You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CentOS 7环境下基于rsyslog实现按日志中user变量动态生成日志文件的配置咨询

Absolutely feasible with rsyslog on CentOS 7—let's tweak your config to split logs by the user field as you need. Here's how to do it step by step:

1. Enable Automatic Directory Creation

First, ensure rsyslog automatically creates any required subdirectories for your dynamic log files. Add this line at the top of your rsyslog.conf:

$CreateDirs on

2. Create a Template to Extract the Username

We need to parse the user="..." value from your log messages. Rsyslog supports regex-based field extraction directly in templates. Add this template to capture the username:

$template ExtractUser, "%msg:R,ERE:1,FIELD:user=\"([^\"]+)\":--end%"

This regex targets the user="XXX" pattern in the log message and extracts the username (everything between the quotes) as a reusable field.

3. Define the Dynamic User-Specific File Template

Modify your existing DynamicFile template to include the extracted username. You can structure the path to include date, hostname, and user for better organization, or keep it simple as you requested. Here's an example:

$template DynamicUserFile, "/var/log/syslogclients/$YEAR-$MONTH-$DAY/%HOSTNAME%/%ExtractUser%.log"

Or if you prefer all user logs grouped directly under the date directory:

$template DynamicUserFile, "/var/log/syslogclients/$YEAR-$MONTH-$DAY/%ExtractUser%.log"

This template generates a unique file path for each user, hostname, and date combination.

4. Update Log Routing Rules

Replace your existing routing rule with one that uses the new dynamic template. You have two options depending on how you want to handle logs without a user field:

Option 1: Route all logs (logs without a user will default to --end.log)

*.* ?DynamicUserFile;ChangeFormatLog

Option 2: Filter only logs with a valid user field (cleaner approach)

Use a conditional to match logs containing the user="..." pattern, and route remaining logs to a default location:

# Route logs with user field to user-specific files
:msg, contains, "user=\"" ?DynamicUserFile;ChangeFormatLog

# Route logs without a user field to a default file
*.* /var/log/syslogclients/default.log;ChangeFormatLog

5. Set Up Permissions

Ensure the rsyslog process (usually running as rsyslog user) has write access to the base log directory:

mkdir -p /var/log/syslogclients
chown rsyslog:rsyslog /var/log/syslogclients

6. Test and Apply the Configuration

First, validate your config for syntax errors:

rsyslogd -N1

If no errors are reported, restart the rsyslog service to apply changes:

systemctl restart rsyslog

Note for 400+ Users

Rsyslog handles dynamic file creation efficiently even for hundreds of users—you won't hit limits here as long as your filesystem has enough space and inodes. The regex extraction is lightweight and won't cause significant performance overhead.

内容的提问来源于stack exchange,提问作者Aurélien BOURDOIS

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.28 11:23:15