Syslog logging levels

Support for security such as Firewalls and securing linux
Post by Aed

Hi when configuring Syslog logging to a remote server or SIEM tool can we please review what logging levels are available and what details are captured at each level - this can be very useful to explain in the context of use cases?

For example if logs are collected at Warn(ing) or above will this capture multiple failed login attempts against accounts as failed logins are treated as an Info(rmational) message.

Is this missed for normal user accounts? Suppose it was multiple failed attempts to access root accounts or sudo privileges .. are these handled differently?

Re: Syslog logging levels

Post by Whoever

Code: Select all

man rsyslog.conf

