Chapter 13 - Configuring Logging Flashcards

1
Q

What are the 3 different approaches by services to write log information?

A
  1. Direct Write
  2. rsyslogd
  3. journald
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is rsyslogd?

A

rsyslog id is the enhancement of syslogd, a service that takes care of managing centralized log files.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which daemon implements the journald?

A

systemd-joiurnald daemon

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does journald collect?

A

journald collects messages from the kernel, the entire boot procedure, and services and writes these messages to an event journal. This event journal is stored in a binary format, and it can be queried using the journalctl command.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Apart from rsyslogd and systemd-journald, there is the auditd service, What does the Audit service do?

A

This service provides auditing, an in-depth trace of what specific services, processes, or users have
been doing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Who writes the files to /var/log?

A

rsyslogd

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which command helps users to write messages to rsyslog from the command line or a script?

A

logger command

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Where is the configuration file for rsyslogd located?

A

/etc/rsyslog.conf

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

The rsyslog.conf file is used for what purpose?

A

This file is used to specify what should be logged and where it should be logged.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is facility, priority and destination in logging?

A

A facility specifies a category of information that is logged. rsyslogd uses a fixed list of facilities, which cannot be extended.
A priority is used to define the severity of the message that needs to be logged.
A destination defines where the message should be written

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the logrotate feature?

A

To prevent syslog messages from filling up your system completely, the log messages can be rotated. That means that when a certain threshold has been reached, the old log file is closed and a new log file is opened.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Where are the default setting for log rotation kept?

A

/etc/logrotate.conf

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

By default where is the journal log file stored?

A

/run/log/journal

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the entire directory /run used for?

A

The entire /run directory is used for current process status information only.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly