syslog-ng通过systemd启动无法写入/var/log/messages问题求助
Hey there, let’s tackle this syslog-ng issue you’re facing—it’s a classic gap between how services run under systemd vs. a regular shell, so I’ve got a few targeted checks to get things working.
The core issue here is that systemd runs services in a constrained environment with different defaults compared to your interactive shell. When you start syslog-ng manually, it inherits your shell’s context and full access to system resources, but systemd adds sandboxing, environment variables, and default logging routing that can interfere with writes to /var/log/messages.
1. Fix your syslog-ng configuration to include the right sources and destinations
First, confirm your syslog-ng config is set up to send logs to /var/log/messages, especially if it’s pulling from the systemd journal (which is likely what’s happening when launched via systemd).
Open your main config file (typically /etc/syslog-ng/syslog-ng.conf) and verify these sections exist:
Add a destination for /var/log/messages
destination d_messages { file("/var/log/messages" perm(0644) owner(root) group(root) ); };
Add a log path that feeds sources into this destination
Make sure you’re capturing both traditional system logs and systemd journal logs (since systemd might be routing logs there by default):
# Define the systemd journal source if it's missing source s_journal { systemd-journal(); }; # Combine sources and send to messages log { source(s_system); # Default system source (e.g., /dev/log) source(s_journal); # Capture systemd journal entries destination(d_messages); flags(final); };
2. Check systemd service file for sandboxing restrictions
Systemd service files often include settings that block access to /var/log. Open your syslog-ng service file (check /lib/systemd/system/syslog-ng.service or /etc/systemd/system/syslog-ng.service) and look for these problematic lines:
PrivateTmp=true: This creates an isolated temporary filesystem for the service, so any writes to/var/log/messageswon’t show up in the real file. Change this toPrivateTmp=false.ProtectSystem=strict: This locks down system directories to read-only. If present, modify it toProtectSystem=fullor add an exception:ReadWritePaths=/var/log
After editing the service file, reload systemd and restart syslog-ng:
systemctl daemon-reload systemctl restart syslog-ng
3. Verify file permissions for /var/log/messages
Ensure the syslog-ng process (running under systemd) has write access to the messages file:
- Check which user syslog-ng runs as:
It’s usuallyps aux | grep syslog-ngrootorsyslog. - Check the messages file’s permissions:
ls -l /var/log/messages - If the file is owned by a group that doesn’t include the syslog-ng user, add the user to that group:
(Replaceusermod -aG <group-name> syslog<group-name>with the group from thelsoutput, e.g.,admorroot.)
4. Test your changes
Send a test log message and verify it appears in /var/log/messages:
logger "Test: syslog-ng systemd write check" tail -10 /var/log/messages
If it’s still not working, check the syslog-ng service status for errors:
systemctl status syslog-ng
You can also run syslog-ng in debug mode temporarily to see real-time issues:
systemctl stop syslog-ng /usr/sbin/syslog-ng -Fv
This will output detailed logs about missing sources, config errors, or permission blocks.
内容的提问来源于stack exchange,提问作者hteejus

