Linux · System Logging (syslog & journald)

logwatch is meant to save you from reading raw logs, but on a freshly configured box its daily report never arrives. What does logwatch do, and what dependency silently blocks it?

Answer locked. Get the free KnowCard app to reveal it — plus spaced-repetition review so it actually sticks.

Get it on App StoreGet it on Google Play

This is one card from the KnowCard library — thousands more across SAP, Linux, Python and more. In the app you get the answer, AI explanations, and cards that come back right before you would forget them. Free to start on iOS, Android or the web.

More in System Logging (syslog & journald)

syslog groups messages by facility. Which facilities are reserved for admins to use freely, and why is authpriv treated more carefully than auth?
Apache, MySQL, CUPS, and Samba all write logs, yet none of them are affected when you edit the central syslog configuration. Why do they escape it, and where do their logs come from instead?
An rsyslogd rule looks like mail.err written before /var/log/mail.err. What are the two structural halves of every such rule, and what does each one decide?
Kernel messages land in a fixed 16 KiB RAM ring buffer. What happens to old kernel messages over time, and how does that structure make persistent kernel logs a separate concern?
Left alone, log files grow without bound. What sequence of actions does logrotate perform on a log, and how often is it triggered?
A security auditor complains that on a syslog-based host an intruder could quietly edit /var/log to erase their tracks. What does systemd's journal change about that, and what does it trade away to get it?

Start learning today

Free to start — download the app or use it in your browser.

Get it on App StoreGet it on Google Play