如何通过CentOS Syslog高效监控系统状态,实现系统安全保障?
- 内容介绍
- 文章标签
- 相关推荐
为什么 CentOS Syslog 监控常让运维头疼?
日志分散在多个文件中,难以快速定位关键错误;日志文件随时间膨胀,磁盘易被占满导致服务异常;怎么说呢,缺乏实时告警机制。问题往往在事后才被发现;手工过滤日志费时费力,影响故障响应速度。
一、确保 rsyslog 服务正常运行
1. 检查服务状态
sudo systemctl status rsyslog
2. 未运行则启动并设置开机自启
sudo systemctl start rsyslog
sudo systemctl enable rsyslog
1. 编辑主配置文件
sudo vi /etc/rsyslog.conf
确保以下行未被注释:
$ModLoad imjournal # 读取 systemd journal
$OmitLocalLogging on # 防止重复记录
$ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat
2. 按设施与级别分文件存储
/etc/rsyslog.d/00-local.conf
*.* -/var/log/messages authpriv.* /var/log/secure mail.* -/var/log/maillog cron.* /var/log/cron local0.* /var/log/local0.log local1.* /var/log/local1.log ...
3. 重载配置使更改生效
1. 使用 tail -f 查看最新日志
sudo tail -f /var/log/secure # 安全相关日志
2. 配合 grep/egrep 快速过滤关键字
sudo egrep "Invalid user|Failed password" /var/log/secure # SSH暴力
3. 用 awk 输出摘要信息
痛点缓解通过组合 tail -f + grep/awk 能在秒级内看到异常,避免“事后才发现问题”的困扰。
/etc/logrotate.d/syslog 配置示例
/var/log/messages {
daily
rotate 7
compress
delaycompress
missingok
notifempty
create 640 root adm
sharedscripts
postrotate
systemctl kill -s HUP rsyslog.service>/dev/null 2>&1 || true
endscript
}
/var/log/secure {
daily
rotate 4
compress
delaycompress
missingok
notifempty
create 600 root root
}
效果每天自动压缩旧日志,保留最近若干天彻底避免磁盘被撑满导致服务不可用的风险。
/etc/rsyslog.d/remote.conf
*.* @192.168.10.50:514 # UDP 转发,可改为 @@ 开头使用 TCP # 若需可靠传输: *.* @@192.168.10.50:514; RSYSLOG_SyslogProtocol23Format
痛点缓解不再需要逐台登录看日志,所有主机的统一视图让安全事件能够在全局范围内快速关联。
-
ELK Stack
-
Logstash 收集 rsyslog 输出 → 写入 Elasticsearch → Kibana 提供仪表盘、字段分析。
-
Graylog
-
直接接受 syslog/UDP/TCP,内置流规则与告警插件。
-
Promeus + Grafana
-
适合已有监控程序的团队,把异常日币转为指标触发告警。
-
自建告警脚本
-
说到示例,每分钟检查
/var/log/secure 中是否出现 Failed password 超过 5 次若触发则发送邮件或 Webhook。从代码片段来看,
#!/bin/bash
THRESHOLD=5
COUNT=$
if;n
echo "SSH brute force detected " | mail -s "Security Alert"
fi
html
)
) ) ) ) ) ) ) ) ) )
为什么 CentOS Syslog 监控常让运维头疼?
日志分散在多个文件中,难以快速定位关键错误;日志文件随时间膨胀,磁盘易被占满导致服务异常;怎么说呢,缺乏实时告警机制。问题往往在事后才被发现;手工过滤日志费时费力,影响故障响应速度。
一、确保 rsyslog 服务正常运行
1. 检查服务状态
sudo systemctl status rsyslog
2. 未运行则启动并设置开机自启
sudo systemctl start rsyslog
sudo systemctl enable rsyslog
1. 编辑主配置文件
sudo vi /etc/rsyslog.conf
确保以下行未被注释:
$ModLoad imjournal # 读取 systemd journal
$OmitLocalLogging on # 防止重复记录
$ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat
2. 按设施与级别分文件存储
/etc/rsyslog.d/00-local.conf
*.* -/var/log/messages authpriv.* /var/log/secure mail.* -/var/log/maillog cron.* /var/log/cron local0.* /var/log/local0.log local1.* /var/log/local1.log ...
3. 重载配置使更改生效
1. 使用 tail -f 查看最新日志
sudo tail -f /var/log/secure # 安全相关日志
2. 配合 grep/egrep 快速过滤关键字
sudo egrep "Invalid user|Failed password" /var/log/secure # SSH暴力
3. 用 awk 输出摘要信息
痛点缓解通过组合 tail -f + grep/awk 能在秒级内看到异常,避免“事后才发现问题”的困扰。
/etc/logrotate.d/syslog 配置示例
/var/log/messages {
daily
rotate 7
compress
delaycompress
missingok
notifempty
create 640 root adm
sharedscripts
postrotate
systemctl kill -s HUP rsyslog.service>/dev/null 2>&1 || true
endscript
}
/var/log/secure {
daily
rotate 4
compress
delaycompress
missingok
notifempty
create 600 root root
}
效果每天自动压缩旧日志,保留最近若干天彻底避免磁盘被撑满导致服务不可用的风险。
/etc/rsyslog.d/remote.conf
*.* @192.168.10.50:514 # UDP 转发,可改为 @@ 开头使用 TCP # 若需可靠传输: *.* @@192.168.10.50:514; RSYSLOG_SyslogProtocol23Format
痛点缓解不再需要逐台登录看日志,所有主机的统一视图让安全事件能够在全局范围内快速关联。
-
ELK Stack
-
Logstash 收集 rsyslog 输出 → 写入 Elasticsearch → Kibana 提供仪表盘、字段分析。
-
Graylog
-
直接接受 syslog/UDP/TCP,内置流规则与告警插件。
-
Promeus + Grafana
-
适合已有监控程序的团队,把异常日币转为指标触发告警。
-
自建告警脚本
-
说到示例,每分钟检查
/var/log/secure 中是否出现 Failed password 超过 5 次若触发则发送邮件或 Webhook。从代码片段来看,
#!/bin/bash
THRESHOLD=5
COUNT=$
if;n
echo "SSH brute force detected " | mail -s "Security Alert"
fi
html
)
) ) ) ) ) ) ) ) ) )

