d/S30syslog
/etc/rc.d/rc6.d/K99syslog
/etc/syslog.conf --->> ¼³Á¤ÆÄÀÏ
/sbin/klogd --->> Ä¿³Î ·Î±× ´ë¸ó
/sbin/syslogd --->> ½Ã½ºÅÛ ·Î±× ´ë¸ó
/usr/doc/sysklogd-1.3.31
/usr/doc/sysklogd-1.3.31/ANNOUNCE
/usr/doc/sysklogd-1.3.31/INSTALL
/usr/doc/sysklogd-1.3.31/NEWS
/usr/doc/sysklogd-1.3.31/README.1st
/usr/doc/sysklogd-1.3.31/README.linux
/usr/doc/sysklogd-1.3.31/Sysklogd-1.3.lsm
/usr/man/man5/syslog.conf.5
/usr/man/man8/klogd.8
/usr/man/man8/sysklogd.8
/usr/man/man8/syslogd.8


Âü°í·Î ¹®¼­µð·ºÅ丮ÀÇ ³»¿ëÀº »ç¿ë°ú °ü·ÃÇؼ­´Â ±×´ÙÁö µµ¿òÀÌ
µÇÁö ¾Ê°í ¿ÀÈ÷·Á ¸ÇÆäÀÌÁö°¡ µµ¿òÀÌ µÇ¾ú´Ù.


# ps aux | head -n10
USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND
root 1 0.0 0.1 1168 56 ? S 14:07 0:05 init [3]
root 2 0.0 0.0 0 0 ? SW 14:07 0:00 [kflushd]
root 3 0.0 0.0 0 0 ? SW 14:07 0:00 [kupdate]
root 4 0.0 0.0 0 0 ? SW 14:07 0:00 [kpiod]
root 5 0.0 0.0 0 0 ? SW 14:07 0:05 [kswapd]
root 6 0.0 0.0 0 0 ? SW< 14:07 0:00 [mdrecoveryd]
root 285 0.0 0.5 1232 180 ? S 14:07 0:00 syslogd -m 0
root 296 0.0 0.0 1464 0 ? SW 14:07 0:00 [klogd]

º¸Åë À§¿Í °°ÀÌ ·Î±× ´ë¸óÀº ½Ã½ºÅÛÀÇ ºÎÆýà ÃÊâ±â¿¡ ½ÇÇàÀÌ µÈ´Ù.


±×·¯¸é °¡Àå ¸ÕÀú /etc/syslog.conf ¸¦ »ìÆ캸ÀÚ. syslodÀÇ ¼³Á¤ ÆÄÀÏÀÌ´Ù.

# cat /etc/syslog.conf


# Log all kernel messages to the console.
# Logging much else clutters up the screen.
#kern.* /dev/console


# Log anything (except mail) of level info or higher.
# Don't log private authentication messages!
*.info;mail.none;authpriv.none /var/log/messages

# The authpriv file has restricted access.
authpriv.* /var/log/secure

# Log all the mail messages in one place.
mail.* /var/log/maillog

# Everybody gets emergency messages, plus log them on another
# machine.
*.emerg *

# Save mail and news errors of level err and higher in a
# special file.
uucp,news.crit /var/log/spooler

# Save boot messages also to boot.log
local7.* /var/log/boot.log



¼³Á¤ÆÄÀÏÀº ¸Å¿ì °£´ÜÇÏ´Ù. ºó Çà°ú # À¸·Î ½ÃÀ۵Ǵ ÇàÀº ¹«½ÃµÈ´Ù.
(Âü°í·Î ¸®´ª½º´Â BSD Çü½ÄÀ¸·Î ·Î±×¸¦ ±¸¼ºÇÑ´Ù)
¼³Á¤ÇàÀÇ ±¸Á¶´Â ´ÙÀ½°ú °°´Ù.

facility.level destination

facility´Â ¸Þ½ÃÁö¸¦ º¸³»´Â ¼­ºê½Ã½ºÅÛÀÇ À̸§À̸ç
level(priority)Àº ¸Þ½ÃÁöÀÇ Á߿伺(¾ö°Ýµµ)À» ³ªÅ¸³½´Ù.

facility´Â ´ÙÀ½°ú °°´Ù.
auth, authpriv, cron, daemon, kern, lpr, mail, news, syslog,
user, uucp, local0 - local7

priority´Â ´ÙÀ½°ú °°´Ù. (¾ö°Ýµµ°¡ °¨¼ÒÇÏ´Â ¼ø¼­)
debug, info, notice, warning, warn (same as warning),
err, error (same as err), crit, alert, emerg,
panic (same as emerg)

°¢ÀÚ¿¡ ´ëÇÑ ¼³¸íÀº ¾Æ·¡¸¦ Âü°íÇÏÀÚ.

# man 3 syslog


facility
The facility argument is used to specify what type of pro
gram is logging the message. This lets the configuration
file specify that messages from different facilities will
be handled differently.

LOG_AUTH
security/authorization messages (DEPRECATED Use
LOG_AUTHPRIV instead)

LOG_AUTHPRIV
security/authorization messages (private)

LOG_CRON
clock daemon (cron and at)

LOG_DAEMON
other system daemons

LOG_KERN
kernel messages

LOG_LOCAL0 through LOG_LOCAL7
reserved for local use

LOG_LPR
line printer subsystem

LOG_MAIL
mail subsystem

LOG_NEWS
USENET news subsystem

LOG_SYSLOG
messages generated internally by syslogd

LOG_USER(default)
generic user-level messages

LOG_UUCP
UUCP subsystem


level
This determines the importance of the message. The levels
are, in order of decreasing importance:

LOG_EMERG
system is unusable

LOG_ALERT
action must be taken immediately

LOG_CRIT
critical conditions

LOG_ERR
error conditions

LOG_WARNING
warning conditions

LOG_NOTICE
normal, but significant, condition

LOG_INFO
informational message

LOG_DEBUG
debug-level message


auth ´ë½Å auth_priv¸¦ »ç¿ëÇÒ °ÍÀ» ÃßõÇÏ°í ÀÖÀ¸¸ç ³ª¸ÓÁö´Â
Àо¸é ½±°Ô ÀÌÇØ°¡ °¥ °ÍÀÌ´Ù. Å©·Ð, ´ë¸ó, Ä¿³Î ¸Þ½ÃÁö,
·ÎÄÿ¡¼­ »ç¿ë, ÇÁ¸°ÅÍ, ¸ÞÀÏ, ´º½º, syslog, »ç¿ëÀÚ Á¤ÀÇ,
UUCP. (auth´Â ·Î±×ÀÎ ÀÎÁõ ½Ã½ºÅÛ)

emerg : ½Ã½ºÅÛ ÆдÐ
alert : ¿¡·¯ °æ°í. Áï°¢ ¾Ë·Á¾ßÇÒ ³»¿ë
crit : Çϵå ÀåÄ¡ ¿¡·¯¿Í °°Àº ÀÓ°è ¿¡·¯(critical error)
err : ¿¡·¯
warn : °æ°í
notice : ºñÀÓ°è ¸Þ½ÃÁö
info : Á¤º¸ ¸Þ½ÃÁö
debug :¹®Á¦ ÃßÀûÀ» µ½´Â Ư¼ö Á¤º¸
¸¸¾à none À̶ó°í ÇÏ¸é ±×¿¡ ´ëÇÑ ¸ðµç ·Î±× ¸Þ½ÃÁö¸¦ Á¦¿ÜÇ϶ó´Â ¶æÀÔ´Ï´Ù.


¸ðµç facility ³ª priority ¸¦ ÁöÁ¤ÇÏ·Á¸é * ¸¦ ¾²¸é µÇ¸ç
¿©·¯°³¸¦ ÁöÁ¤ÇÏ·Á¸é , ¸¦ »ç¿ëÇÏ¸é µË´Ï´Ù.

±×·±µ¥ ¿©±â¼­ ¹Ýµå½Ã ¾Ë¾ÆµÎ¾ßÇÒ°ÍÀÌ priority¸¦ ÁöÁ¤ÇÏ¸é ±×¿Í
°¥Àº priorityºÎÅÍ ±× À§ÀÇ priority¿¡ °ü·ÃµÈ ·Î±×¸¦ ±â·ÏÇÑ´Ù´Â
°ÍÀÔ´Ï´Ù. ¸¸¾à info ¸¦ ÁöÁ¤Çϸé emerg ºÎÅÍ info »çÀÌÀÇ ¸ðµç
·Î±×¸¦ ±â·ÏÇÏ´Â °ÍÀÌÁö¿ä.

¸¸¾à ´ÜÀÏÇÑ priority¸¦ ÁöÁ¤ÇÏ·Á¸é = ¸¦ »ç¿ëÇÏ¸é µË´Ï´Ù.
!´Â priority ¹üÀ§¸¦ Á¦ÇÑÇÕ´Ï´Ù.
ÀÌ¿¡ ´ëÇؼ­´Â ¾Æ·¡¿¡¼­ ¼³¸íÇÏ´Â ¿¹¸¦ Âü°íÇϼ¼¿ä.

** ¸®´ª½º¿¡¼­ syslogd´Â ¿ø·¡ BSD ¼Ò½º¿¡ ¸î°¡Áö ±â´ÉÀÌ Ãß°¡
µÇ¾ú´Ù. =, ! µîÀÌ ÀÌ¿¡ ¼ÓÇÑ´Ù.


·Î±×ÆÄÀÏÀ» ±â·ÏÀ¸·Î ³²±â´Â ¹æ½Ä¿¡´Â ¿©·¯°¡Áö°¡ ÀÖ´Ù.
°¡Àå ¸ÕÀú ÆÄÀÏÇüÅÂ(/var/log/messages). named pipe.
Å͹̳ΰú ÄܼÖ(/dev/console). ¿ø°Ý ¸Ó½Å(@). »ç¿ëÀÚ.
·Î±×ÀÎÇÑ Àüü »ç¿ëÀÚ(*)

ÀÚ °¡Àå ¸ÕÀú /etc/syslog.conf ¸¦ »ìÆ캸ÀÚ.

# cat /etc/syslog.conf



# Log all kernel messages to the console.
# Logging much else clutters up the screen.
kern.* /dev/console

# ¸ðµç Ä¿³Î ¸Þ½ÃÁö¸¦ ÄַܼÎ.


# Log anything (except mail) of level info or higher.
# Don't log private authentication messages!
*.info;mail.none;authpriv.none /var/log/messages

# ¸ðµç info¸¦ messages¿¡ ±â·Ï. ¿©±â¼­ mail, authpriv °ü·Ã ±â·ÏÀº Á¦¿Ü


# The authpriv file has restricted access.
authpriv.* /var/log/secure

# ¸ðµç ·Î±×ÀÎ ÀÎÁõ °ü·Ã ±â·Ï. su, login µîÀ» ¸ðµÎ ¿©±â ±â·Ï


# Log all the mail messages in one place.
mail.* /var/log/maillog

# ¸ðµç ¸ÞÀÏ ¸Þ½ÃÁö


# Everybody gets emergency messages, plus log them on another
# machine.
*.emerg *

# ºñ»ó ¸Þ½ÃÁö(emerg)´Â ÇöÀç ·Î±×ÀÎÇÑ ¸ðµç »ç¿ëÀÚ¿¡°Ô ¾Ë¸²


# Save mail and news errors of level err and higher in a
# special file.
uucp,news.crit /var/log/spooler

# uucp, news ÀÇ crit Á¤º¸ ±â·Ï


# Save boot messages also to boot.log
local7.* /var/log/boot.log

# ºÎÆ® ¸Þ½ÃÁö ±â·Ï



º¸Åë À§ÀÇ ³»¿ëÀÌ ÀϹÝÀûÀÎ ¹èÆ÷ÆÇ ±¸¼ºÀÌ´Ù.
¾Æ¸¶ kernel ¸Þ½ÃÁö¿¡´Â ÁÖ¼®ÀÌ µÇ¾îÀÖÀ» °ÍÀÌ´Ù.


¿¹¸¦ µé¾î *.err /dev/tty8 ¸¦ Ãß°¡Çغ¸ÀÚ.
³î°íÀÖ´Â tty8 Äֿܼ¡¼­ ½Ã½ºÅÛ¿¡¼­ ¹ß»ýÇÏ´Â ¸ðµç
¿¡·¯¸¦ º¼ ¼ö ÀÖ´Ù.

*.* @taejun

ÀÌ°Ç ¸ðµç ¸Þ½ÃÁö¸¦ taejun À̶ó´Â ¿ø°Ý È£½ºÆ®¿¡¼­ ó¸®Çϵµ·Ï
ÇÒ ¼ö ÀÖ´Ù. ¾î¶² °æ¿ì ÀÌ°Ô À¯¿ëÇÒ±î? ÀÌ°Ç Å¬·¯½ºÅ͸µÀ¸·Î ±¸¼ºµÈ
½Ã½ºÅÛ¿¡¼­ ¾ÆÁÖ À¯¿ëÇÒ °ÍÀÌ´Ù. ¸ðµç syslog ¸Þ½ÃÁö¸¦ ÇÑ´ëÀÇ
½Ã½ºÅÛÀ¸·Î ¸ðÀ» ¼ö ÀÖÀ¸´Ï±ñ.


±×·¯¸é À§ÀÇ ±âº» ¼³Á¤¸»°í ¸î°¡Áö ¿¹¸¦ ´õ º¸ÀÚ.


# Store critical stuff in critical
#
*.=crit;kern.none /var/adm/critical


# Ä¿³ÎÀ» Á¦¿ÜÇÏ°í ¸ðµç crit ¿¡ ÇØ´çÇÏ´Â ¸Þ½ÃÁö ±â·Ï
# (¿©±â¼­ = ¸¦ ÁöÁ¤ÇÑ Â÷ÀÌÁ¡¿¡ ´ëÇؼ­ ÀÌÇØÇؾßÇÔ)



# Kernel messages are first, stored in the kernel
# file, critical messages and higher ones also go
# to another host and to the console
#
kern.* /var/adm/kernel
kern.crit @finlandia
kern.crit /dev/console
kern.info;kern.!err /var/adm/kernel-info


# Ä¿³Î °ü·Ã ¸ðµç ±â·ÏÀº kernel ÆÄÀÏ¿¡,
# Ä¿³Î¿¡¼­ crit ÀÌ»óÀÇ ¸Þ½ÃÁö´Â´Â Äְܼú ¿ø°Ý È£½ºÆ®·Î.
# µÎ¹ø° ºÎºÐ(¿ø°Ý È£½ºÆ®)ÀÌ À¯¿ëÇÑ °ÍÀº ¸¸¾à ½Ã½ºÅÛÀÌ
# ºØ±«Çؼ­ µð½ºÅ©¿¡¼­ º¹±¸ÇÒ ¼ö ¾ø´Â ¿¡·¯°¡ ³µ´õ¶óµµ
# ¿ø°Ý È£½ºÆ®¿¡¼­ ÀÌ ¹®Á¦¸¦ ÇØ°áÇÒ ¼ö ÀÖ´Â ¿øÀÎÀ»
# ãÀ» ¼ö ÀÖ´Ù.
# ÀÌÁ¦ ³×¹ø° ÁÙ. ÀÌ°Ç info ºÎÅÍ err ÀÌÀü ±×·¯´Ï±ñ
# info , notice, warn ¿¡ ´ëÇÑ ¸Þ½ÃÁö¸¦ ±â·ÏÇÑ´Ù.
# ·Î±× ¹üÀ§À» Á¦ÇÑÇÏ´Â °ÍÀÌÁö¿ä.



# The tcp wrapper loggs with mail.info, we display
# all the connections on tty12
#
mail.=info /dev/tty12

# mail.info¿¡ °ü·ÃµÈ ¸Þ½ÃÁö¸¦ 12¹ø° Äֿܼ¡ ±â·Ï.


# Store all mail concerning stuff in a file
#
mail.*;mail.!=info /var/adm/mail


# mail.info ¸¸ Á¦¿ÜÇÏ°í ¸ðµç mail ¸Þ½ÃÁö.


# Log all mail.info and news.info messages to info
#
mail,news.=info /var/adm/info

# mail °ú newsÀÇ info ¸¸ ±â·Ï


# Log info and notice messages to messages file
#
*.=info;*.=notice;\
mail.none /var/log/messages

# info ¿Í notice ¿¡ ÇØ´çÇÏ´Â ¸ðµç ¸Þ½ÃÁö ±â·Ï.
# ¿©±â¼­ mailÀÇ ¸ðµç ¸Þ½ÃÁö¸¸ Á¦¿Ü.



# Log info messages to messages file
#
*.=info;\
mail,news.none /var/log/messages

# ¸ðµç info ¿¡ °ü·ÃµÈ ¸Þ½ÃÁö.
# ´Ü, ¸ÞÀÏ, ´º½ºÀÇ ¸ðµç ¸Þ½ÃÁö´Â Á¦¿Ü



# Emergency messages will be displayed using wall
#
*.=emerg *

# ¸ðµç emergency ¸Þ¼¼Áö¸¦ ÇöÀç ·Î±×ÀÎÇÑ ¸ðµç »ç¿ëÀÚ¿¡°Ô.
# ÀÌ´Â wall °ú °°´Ù.



# Messages of the priority alert will be directed
# to the operator
#
*.alert root,taejun

# ¸ðµç alert ÀÌ»ó ¸Þ½ÃÁö¸¦ root ¿Í taejun »ç¿ëÀÚ¿¡°Ô


*.* @taejun

# ¸ðµç ¸Þ½ÃÁö¸¦ taejun À̶ó´Â ¿ø°Ý È£½ºÆ®·Î
# À§¿¡¼­ ¼³¸íÇß´ø °Íó·³ Ŭ·¯½ºÅ͸µ ½Ã½ºÅÛ¿¡¼­
# ¸ð¸¥ ·Î±× ¸Þ½ÃÁö¸¦ ÇÑ°÷¿¡ ±â·ÏÇÏ´Â °æ¿ì À¯¿ë




logger À¯Æ¿¸®Æ¼´Â ½© ½ºÅ©¸³Æ®¿¡¼­ syslog ±â´ÉÀ» ÀÌ¿ë
¸Þ½ÃÁö¸¦ º¸³¾ ¼ö ÀÖ´Ù.

# logger -p authpriv.alert -t oh_no_login \
"ÅÂÁØÀÌ°¡ ÀÌ»óÇÑ °÷¿¡¼­ ·Î±×ÀÎÇß¾î¿ä... ¿À¿Ê ÀÌ·±~~"


# tail -f secure


Feb 22 18:31:42 taejun oh_no_login: ÅÂÁØÀÌ°¡ ÀÌ»óÇÑ °÷¿¡¼­
·Î±×ÀÎÇß¾î¿ä... ¿À¿Ê ÀÌ·±~~


Á» À¯Ä¡ÇÑ ¿¹ÀÌÁö¿ä????

Âü°í·Î /var/log/wtmp ¸¦ ÀÌ¿ë, last ¸í·ÉÀ¸·Î
»ç¿ëÀÚÀÇ ·Î±×Àΰú °ü·ÃµÈ ±â·ÏÀ» º¼ ¼ö ÀÖ´Ù.

À§ ¼³Á¤ÆÄÀÏ¿¡¼­ /var/log/¿¡ ÀÖ´Â ·Î±×ÆÄÀÏ¿¡ ´ëÇؼ­
¾î´ÀÁ¤µµ ¼³¸íÀ» ´Ù ÇÏ¿´´Ù. ¿©±â¼­ ¾ð±ÞÇÏÁö ¾ÊÀº °ÍÀÌ
xferlog Àε¥ ÀÌ´Â ftp ¼­¹ö¿¡ ´ëÇÑ ·Î±×ÆÄÀÏÀÌ´Ù.


À§ ³»¿ëÀ» Âü°í·Î ÀÚ½ÅÀÇ ¼­¹ö¿¡ ¸Â´Â ·Î±× ±â·ÏÀ» ¼³Á¤Çغ¸ÀÚ.





2. logrotate ÀÌ¿ëÇÑ ·Î±× ÆÄÀÏ °ü¸®
¼­¹®¿¡¼­ ¸»À» ÇÑ´ë·Î ·Î±×ÆÄÀÏÀ» Á¦´ë·Î °ü¸®ÇÏÁö ¾ÊÀ¸¸é
´ëÇü ¼­¹öÀÇ °æ¿ì ·Î±×ÆÄÀ϶§¹®¿¡ Çϵåµð½ºÅ© °ø°£ÀÌ ³²¾Æ³ªÁö
¾Ê°í ¶Ç ·Î±×ÆÄÀÏ Ã³¸®·Î ¹ö¹÷°Å¸®°Ô µÈ´Ù.

´ëºÎºÐ ·¹µåÇÞ ±â¹ÝÀÇ ¹èÆ÷ÆÇ¿¡¼­´Â ±âº»À¸·Î ¼³Ä¡µÇ¾î ÀÖ´Ù.


# rpm -qa | grep logrotate
logrotate-3.3-1


# rpm -ql logrotate
/etc/cron.daily/logrotate
/etc/logrotate.conf
/etc/logrotate.d
/usr/man/man8/logrotate.8
/usr/sbin/logrotate

logrotate´Â °è¼Ó Ä¿Áö´Â ·Î±×ÆÄÀÏÀ» È¿À²ÀûÀ¸·Î
°ü¸®Çϱâ À§ÇÑ ÇÁ·Î±×·¥ÀÌ´Ù.
ÀÚµ¿À¸·Î ·ÎÅ×À̼ÇÀ» ½ÃÄÑÁÖ°í, ¾ÐÃà, Á¦°Å, ¸ÞÀÏ·Î º¸³»Áֱ⠵îÀÇ
ÀÛ¾÷À» ÇÑ´Ù.

Ãʱ⠸®´ª½º ¼³Ä¡½Ã ÀÚµ¿À¸·Î cron¿¡ Ãß°¡°¡ µÈ´Ù.

/etc/cron.daily/logrotate

³»¿ëÀº ´ÙÀ½°ú °°´Ù.

# cat /etc/cron.daily/logrotate

#!/bin/sh

/usr/sbin/logrotate /etc/logrotate.conf


À§¿¡¼­ º¸¸é logrotate °¡ ÇÁ·Î±×·¥ÀÌ°í logrotate.conf°¡
¼³Á¤ÆÄÀÏÀ̶ó´Â °ÍÀ» ¾Ë ¼ö ÀÖÀ» °ÍÀÌ´Ù.
À§¿¡¼­ .conf ÆÄÀÏ´ë½Å ƯÁ¤ µð·ºÅ丮¸¦ ÁöÁ¤Çϸé
±× ÇØ´ç µð·ºÅ丮ÀÇ ¸ðµç ÆÄÀÏÀ» »ç¿ëÇØ ÀÛ¾÷À» ÇÑ´Ù.
logrotate ¿¡ ¿©·¯°¡Áö ¿É¼ÇÀÌ ÀÖÁö¸¸ ±×´ÙÁö »ç¿ëÇÒ ÀÏÀº
¾øÀ» °Í °°´Ù. Ȥ½Ã³ª ±Ã±ÝÇϸé man À¸·Î È®ÀÎ.

¸ÕÀú rotate ¿¡ ´ëÇؼ­ ¼³¸íÇÏ°Ú´Ù.
rotate 3 ¶ó¸é cron ·Î±×¶ó°í ÇßÀ» °æ¿ì.
/var/log µð·ºÅ丮¿¡ cronÀÌ Á¦ÀÏ Ã³À½ »ý¼ºµÇ°í
¼øȯ°£°Ý¸¶¸¶ ¿¹Àü cron Àº cron.1 ÀÌ, cron.1Àº cron.2,
cron.2 ´Â cron.3 À¸·Î µÈ´Ù. ±âÁ¸ÀÇ cron.3Àº »èÁ¦°¡ µÉ °ÍÀÌ´Ù.
±×·¯´Ï±ñ »õ·Î »ý¼ºÇÑ ¸ÞÀϷα׿ܿ¡ ÀÌÀüÀÇ ·Î±×¸¦ 3°³±îÁö ±â·Ï
ÇÏ´Â °ÍÀÌ´Ù.



ÀÚ ±×·¯¸é ÀÌÁ¦ ¼³Á¤ÆÄÀÏÀ» Çѹø »ìÆ캸ÀÚ.

# cat /etc/logrotate.conf


# see "man logrotate" for details
# rotate log files weekly
weekly

# ±âº»ÀûÀ¸·Î ÀÏÁÖÀϸ¶´Ù ·Î±×ÆÄÀÏÀ» ¼øȯ½ÃÅ´


# keep 4 weeks worth of backlogs
rotate 4

# ÀÌÀü ·Î±×ÆÄÀÏÀ» 4ÁÖµ¿¾È °£Á÷.
# À§¿¡¼­ ¼øȯ°£°ÝÀ» 1ÁÖÀÏ·Î ÇßÀ¸¹Ç·Î.



# send errors to root
errors root

# ¿¡·¯°¡ »ý±æ°æ¿ì root ¿¡°Ô ¸ÞÀÏ·Î.


# create new (empty) log files after rotating old ones
create

# ¿¹Àü ·Î±×ÆÄÀÏÀ» ¼øȯ½ÃŲÈÄ »õ·Î¿î ·Î±×ÆÄÀÏ »ý¼º


# uncomment this if you want your log files compressed
#compress

# gzip À» ÀÌ¿ë ¾ÐÃàÇÑ´Ù.


# RPM packages drop log rotation information into this directory
include /etc/logrotate.d

# /etc/logrotate.d ÆÄÀÏ ¶Ç´Â µð·ºÅ丮 ¾È¿¡ ÀÖ´Â ÆÄÀÏÀ» ÀоîµéÀδÙ.
# Âü°í·Î ÇÊÀÚÀÇ ¼­¹ö¿¡´Â ´ÙÀ½°ú °°Àº ±âº»¼³Á¤ ÆÄÀÏÀÌ ÀÖ´Ù.
# ls /etc/logrotate.d
# apache cron ftpd named samba squid syslog
# ¿©±â¼­ °¡Àå Áß¿äÇÑ syslog´Â messages, secure, maillog, spooler,
# bootlog ·Î ±¸¼º



# no packages own lastlog or wtmp -- we'll rotate them here
/var/log/wtmp {
monthly
create 0664 root utmp
rotate 1
}

# ¸Å¿ù¸¶´Ù ¼øȯ½ÃÅ´
# create ´Â ¼øȯÈÄ Áï½Ã (postrotate ½ºÅ©¸³Æ®¸¦ ½ÇÇà½ÃÅ°±âÀü¿¡)
# ·Î±× ÆÄÀÏÀ» »ý¼ºÇÑ´Ù. µÚ¿¡¼­ ¼³¸íÇÒ °ÍÀÌÁö¸¸ postrotate´Â
# ·Î±×ÆÄÀÏÀ» ¼øȯÇÑÈÄ ÁøÇàÇÒ ÀÛ¾÷À» ¸í½ÃÇÑ´Ù.
# 0664 ´Â »ý¼ºÇÏ´Â ÆÄÀÏÀÇ Çã°¡±Ç, root ´Â ¼ÒÀ¯ÀÚ, utmp ´Â ±×·ì
# rotate 1 Àº À§¿¡¼­ ¼³¸íÇß´Ù. ±×·±µ¥ °³º°ÀûÀ¸·Î ¼³Á¤Çϸé
# Ãʱ⿡ ¼³Á¤ÇÑ weekly ´Â ¹«½ÃµÇ °³º° ¼³Á¤À» µû¸¥´Ù
# ±×·¯¹Ç·Î ¿©±â¿¡¼­´Â ÀÌÀüÀÇ ·Î±×ÆÄÀÏÀÌ 1°³¸¸ ³²À»°ÍÀÌ´Ù.
# (¿øº» Á¦¿Ü)
# Âü°í·Î ±âº»ÀûÀ¸·Î syslog¿¡¼­´Â 600À¸·Î Çã°¡±ÇÀ» ¼³Á¤ÇÑ´Ù.
# ´Ù¸¥ ´©±¸µµ ·Î±×ÆÄÀÏ¿¡ Á¢±ÙÇÏ¸é ¾ÈµÇ±â ¶§¹®ÀÌ´Ù.


/var/log/lastlog {
monthly
rotate 1
}

# system-specific logs may be configured here



ÀÌÁ¦ ¸î°¡Áö ÁÖ¿äÇÑ ¿É¼Ç¿¡ ´ëÇؼ­ »ìÆ캸ÀÚ.

¤· ¼øȯÇÒ ±â°£ ¼³Á¤ : daily, weekly, monthly µî
¿©±â¿¡ size ¸¦ ÀÌ¿ëÇØ Å©±â±îÁö ¼³Á¤ÇÒ ¼ö ÀÖ´Ù.
Á¢¼ÓÀÌ ¸¹¾Æ¼­ ·Î±×ÆÄÀÏÀÌ ¾öû³ª°Ô ´Ã¾î³ª´Â °æ¿ì¿¡´Â
size(±âº» kilobytes)¸¦ ÀÌ¿ë Á¦¾îÇØ¾ß ÇÒ °ÍÀÌ´Ù.
size 100k(= size 100)


¤· ¾ÐÃ༳Á¤ : compress
gzipÀ¸·Î ÀÌÀü ·Î±×ÆÄÀÏÀ» ¾ÐÃàÇÑ´Ù.
°ø°£À» Àý¾àÇÒ ¼ö ÀÖ´Ù.
ÀÌ ¿É¼ÇÀ» ¾ø¾Ö·Á¸é ÁÖ¼®À» ´ÞµçÁö ¾Æ´Ï¸é
nocompress(±âº»°ª) »ç¿ë

¤· ¸ÞÀϼ³Á¤ : error, mail
error taejun -> ¿¡·¯¸¦ taejun À̶ó´Â »ç¿ëÀÚ¿¡°Ô º¸³¿
mail taejun -> ·Î±×ÆÄÀÏÀ» ¼øȯ½ÃÅ°°í ³ªÁß¿¡ »èÁ¦ÇؾßÇÒ¶§
»èÁ¦ÇÏÁö ¾Ê°í ¸ÞÀÏ·Î º¸³»´Â °ÍÀÌ´Ù.

¤· ·Î±×ÆÄÀÏ »ý¼º
create mode owner group (±âº»°ª)
À§¿¡¼­ »ç¿ë¿¹´Â ¼³¸íÇß´Ù. create ¸¦ ÁöÁ¤ÇÏ¸é ¼øȯÈÄ ·Î±×
ÆÄÀÏÀ» »ý¼ºÇÑ´Ù. ¹Ý´ë´Â nocreate

¤· ¼øȯ°£°Ý : rotate count
ÀÌÀü ·Î±×ÆÄÀÏÀÌ »èÁ¦µÇ°Å³ª ¸ÞÀÏ·Î º¸³»±âÀü¿¡ ¼øȯÀ» ÇÒ
Ƚ¼ö ÁöÁ¤. ¿©±â¼­ 0À¸·Î ÁöÁ¤ÇÏ¸é ¿¹Àü ·Î±×ÆÄÀÏÀº
¹«Á¶°Ç »èÁ¦µÈ´Ù.


¤· ÁöÁ¤ÇÑ ·Î±×ÆÄÀÏÀÌ ¾øÀ» °æ¿ì : missingok, nomissingok
·Î±×ÆÄÀÏÀÌ ¾øÀ¸¸é ±âº»Àº ¿¡·¯¸¦ ³½´Ù(nomissingok, ±âº»°ª).
missingok ¸¦ ÁöÁ¤ÇÏ¸é ¾ø´õ¶óµµ ¿¡·¯¸¦ ³»Áö´Â ¾Ê´Â´Ù.


¤· ·Î±×ÆÄÀÏÀÇ ³»¿ëÀÌ ¾øÀ» °æ¿ì(ºñ¾îÀÖÀ»°æ¿ì)
±âº»Àº ifempty·Î ³»¿ëÀÌ ºñ¾ú¾îµµ ¼øȯÀ» ÇÑ´Ù.
¼øȯÀ» ÇÏÁö ¾Êµµ·Ï ÇÏ·Á¸é notifempty ¸¦ ÁöÁ¤ÇÏ¸é µÈ´Ù.


¤· ¼øȯÈÄ ÀÛ¾÷ : postrotate/endscript
¼øȯÇϱâÀü ÀÛ¾÷À» ÇÏ·Á¸é prerotate/endscript
¸¦ »ç¿ëÇÑ´Ù. ÀϹÝÀûÀ¸·Î´Â ¼øȯÈÄ ÀÛ¾÷À» ÇÒ °ÍÀÌ´Ù.
¿¹¸¦ µé¾î ¸ÞÀÏ°ü·Ã ·Î±×¸¦ »õ·Î »ý¼ºÇßÀ¸¸é syslogd¸¦
´Ù½Ã °¡µ¿½ÃÄÑ¾ß ÇÒ °ÍÀÌ´Ù. ÀÌ·±°ÍµéÀ» ÁöÁ¤ÇÑ´Ù.

¤· ÆÄÀÏ ¶Ç´Â µð·ºÅ丮 Æ÷ÇÔ : include
´Ù¸¥ ÆÄÀÏÀ̳ª µð·ºÅ丮¾ÈÀÇ ÆÄÀÏÀ» Æ÷ÇÔÇÒ °æ¿ì




ÀÚ ÀÌ¿¡ À§ÀÇ ³»¿ëÀ» Åä´ë·Î ¸ÞÀÏÀÇ ·Î±×¸¦ Á¶Á¤Çغ¸ÀÚ.
¿©±â¼­´Â /etc/logrotate.d/syslog ¿¡¼­ ¸ÞÀϼ­¹öÀÇ
·Î±×¸¸ µû·Î 󸮸¦ Çغ¸°Ú´Ù.

# vi /etc/logrotate.d/maillog
weekly
size 500k
rotate 4
compress
errors admin
mail admin
nomissingok
create 0644 root root
/var/log/maillog {
postrotate
/usr/bin/killall -HUP syslogd
endscript
}


/var/log/messages {
postrotate
/usr/bin/killall -HUP syslogd
endscript
}


À§ÀÇ ¿¹Á¦´Â ±×³É Âü°í·Î ¸¸µç °ÍÀ̹ǷΠµû¶óÇÒ ÇÊ¿ä´Â ¾ø´Ù.
¸ÅÁÖ¸¶´Ù Çѹø½Ä ¼øȯ½ÃÅ°°í Å©±â°¡ 500k°¡ ³ÑÁö ¾Êµµ·Ï Çϸç
¼øȯÇÑ ÆÄÀÏÀº ¾ÐÃàÀ» ÇÑ´Ù. ¿¡·¯¸¦ admin À̶ó´Â »ç¿ëÀÚ¿¡°Ô
º¸³»°í ¼øȯÈÄ »èÁ¦ÇÒ ÆÄÀÏÀ» ¸ÞÀÏ·Î admin ¿¡°Ô º¸³½´Ù.
¸¸¾à ·Î±×ÆÄÀÏÀÌ ¾øÀ¸¸é ¿¡·¯¸¦ ³»¸ç ¼øȯÈÄ ÆÄÀÏÀ» »ý¼º½ÃÅ°°í
ÀÌ ÆÄÀÏÀÇ ¸ðµå´Â 0644 ·Î ¼ÒÀ¯ÀÚ¿Í ±×·ìÀº root ·Î ÇÑ´Ù.


¼­ºñ½ºÀÇ ±Ô¸ð¿¡ µû¶ó ·Î±×ÆÄÀÏÀ» ¼øȯÇÒ Áֱ⸦ ´õ ª°Ô Àâ¾Æ¾ß
ÇÑ´Ù. Å©±â¸¦ ÁöÁ¤Çϴ°ÍÀÌ ¿©·¯¸ð·Î È¿À²ÀûÀÏ °ÍÀÌ´Ù.




3. ¸¶Ä¡¸ç
¿©±â±îÁö Àоú´Ù¸é ´ë·« ½Ã½ºÅÛÀÇ ·Î±×°¡ ¾î¶»°Ô ÀÛ¼ºµÇ°í
¾î¶»°Ô °ü¸®¸¦ ÇؾßÇÒÁö °¨À» Àâ¾ÒÀ» °ÍÀÌ´Ù.
½Ã½ºÅÛÀÌ ³ª»Ú´Ù´Â °ÍÀ» Å¿ÇÏÁö Àü¿¡ °ü¸®ÀÚ°¡ ¾ó¸¶³ª
½Ã½ºÅÛÀÇ »óŸ¦ ÁÖ±âÀûÀ¸·Î Á¡°ËÇÏ°í ÃÖÀûÈ­ÇÏ´ÂÁö°¡
Áß¿äÇÏ´Ù.




### Âü°í : ¼­¹ö ·Î±×¸¦ ´Ù¸¥ È£½ºÆ®¿¡ ±â·ÏÇϱâ

Ŭ·¯½ºÅ͸µ ½Ã½ºÅÛÀ» ±¸¼ºÇÏ´Â °æ¿ì ¿©·¯ ¼­¹ö·Î ·Î±×°¡ ³ª´©¾îÁý´Ï´Ù.
ÀÌ·² °æ¿ì Áß¾ÓÀÇ °ü¸®ÀÚ¿ë ¼­¹ö·Î ·Î±×¸¦ ÁýÁß½Ãų ¼ö ÀÖ½À´Ï´Ù.


1. ¸ÕÀú È®ÀÎÇØ¾ß ÇÒ °Í
/etc/services
syslog 514/udp

·Î±×¸¦ ¸¸µå´Â ÂÊ°ú ¹Þ´Â ÂÊ µÎ±ºµ¥¿¡¼­ ´Ù ÇÊ¿äÇÕ´Ï´Ù.
º¸Åë ±âº» ¼³Á¤µÇ¾îÀÖÀ» °ÍÀÔ´Ï´Ù.
¸Þ½ÃÁö¸¦ ÁÖ°í¹Þ´Âµ¥ UDP Æ÷Æ®°¡ ÇÊ¿äÇϱ⠶§¹®ÀÔ´Ï´Ù.


2. ·Î±×¸¦ ÀÛ¼ºÇÏ´Â ¼­¹ö¿¡¼­ ÇÊ¿äÇÑ ¼³Á¤.

/etc/syslog.conf

mail.info @admin

ÀÌ°Ç mail.info ¿¡ ÇØ´çÇÏ´Â ·Î±×¸¦ admin À̶ó´Â È£½ºÆ®·Î º¸³»´Â °ÍÀÔ´Ï´Ù.

ÀÌ¿ÕÀ̸é adminÀº DNS¿¡ ¹®Á¦°¡ »ý±æ ¼öµµ ÀÖÀ¸¹Ç·Î /etc/hosts¿¡ µî·ÏÇØ
µÎ´Â °ÍÀÌ ÁÁÀ» °ÍÀÔ´Ï´Ù.

ÇÊ¿äÇÏ´Ù¸é *.* À» ÀÌ¿ë ÀüºÎ¸¦ ´Ù º¸³¾ ¼öµµ ÀÖ°ÚÁö¿ä.
ÀÌ°Ô ÁÁÀº°Ô ¹¹³Ä¸é ½Ã½ºÅÛÀÌ ¸ÀÀÌ °¡´õ¶óµµ ¿ø°Ý È£½ºÆ®¿¡µµ ·Î±× ÆÄÀÏÀÌ
³²À¸¹Ç·Î ³ªÁß¿¡ ºÐ¼®À» ÇÒ ¼ö ÀÖ´Ù´Â °ÍÀÔ´Ï´Ù.


3. ·Î±×¸¦ ¹Þ´Â ¼­¹ö¿¡¼­ ÇÊ¿äÇÑ ¼³Á¤
syslogd ´ë¸óÀ» ½ÃÀÛÇÒ¶§ Ãß°¡ ¿É¼ÇÀÌ ÇÊ¿äÇÕ´Ï´Ù.
·¹µåÇÞÀÇ °æ¿ì ½ÃÀÛÆÄÀÏÀº ´ÙÀ½°ú °°Àº ÇüÅÂÀÏ °ÍÀÔ´Ï´Ù.

/etc/rc.d/init.d/syslog

¿©±â¼­ ´ë¸óÀ» ½ÃÀÛÇÏ´Â ¿É¼ÇÀ¸·Î

daemon syslogd -m 0 -r -h

ÀÌ·¸°Ô »ç¿ëÀ» ÇÕ´Ï´Ù.

-m 0 : ±âº»¼³Á¤µÇ¾îÀִ°ÍÀ¸·Î º¯°æÇÏÁö ¾Ê¾Æµµ µË´Ï´Ù. ÀÌ°Ç ÁöÁ¤ÇÑ ºÐµ¿¾È¿¡
MARK ¶ó°í ·Î±×ÆÄÀÏ¿¡ ±â·ÏÀ» ÇÕ´Ï´Ù. 0ÀÌ¸é ±â·ÏÀ» ÇÏÁö ¾Ê´Â °ÍÀÌÁö¿ä.
-r : ÀÎÅÍ³Ý µµ¸ÞÀÎ ¼ÒÄÏÀ» ÀÌ¿ëÇØ ³×Æ®¿÷¿¡¼­ ¸Þ½ÃÁö¸¦ ¹Þ´Â ¿É¼Ç
-h : ±âº»ÀûÀ¸·Î syslogd´Â ¿ø°Ý È£½ºÆ®¿¡¼­ ¹ÞÀº ¸Þ½ÃÁö¸¦ ·Î±× ±â·ÏÀ¸·Î Àü¼ÛÇÏÁö
¾Ê½À´Ï´Ù. ÀÌ ¿É¼ÇÀ» »ç¿ëÇÏ¿© ¿ø°Ý È£½ºÆ®¿¡¼­ ¹ÞÀº ·Î±×ÆÄÀÏÀ» Àü¼ÛÇÕ´Ï´Ù.
(Àü¼ÛÀ̶õ ¹ÞÀº ÂÊÀÇ ·Î±× ÆÄÀÏ¿¡ ±â·ÏÇÑ´Ù°í »ý°¢ÇÏ¸é µË´Ï´Ù)

man syslogd ¸¦ Çغ¸¸é µµ¿òÀ» ¾òÀ» ¼ö ÀÖ½À´Ï´Ù.

syslogdÀÇ º¸¾ÈÀ» À§ÇÑ º¸¾È ÆÐÅ°Áöµµ ÀÖ½À´Ï´Ù.

http://www.core-sdi.com/english/freesoft.htm
secure system logging tool ÀÔ´Ï´Ù.
±×·±µ¥ Áö¿øÇÏ´Â °ÍÀ» º¸¸é ½½·¢¿þ¾îÀ̱º¿ä.
ÄÄÆÄÀÏÇÏ¿© ¼³Ä¡ÇÏ´Â °ÍÀ̴ϱñ ¹«³­È÷ ¼³Ä¡µÉ °ÍÀÌ¶ó ¿¹»óµÇ³×¿ä.  


  ÃßõÇÏ±â   ¸ñ·Ïº¸±â

Copyright 1999-2024 Zeroboard / skin by zero