# Logging question

**URL:** <https://forums.suse.com/t/logging-question/30150>\
**Category:** SLES Configure-Administer\
**Created:** [August 9, 2017, 11:19pm UTC](https://forums.suse.com/t/logging-question/30150 "2017-08-09T23:19:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![cisaksen](https://avatars.discourse-cdn.com/v4/letter/c/49beb7/32.png) [@cisaksen](https://forums.suse.com/u/cisaksen)\
**Post date:** [August 9, 2017, 11:19pm UTC](https://forums.suse.com/t/logging-question/30150/1 "2017-08-09T23:19:41Z")

</div>

I’m discovering that syslog(-ng) has actually been replaced by systemd-journal, yet it still writes out log messages to /var/log/messages as syslog did for compatibility.

As we are starting to use splunk this will work for us. But I was wondering if SUSE is planning on changing this in the future ? They seem to like to change things without warning.

Another question I have: is it possible to modify or customize a log entries for logins so they are easily recognizable and perhaps add additional information like where a user logged in from (ip, hostname,etc…)

Thanks

---

<div class="post-metadata">

**Author:** ![Automatic\_Reply](https://avatars.discourse-cdn.com/v4/letter/a/ecb155/32.png) [@Automatic\_Reply](https://forums.suse.com/u/Automatic_Reply)\
**Post date:** [August 14, 2017, 7:30am UTC](https://forums.suse.com/t/logging-question/30150/2 "2017-08-14T07:30:28Z")

</div>

cisaksen,

It appears that in the past few days you have not received a response to your  
posting. That concerns us, and has triggered this automated reply.

These forums are peer-to-peer, best effort, volunteer run and that if your issue  
is urgent or not getting a response, you might try one of the following options:

- Visit [http://www.suse.com/support](http://www.suse.com/support) and search the knowledgebase and/or check all  
the other support options available.
- Open a service request: [https://www.suse.com/support](https://www.suse.com/support)
- You could also try posting your message again. Make sure it is posted in the  
correct newsgroup. ([http://forums.suse.com](http://forums.suse.com))

Be sure to read the forum FAQ about what to expect in the way of responses:  
[http://forums.suse.com/faq.php](http://forums.suse.com/faq.php)

If this is a reply to a duplicate posting or otherwise posted in error, please  
ignore and accept our apologies and rest assured we will issue a stern reprimand  
to our posting bot…

Good luck!

Your SUSE Forums Team  
[http://forums.suse.com](http://forums.suse.com)

---

<div class="post-metadata">

**Author:** ![smflood](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/smflood/32/10576_2.png) [@smflood](https://forums.suse.com/u/smflood)\
**Post date:** [August 17, 2017, 2:05pm UTC](https://forums.suse.com/t/logging-question/30150/3 "2017-08-17T14:05:42Z")

</div>

On 09/08/17 21:24, cisaksen wrote:  
[color=blue]

> I’m discovering that syslog(-ng) has actually been replaced by  
> systemd-journal, yet it still writes out log messages to  
> /var/log/messages as syslog did for compatibility.
> 
> As we are starting to use splunk this will work for us. But I was  
> wondering if SUSE is planning on changing this in the future ? They  
> seem to like to change things without warning.[/color]

I can’t give an official answer (you’d have to ask SUSE directly) but I  
wouldn’t expect them to change this without warning and certainly not  
within the same product release (i.e. SLES12). Instead if it was going  
to change with a future release it would probably start as a Technical  
Preview in a beta for that future release.  
[color=blue]

> Another question I have: is it possible to modify or customize a log  
> entries for logins so they are easily recognizable and perhaps add  
> additional information like where a user logged in from (ip,  
> hostname,etc…)[/color]

This I don’t know though I suspect given we’re talking about Linux it’s  
probably possible.

## HTH.

Simon  
SUSE Knowledge Partner

* * *

## If you find this post helpful and are logged into the web interface, please show your appreciation and click on the star below. Thanks.
