Content Fri Jul 30 06:44:48 2010 GMT. JEB: code, comment, creativity — Blog, SVN, Photos RSS Feed of recent pictures, Nagios, Server status, Smokeping

[Home] programs/ syslog-summary/

Ignoring useless Syslog messages

Three steps to knowing what's going on in Syslog in one easy daily email:

  1. Install syslog summary (apt-get install syslog-summary).
  2. Set up your ignore file (see suggestions below)
  3. Update your /etc/logrotate.d/syslog-ng or similar rotation script to call syslog summary and email you the results

JEB's list of messages to ignore

The key item here is what you want ot ignore

Here's a reasonable list to get started: syslog.ignore

Other syslog-summary tips

  1. Always test any changes manually before leaving for the day!
  2. Kernel messages now have a timestamp on them (see above example.
  3. Some of the kernel messages we only want to ignore during boot time: the pattern match for up to 2 digits of uptime in the above example will ignore link change notices for the first 99 seconds (kernel: (\[\s+\d{1,2}\.\d+\] )?)
James "JEB" Bromberger - james_AT_rcpt.to, replace '_AT_' with @ sign
UK cell: +44 7952 042920. Perth VoIP number: (08) 6424 8325
MSN: james_AT_rcpt.to, AIM: JamesEBromberger
Skype: james.bromberger

IPv6 Valid HTML 4.01 Strict Valid CSS! Powered by HTML, CSS, Template Toolkit, Perl, and Debian GNU/Linux!

Your IP is 38.107.191.86