Installing Logwatch is very straight forward and it’s definitly worth taking a few minutes to do it. The format that it can send your system logs to you in is so nice and easy to read you’ll wonder how you ever kept track of your server without it.
I like logs to be mailed to me every morning. These are the steps you need to take to get a similar report:
- Firstly run the following command to install Logwatch. I’m assuming you already have postfix and sendmail installed.
apt-get install logwatch
- The config file you need to edit is located at:
- I’d suggest replacing the following entries as follows:
Output = mail
Format = html
MailTo = firstname.lastname@example.org
MailFrom = email@example.com
Archives = No
Range = yesterday
Detail = Med
- Test your logwatch configuration by running logwatch on the command line.
- Create a new cron job to run this at 5:45AM every day. This is the time I generally get reports sent out. Backup jobs, Windows and Linux security and Logwatch reports are sent out during 5:30AM and 6AM so that things are spaced out.
45 5 * * * /usr/sbin/logwatch
That’s all there is too it.
Update on 27th January 2012
Logwatch in some versions of Debian is slightly broken if you choose to format messages using HTML. To get around this you will need to download the package from source and install it. The instructions to do this are outlined below.
- Create a temporary directory to save the files to:
- Download the package from sourceforge by using the following command.
- Unpack the archive that you downloaded in step 2.
tar xzvf logwatch*
- cd to this directory.
[tab] means that if you press the tab key on your keyboard the name of the directory / file will be automatically completed for you. When using the console this saves a lot of time.
- Make the install file executable.
chmod 777 install[tab]
- Run the install script.
- Answer all questions with the defaults by pressing the enter key.
- The config is now to be created in /etc/logwatch/logwatch.conf
- Use the lines above to specify what you want to configure.
alternatively, run the following command replacing it with your own Email address of course. This runs logwatch and does not read from a configuration file.
logwatch –output mail –format html –mailto joe.bloggs@MadeUpCompany.com –archives no –range Yesterday –debug Med