{"id":6048,"date":"2014-03-09T10:17:28","date_gmt":"2014-03-09T14:17:28","guid":{"rendered":"http:\/\/g33kinfo.com\/info\/?p=6048"},"modified":"2014-03-09T10:17:28","modified_gmt":"2014-03-09T14:17:28","slug":"common-linux-log-files","status":"publish","type":"post","link":"https:\/\/g33kinfo.com\/info\/common-linux-log-files\/","title":{"rendered":"Common Linux Log Files"},"content":{"rendered":"<p>&nbsp;<\/p>\n<div class=\"post-header\"><\/div>\n<p>&nbsp;<\/p>\n<div class=\"post-body entry-content\" id=\"post-body-7256318887016413630\">\n<div style=\"float: right;\"><\/div>\n<div dir=\"ltr\" style=\"text-align: left;\">If you spend lot of time in Linux, it is essential that you know where the log files are located, and what is contained in each and every log file.<\/p>\n<p>\/etc\/rsyslog.conf controls what goes inside some of the log files. For example, following is the entry in rsyslog.conf for \/var\/log\/messages.<\/p>\n<div class=\"block-panel\"><span style=\"font-family: 'Courier New',Courier,monospace;\"><b>$ grep &#8220;\/var\/log\/messages&#8221; \/etc\/rsyslog.conf<\/b><\/span><br \/>\n<span style=\"font-family: 'Courier New',Courier,monospace;\"><b><br \/>\n<\/b><\/span> <span style=\"font-family: 'Courier New',Courier,monospace;\"><b>*.info;mail.none;authpriv.none;cron.none <\/b><\/span><br \/>\n<span style=\"font-family: 'Courier New',Courier,monospace;\"><b>\/var\/log\/messages <\/b><\/span>\n<\/div>\n<p>In the above output&#8230;<br \/>\n<!--more--><\/p>\n<p>*.info indicates that all logs with type INFO will be logged.<br \/>\nmail.none,authpriv.none,cron.none indicates that those error messages should not be logged into the \/var\/log\/messages file.<br \/>\nYou can also specify *.none, which indicates that none of the log messages will be logged.<\/p>\n<p>The following are the 20 different log files that are located under \/var\/log\/ directory. Some of these log files are distribution specific. For example, you\u2019ll see dpkg.log on Debian based systems (for example, on Ubuntu).<\/p>\n<p><b>\/var\/log\/messages<\/b>\u2013 Contains global system messages, including the messages that are logged during system startup. There are several things that are logged in \/var\/log\/messages including mail, cron, daemon, kern, auth, etc.<br \/>\n<b>\/var\/log\/dmesg<\/b>\u2013 Contains kernel ring buffer information. When the system boots up, it prints number of messages on the screen that displays information about the hardware devices that the kernel detects during boot process. These messages are available in kernel ring buffer and whenever the new message comes the old message gets overwritten. You can also view the content of this file using the dmesg command.<br \/>\n<b>\/var\/log\/auth.log<\/b> \u2013 Contains system authorization information, including user logins and authentication machinsm that were used.<br \/>\n<b>\/var\/log\/boot.log<\/b> \u2013 Contains information that are logged when the system boots<br \/>\n<b>\/var\/log\/daemon.log<\/b> \u2013 Contains information logged by the various background daemons that runs on the system<br \/>\n<b>\/var\/log\/dpkg.log<\/b> \u2013 Contains information that are logged when a package is installed or removed using dpkg command<br \/>\n<b>\/var\/log\/kern.log<\/b> \u2013 Contains information logged by the kernel. Helpful for you to troubleshoot a custom-built kernel.<br \/>\n<b>\/var\/log\/lastlog<\/b>\u2013 Displays the recent login information for all the users. This is not an ascii file. You should use lastlog command to view the content of this file.<br \/>\n<b>\/var\/log\/maillog<\/b> <b>\/var\/log\/mail.log<\/b> \u2013 Contains the log information from the mail server that is running on the system. For example, sendmail logs information about all the sent items to this file<br \/>\n<b>\/var\/log\/user.log<\/b> \u2013 Contains information about all user level logs<br \/>\n<b>\/var\/log\/Xorg.x.log<\/b> \u2013 Log messages from the X<br \/>\n<b>\/var\/log\/alternatives.log<\/b> \u2013 Information by the update-alternatives are logged into this log file. On Ubuntu, update-alternatives maintains symbolic links determining default commands.<br \/>\n<b>\/var\/log\/btmp<\/b> (lastb command; shows all bad login attempts) \/var\/log\/wtmp (displays all users logged in and out since the file is created&#8230;last command;login attempts)\u2013 This file contains information about failed login attemps. Use the last command to view the btmp file. For example, \u201clast -f \/var\/log\/btmp | more\u201d<br \/>\n<b>\/var\/log\/cups<\/b>\u2013 All printer and printing related log messages<br \/>\n<b>\/var\/log\/anaconda.log<\/b> \u2013 When you install Linux, all installation related messages are stored in this log file<br \/>\n<b>\/var\/log\/yum.log<\/b> \u2013 Contains information that are logged when a package is installed using yum<br \/>\n<b>\/var\/log\/cron<\/b>\u2013 Whenever cron daemon(or anacron) starts a cron job, it logs the information about the cron job in this file<br \/>\n<b>\/var\/log\/secure<\/b>\u2013 Contains information related to authentication and authorization privileges. For example, sshd logs all the messages here, including unsuccessful login.<br \/>\n<b>\/var\/log\/wtmp or \/var\/log\/utmp<\/b>\u2013 Contains login records. Using wtmp you can find out who is logged into the system. who command uses this file to display the information.<br \/>\n<b>\/var\/log\/faillog<\/b>\u2013 Contains user failed login attemps. Use faillog command to display the content of this file.<br \/>\nApart from the above log files, \/var\/log directory may also contain the following sub-directories depending on the application that is running on your system.<br \/>\n<b>\/var\/log\/httpd\/ (or) \/var\/log\/apache2<\/b>\u2013 Contains the apache web server access_log and error_log<br \/>\n<b>\/var\/log\/lighttpd\/<\/b>\u2013 Contains light HTTPD access_log and error_log<br \/>\n<b>\/var\/log\/conman\/<\/b>\u2013 Log files for ConMan client. conman connects remote consoles that are managed by conmand daemon.<br \/>\n<b>\/var\/log\/mail\/<\/b>\u2013 This subdirectory contains additional logs from your mail server. For example, sendmail stores the collected mail statistics in \/var\/log\/mail\/statistics file<br \/>\n<b>\/var\/log\/prelink\/<\/b>\u2013 prelink program modifies shared libraries and linked binaries to speed up the startup process.<br \/>\n<b>\/var\/log\/prelink\/prelink.log<\/b> contains the information about the .so file that was modified by the prelink.<br \/>\n<b>\/var\/log\/audit\/<\/b>\u2013 Contains logs information stored by the Linux audit daemon (auditd).<br \/>\n<b>\/var\/log\/setroubleshoot\/<\/b>\u2013 SELinux uses setroubleshootd (SE Trouble Shoot Daemon) to notify about issues in the security context of files, and logs those information in this log file.<br \/>\n<b>\/var\/log\/samba\/<\/b>\u2013 Contains log information stored by samba, which is used to connect Windows to Linux.<br \/>\n<b>\/var\/log\/sa\/<\/b>\u2013 Contains the daily sar files that are collected by the sysstat package.<br \/>\n<b>\/var\/log\/sssd\/<\/b>\u2013 Use by system security services daemon that manage access to remote directories and authentication mechanisms.<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; &nbsp; If you spend lot of time in Linux, it is essential that you know where the log files are located, and what is contained in each and every log file. \/etc\/rsyslog.conf controls what goes inside some of the log files. For example, following is the entry in rsyslog.conf for \/var\/log\/messages. $ grep &#8220;\/var\/log\/messages&#8221;&#8230; <\/p>\n<div class=\"read-more navbutton\"><a href=\"https:\/\/g33kinfo.com\/info\/common-linux-log-files\/\">Read More<i class=\"fa fa-angle-double-right\"><\/i><\/a><\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[],"class_list":["post-6048","post","type-post","status-publish","format-standard","hentry","category-info"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.9 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Common Linux Log Files - Linux Shtuff<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/g33kinfo.com\/info\/common-linux-log-files\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Common Linux Log Files - Linux Shtuff\" \/>\n<meta property=\"og:description\" content=\"&nbsp; &nbsp; If you spend lot of time in Linux, it is essential that you know where the log files are located, and what is contained in each and every log file. \/etc\/rsyslog.conf controls what goes inside some of the log files. For example, following is the entry in rsyslog.conf for \/var\/log\/messages. $ grep &#8220;\/var\/log\/messages&#8221;... Read More\" \/>\n<meta property=\"og:url\" content=\"https:\/\/g33kinfo.com\/info\/common-linux-log-files\/\" \/>\n<meta property=\"og:site_name\" content=\"Linux Shtuff\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/fb.me\/g33kinf0\" \/>\n<meta property=\"article:author\" content=\"https:\/\/fb.me\/g33kinf0\" \/>\n<meta property=\"article:published_time\" content=\"2014-03-09T14:17:28+00:00\" \/>\n<meta name=\"author\" content=\"g33kadmin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@https:\/\/twitter.com\/drsinger1111\" \/>\n<meta name=\"twitter:site\" content=\"@drsinger1111\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/g33kinfo.com\\\/info\\\/common-linux-log-files\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/g33kinfo.com\\\/info\\\/common-linux-log-files\\\/\"},\"author\":{\"name\":\"g33kadmin\",\"@id\":\"https:\\\/\\\/g33kinfo.com\\\/info\\\/#\\\/schema\\\/person\\\/c022e4c40b13ea1b678e6f020756f547\"},\"headline\":\"Common Linux Log Files\",\"datePublished\":\"2014-03-09T14:17:28+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/g33kinfo.com\\\/info\\\/common-linux-log-files\\\/\"},\"wordCount\":875,\"publisher\":{\"@id\":\"https:\\\/\\\/g33kinfo.com\\\/info\\\/#\\\/schema\\\/person\\\/c022e4c40b13ea1b678e6f020756f547\"},\"articleSection\":[\"General Info\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/g33kinfo.com\\\/info\\\/common-linux-log-files\\\/\",\"url\":\"https:\\\/\\\/g33kinfo.com\\\/info\\\/common-linux-log-files\\\/\",\"name\":\"Common Linux Log Files - Linux Shtuff\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/g33kinfo.com\\\/info\\\/#website\"},\"datePublished\":\"2014-03-09T14:17:28+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/g33kinfo.com\\\/info\\\/common-linux-log-files\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/g33kinfo.com\\\/info\\\/common-linux-log-files\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/g33kinfo.com\\\/info\\\/common-linux-log-files\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/g33kinfo.com\\\/info\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Common Linux Log Files\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/g33kinfo.com\\\/info\\\/#website\",\"url\":\"https:\\\/\\\/g33kinfo.com\\\/info\\\/\",\"name\":\"Linux Shtuff\",\"description\":\"Because I have CRS Syndrome...\",\"publisher\":{\"@id\":\"https:\\\/\\\/g33kinfo.com\\\/info\\\/#\\\/schema\\\/person\\\/c022e4c40b13ea1b678e6f020756f547\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/g33kinfo.com\\\/info\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/g33kinfo.com\\\/info\\\/#\\\/schema\\\/person\\\/c022e4c40b13ea1b678e6f020756f547\",\"name\":\"g33kadmin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/g33kinfo.com\\\/info\\\/wp-content\\\/uploads\\\/2022\\\/07\\\/minion-researchA.gif\",\"url\":\"https:\\\/\\\/g33kinfo.com\\\/info\\\/wp-content\\\/uploads\\\/2022\\\/07\\\/minion-researchA.gif\",\"contentUrl\":\"https:\\\/\\\/g33kinfo.com\\\/info\\\/wp-content\\\/uploads\\\/2022\\\/07\\\/minion-researchA.gif\",\"width\":512,\"height\":512,\"caption\":\"g33kadmin\"},\"logo\":{\"@id\":\"https:\\\/\\\/g33kinfo.com\\\/info\\\/wp-content\\\/uploads\\\/2022\\\/07\\\/minion-researchA.gif\"},\"description\":\"I am a g33k, Linux blogger, developer, student and Tech Writer for Liquidweb.com\\\/kb. My passion for all things tech drives my hunt for all the coolz. I often need a vacation after I get back from vacation....\",\"sameAs\":[\"https:\\\/\\\/thelinuxreport.com\",\"https:\\\/\\\/fb.me\\\/g33kinf0\",\"https:\\\/\\\/x.com\\\/https:\\\/\\\/twitter.com\\\/drsinger1111\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Common Linux Log Files - Linux Shtuff","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/g33kinfo.com\/info\/common-linux-log-files\/","og_locale":"en_US","og_type":"article","og_title":"Common Linux Log Files - Linux Shtuff","og_description":"&nbsp; &nbsp; If you spend lot of time in Linux, it is essential that you know where the log files are located, and what is contained in each and every log file. \/etc\/rsyslog.conf controls what goes inside some of the log files. For example, following is the entry in rsyslog.conf for \/var\/log\/messages. $ grep &#8220;\/var\/log\/messages&#8221;... Read More","og_url":"https:\/\/g33kinfo.com\/info\/common-linux-log-files\/","og_site_name":"Linux Shtuff","article_publisher":"https:\/\/fb.me\/g33kinf0","article_author":"https:\/\/fb.me\/g33kinf0","article_published_time":"2014-03-09T14:17:28+00:00","author":"g33kadmin","twitter_card":"summary_large_image","twitter_creator":"@https:\/\/twitter.com\/drsinger1111","twitter_site":"@drsinger1111","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/g33kinfo.com\/info\/common-linux-log-files\/#article","isPartOf":{"@id":"https:\/\/g33kinfo.com\/info\/common-linux-log-files\/"},"author":{"name":"g33kadmin","@id":"https:\/\/g33kinfo.com\/info\/#\/schema\/person\/c022e4c40b13ea1b678e6f020756f547"},"headline":"Common Linux Log Files","datePublished":"2014-03-09T14:17:28+00:00","mainEntityOfPage":{"@id":"https:\/\/g33kinfo.com\/info\/common-linux-log-files\/"},"wordCount":875,"publisher":{"@id":"https:\/\/g33kinfo.com\/info\/#\/schema\/person\/c022e4c40b13ea1b678e6f020756f547"},"articleSection":["General Info"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/g33kinfo.com\/info\/common-linux-log-files\/","url":"https:\/\/g33kinfo.com\/info\/common-linux-log-files\/","name":"Common Linux Log Files - Linux Shtuff","isPartOf":{"@id":"https:\/\/g33kinfo.com\/info\/#website"},"datePublished":"2014-03-09T14:17:28+00:00","breadcrumb":{"@id":"https:\/\/g33kinfo.com\/info\/common-linux-log-files\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/g33kinfo.com\/info\/common-linux-log-files\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/g33kinfo.com\/info\/common-linux-log-files\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/g33kinfo.com\/info\/"},{"@type":"ListItem","position":2,"name":"Common Linux Log Files"}]},{"@type":"WebSite","@id":"https:\/\/g33kinfo.com\/info\/#website","url":"https:\/\/g33kinfo.com\/info\/","name":"Linux Shtuff","description":"Because I have CRS Syndrome...","publisher":{"@id":"https:\/\/g33kinfo.com\/info\/#\/schema\/person\/c022e4c40b13ea1b678e6f020756f547"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/g33kinfo.com\/info\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/g33kinfo.com\/info\/#\/schema\/person\/c022e4c40b13ea1b678e6f020756f547","name":"g33kadmin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/g33kinfo.com\/info\/wp-content\/uploads\/2022\/07\/minion-researchA.gif","url":"https:\/\/g33kinfo.com\/info\/wp-content\/uploads\/2022\/07\/minion-researchA.gif","contentUrl":"https:\/\/g33kinfo.com\/info\/wp-content\/uploads\/2022\/07\/minion-researchA.gif","width":512,"height":512,"caption":"g33kadmin"},"logo":{"@id":"https:\/\/g33kinfo.com\/info\/wp-content\/uploads\/2022\/07\/minion-researchA.gif"},"description":"I am a g33k, Linux blogger, developer, student and Tech Writer for Liquidweb.com\/kb. My passion for all things tech drives my hunt for all the coolz. I often need a vacation after I get back from vacation....","sameAs":["https:\/\/thelinuxreport.com","https:\/\/fb.me\/g33kinf0","https:\/\/x.com\/https:\/\/twitter.com\/drsinger1111"]}]}},"_links":{"self":[{"href":"https:\/\/g33kinfo.com\/info\/wp-json\/wp\/v2\/posts\/6048","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/g33kinfo.com\/info\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/g33kinfo.com\/info\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/g33kinfo.com\/info\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/g33kinfo.com\/info\/wp-json\/wp\/v2\/comments?post=6048"}],"version-history":[{"count":0,"href":"https:\/\/g33kinfo.com\/info\/wp-json\/wp\/v2\/posts\/6048\/revisions"}],"wp:attachment":[{"href":"https:\/\/g33kinfo.com\/info\/wp-json\/wp\/v2\/media?parent=6048"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/g33kinfo.com\/info\/wp-json\/wp\/v2\/categories?post=6048"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/g33kinfo.com\/info\/wp-json\/wp\/v2\/tags?post=6048"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}