rsyslog server - Can you split up and organize logs?

Posted by Jakobud on Server Fault See other posts from Server Fault or by Jakobud
Published on 2011-01-05T21:38:24Z Indexed on 2011/01/05 21:56 UTC
Read the original article Hit count: 242

Filed under:
|

I recently setup one of our servers as an rsyslog server. I now have our firewall setup to log everything to that rsyslog server.

But there doesn't seem to be an organization of the logs. All the firewall logs are just being dumped into the /var/log/messages on the rsyslog server. I guess I was maybe expecting them to at least be in a machine specific log file or directory.

How can I organize the incoming logging? If I setup 20 servers to all log everything to a central rsyslog server, I really don't want everything being dumped into one big file or a few files. How can I setup rsyslog to tell it where to log what? Like if all the logs for a specific server were in it's own directory/file, etc... Is this possible?

© Server Fault or respective owner

Related posts about centos

Related posts about rsyslog