![](https://seccdn.libravatar.org/avatar/861b5545c111d2257fa12e533e723110.jpg?s=120&d=mm&r=g)
The 03.10.13 at 19:38, James Mohr wrote:
I am trying configure PAM logging on SuSE 8.0 and 8.2 systems. The biggest thing that bothers me is that I cannot figure out what facility and what priority is used for the messages.
It is difficult if not documented.
Everything is being written to /var/adm/messages, which is getting overloaded with junk. I would like to be able to define certain piorities (error ane above?) which get written then and all others are either discarded or written to a different log file.
Add an entry to syslog.conf like: facility.* /var/log/testing Where 'facility' is anyone of the available facilities. Restart syslog (rcsyslog restart) and see if there are pam entries there. No? redo for another facility. Otherwise, add multiple entries like: auth.* /var/log/facility.auth authpriv.* /var/log/facility.authpriv cron.* /var/log/facility.cron daemon.* /var/log/facility.daemon kern.* /var/log/facility.kern lpr.* /var/log/facility.lpr mail.* /var/log/facility.mail mark.* /var/log/facility.mark news.* /var/log/facility.news auth.* /var/log/facility.auth syslog.* /var/log/facility.syslog user.* /var/log/facility.user uucp.* /var/log/facility.uucp local0.* /var/log/facility.local0 local1.* /var/log/facility.local1 local2.* /var/log/facility.local2 local3.* /var/log/facility.local3 local4.* /var/log/facility.local4 local5.* /var/log/facility.local5 local6.* /var/log/facility.local6 local7.* /var/log/facility.local7 I have just added this to my syslog.conf, for possible future use ;-) -- Cheers, Carlos Robinson