1999-08-14 15:50:49 +00:00
|
|
|
# This is a sample syslog.conf fragment for use with Sudo.
|
|
|
|
#
|
2010-07-22 17:50:21 -04:00
|
|
|
# By default, sudo logs to "authpriv" if your system supports it, else it
|
|
|
|
# uses "auth". The facility can be set via the --with-logfac configure
|
|
|
|
# option or in the sudoers file.
|
|
|
|
# To see what syslog facility a sudo binary uses, run `sudo -V' as *root*.
|
1999-09-08 08:01:10 +00:00
|
|
|
#
|
|
|
|
# NOTES:
|
|
|
|
# The whitespace in the following line is made up of <TAB>
|
|
|
|
# characters, *not* spaces. You cannot just cut and paste!
|
|
|
|
#
|
|
|
|
# If you edit syslog.conf you need to send syslogd a HUP signal.
|
|
|
|
# Ie: kill -HUP process_id
|
|
|
|
#
|
|
|
|
# Syslogd will not create new log files for you, you must first
|
|
|
|
# create the file before syslogd will log to it. Eg.
|
2022-02-11 19:19:09 -07:00
|
|
|
# 'touch @log_dir@/sudo'
|
1999-08-14 15:50:49 +00:00
|
|
|
|
2022-02-11 19:19:09 -07:00
|
|
|
# This logs successful and failed sudo attempts to the file @log_dir@/auth
|
2010-07-22 17:50:21 -04:00
|
|
|
# If your system has the authpriv syslog facility, use authpriv.debug
|
2022-02-11 19:19:09 -07:00
|
|
|
auth.debug @log_dir@/auth
|
1999-08-14 15:50:49 +00:00
|
|
|
|
|
|
|
# To log to a remote machine, use something like the following,
|
|
|
|
# where "loghost" is the name of the remote machine.
|
2010-07-22 17:50:21 -04:00
|
|
|
# If your system has the authpriv syslog facility, use authpriv.debug
|
|
|
|
auth.debug @loghost
|