Hello,

On Fri, Jul 29, 2022 at 04:30:19PM +1200, Richard Hector wrote:
> My thought is to configure rsyslog to create extra logfiles, equivalent to
> syslog and auth.log (the two files that logcheck monitors by default), which
> only log messages at priority 'warning' or above, and configure logcheck to
> monitor those instead. This should cut down the amount of filter maintenance
> considerably.
> 
> Does this sound like a reasonable idea?

Personally I wouldn't (and don't) do it. It sounds like a bunch of
work only to end up with things that get logged anyway (as you
noted) plus the risk of missing other interesting things.

I don't find writing logcheck filters to be a particularly big time
sink. But if you do then it might alter the balance for you.

Cheers,
Andy

-- 
https://bitfolk.com/ -- No-nonsense VPS hosting

Reply via email to