26.9.2 Configuring System Logging

Verify that the system logging service rsyslog is running:

# systemctl status rsyslog
rsyslogd (pid  1632) is running...

If the service is not running, start it and enable it to start when the system is rebooted:

# systemctl start rsyslog
# systemctl enable rsyslog

Ensure that each log file referenced in /etc/rsyslog.conf exists and is owned and only readable by root:

# touch logfile
# chown root:root logfile
# chmod 0600 logfile

It is also recommended that you use a central log server and that you configure Logwatch on that server. See Section 26.7, “About System Logging”.