如何通过CentOS Syslog高效监控系统状态,实现系统安全保障?

更新于
2026-09-29 17:04:22
2阅读来源:SEO资讯
  • 内容介绍
  • 文章标签
  • 相关推荐

为什么 CentOS Syslog 监控常让运维头疼?

日志分散在多个文件中,难以快速定位关键错误;日志文件随时间膨胀,磁盘易被占满导致服务异常;怎么说呢,缺乏实时告警机制。问题往往在事后才被发现;手工过滤日志费时费力,影响故障响应速度。

一、确保 rsyslog 服务正常运行

1. 检查服务状态

sudo systemctl status rsyslog

如何通过CentOS Syslog系统安全保障?

2. 未运行则启动并设置开机自启

sudo systemctl start rsyslog sudo systemctl enable rsyslog

1. 编辑主配置文件

sudo vi /etc/rsyslog.conf

确保以下行未被注释: $ModLoad imjournal # 读取 systemd journal $OmitLocalLogging on # 防止重复记录 $ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat

2. 按设施与级别分文件存储

/etc/rsyslog.d/00-local.conf

*.* -/var/log/messages
authpriv.* /var/log/secure
mail.* -/var/log/maillog
cron.* /var/log/cron
local0.* /var/log/local0.log
local1.* /var/log/local1.log
...

3. 重载配置使更改生效

1. 使用 tail -f 查看最新日志

sudo tail -f /var/log/secure # 安全相关日志

2. 配合 grep/egrep 快速过滤关键字

sudo egrep "Invalid user|Failed password" /var/log/secure # SSH暴力

3. 用 awk 输出摘要信息

痛点缓解通过组合 tail -f + grep/awk 能在秒级内看到异常,避免“事后才发现问题”的困扰。

/etc/logrotate.d/syslog 配置示例
/var/log/messages {
daily
rotate 7
compress
delaycompress
missingok
notifempty
create 640 root adm
sharedscripts
postrotate
systemctl kill -s HUP rsyslog.service>/dev/null 2>&1 || true
endscript
}
/var/log/secure {
daily
rotate 4
compress
delaycompress
missingok
notifempty
create 600 root root
}

效果每天自动压缩旧日志,保留最近若干天彻底避免磁盘被撑满导致服务不可用的风险。

/etc/rsyslog.d/remote.conf
*.* @192.168.10.50:514 # UDP 转发,可改为 @@ 开头使用 TCP
# 若需可靠传输:
*.* @@192.168.10.50:514;
RSYSLOG_SyslogProtocol23Format

痛点缓解不再需要逐台登录看日志,所有主机的统一视图让安全事件能够在全局范围内快速关联。

ELK Stack Logstash 收集 rsyslog 输出 → 写入 Elasticsearch → Kibana 提供仪表盘、字段分析。 Graylog 直接接受 syslog/UDP/TCP,内置流规则与告警插件。 Promeus + Grafana 适合已有监控程序的团队,把异常日币转为指标触发告警。 自建告警脚本 说到示例,每分钟检查 /var/log/secure 中是否出现 Failed password 超过 5 次若触发则发送邮件或 Webhook。从代码片段来看,

#!/bin/bash
THRESHOLD=5
COUNT=$
if;n
echo "SSH brute force detected " | mail -s "Security Alert"
fi

html

如何通过CentOS Syslog系统安全保障?

)

) ) ) ) ) ) ) ) ) )

标签:CentOS

为什么 CentOS Syslog 监控常让运维头疼?

日志分散在多个文件中,难以快速定位关键错误;日志文件随时间膨胀,磁盘易被占满导致服务异常;怎么说呢,缺乏实时告警机制。问题往往在事后才被发现;手工过滤日志费时费力,影响故障响应速度。

一、确保 rsyslog 服务正常运行

1. 检查服务状态

sudo systemctl status rsyslog

如何通过CentOS Syslog系统安全保障?

2. 未运行则启动并设置开机自启

sudo systemctl start rsyslog sudo systemctl enable rsyslog

1. 编辑主配置文件

sudo vi /etc/rsyslog.conf

确保以下行未被注释: $ModLoad imjournal # 读取 systemd journal $OmitLocalLogging on # 防止重复记录 $ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat

2. 按设施与级别分文件存储

/etc/rsyslog.d/00-local.conf

*.* -/var/log/messages
authpriv.* /var/log/secure
mail.* -/var/log/maillog
cron.* /var/log/cron
local0.* /var/log/local0.log
local1.* /var/log/local1.log
...

3. 重载配置使更改生效

1. 使用 tail -f 查看最新日志

sudo tail -f /var/log/secure # 安全相关日志

2. 配合 grep/egrep 快速过滤关键字

sudo egrep "Invalid user|Failed password" /var/log/secure # SSH暴力

3. 用 awk 输出摘要信息

痛点缓解通过组合 tail -f + grep/awk 能在秒级内看到异常,避免“事后才发现问题”的困扰。

/etc/logrotate.d/syslog 配置示例
/var/log/messages {
daily
rotate 7
compress
delaycompress
missingok
notifempty
create 640 root adm
sharedscripts
postrotate
systemctl kill -s HUP rsyslog.service>/dev/null 2>&1 || true
endscript
}
/var/log/secure {
daily
rotate 4
compress
delaycompress
missingok
notifempty
create 600 root root
}

效果每天自动压缩旧日志,保留最近若干天彻底避免磁盘被撑满导致服务不可用的风险。

/etc/rsyslog.d/remote.conf
*.* @192.168.10.50:514 # UDP 转发,可改为 @@ 开头使用 TCP
# 若需可靠传输:
*.* @@192.168.10.50:514;
RSYSLOG_SyslogProtocol23Format

痛点缓解不再需要逐台登录看日志,所有主机的统一视图让安全事件能够在全局范围内快速关联。

ELK Stack Logstash 收集 rsyslog 输出 → 写入 Elasticsearch → Kibana 提供仪表盘、字段分析。 Graylog 直接接受 syslog/UDP/TCP,内置流规则与告警插件。 Promeus + Grafana 适合已有监控程序的团队,把异常日币转为指标触发告警。 自建告警脚本 说到示例,每分钟检查 /var/log/secure 中是否出现 Failed password 超过 5 次若触发则发送邮件或 Webhook。从代码片段来看,

#!/bin/bash
THRESHOLD=5
COUNT=$
if;n
echo "SSH brute force detected " | mail -s "Security Alert"
fi

html

如何通过CentOS Syslog系统安全保障?

)

) ) ) ) ) ) ) ) ) )

标签:CentOS