| 12
 3
 4
 5
 6
 7
 8
 9
 10
 11
 12
 13
 14
 15
 16
 17
 18
 19
 20
 21
 22
 23
 24
 25
 26
 27
 28
 29
 30
 31
 32
 33
 34
 35
 36
 37
 38
 39
 40
 41
 42
 43
 44
 45
 46
 47
 48
 49
 50
 51
 52
 53
 54
 55
 56
 57
 58
 59
 60
 61
 
 | #  /etc/rsyslog.conf    Configuration file for rsyslog.#
 #                       For more information see
 #                       /usr/share/doc/rsyslog-doc/html/rsyslog_conf.html
 #
 #  Default logging rules can be found in /etc/rsyslog.d/50-default.conf
 
 
 #################
 #### MODULES ####
 #################
 
 module(load="imuxsock") # provides support for local system logging
 module(load="imklog")   # provides kernel logging support
 #module(load="immark")  # provides --MARK-- message capability
 
 # provides UDP syslog reception
 module(load="imudp")
 input(type="imudp" port="514")
 
 # provides TCP syslog reception
 module(load="imtcp")
 input(type="imtcp" port="514")
 
 # Enable non-kernel facility klog messages
 $KLogPermitNonKernelFacility on
 
 ###########################
 #### GLOBAL DIRECTIVES ####
 ###########################
 
 #
 # Use traditional timestamp format.
 # To enable high precision timestamps, comment out the following line.
 #
 $ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat
 
 # Filter duplicated messages
 $RepeatedMsgReduction on
 
 #
 # Set the default permissions for all log files.
 #
 $FileOwner syslog
 $FileGroup adm
 $FileCreateMode 0640
 $DirCreateMode 0755
 $Umask 0022
 $PrivDropToUser syslog
 $PrivDropToGroup syslog
 
 #
 # Where to place spool and state files
 #
 $WorkDirectory /var/spool/rsyslog
 
 #
 # Include all config files in /etc/rsyslog.d/
 #
 $IncludeConfig /etc/rsyslog.d/*.conf
 local7.*        /var/log/cisco.log
 
 |