Hello, On Fri, Jul 29, 2022 at 04:30:19PM +1200, Richard Hector wrote: > My thought is to configure rsyslog to create extra logfiles, equivalent to > syslog and auth.log (the two files that logcheck monitors by default), which > only log messages at priority 'warning' or above, and configure logcheck to > monitor those instead. This should cut down the amount of filter maintenance > considerably. > > Does this sound like a reasonable idea?
Personally I wouldn't (and don't) do it. It sounds like a bunch of work only to end up with things that get logged anyway (as you noted) plus the risk of missing other interesting things. I don't find writing logcheck filters to be a particularly big time sink. But if you do then it might alter the balance for you. Cheers, Andy -- https://bitfolk.com/ -- No-nonsense VPS hosting