| OpenSSH server |
Remote logins, brute force, stolen keys |
Syslog by default. Identifier sshd before OpenSSH 9.8 (Debian 12: 9.2, Ubuntu 22.04: 8.9, Ubuntu 24.04: 9.6). From 9.8 the per-connection process logs as sshd-session (Debian 13: 10.0, Ubuntu 25.10: 10.0, CentOS Stream 10 and current CentOS Stream 9: 9.9). Login lines come from that process: Accepted <method> for <user> from <ip> port <n> ssh2 and Failed <method> for ... (auth.c); pre-login lines end with [preauth] (monitor.c). |
Yes |
log.syslogIdentifier is one of sshd, sshd-session; text Failed password or Accepted |
High |
| sudo and su |
Privilege use, failed sudo, unexpected root shells |
Both log to syslog by default. sudo logs successes and failures (log_allowed and log_denied are on by default) with identifier sudo; failures read N incorrect password attempts, user NOT in sudoers, command not allowed. su logs with identifier su (runuser for runuser). |
Yes |
log.syslogIdentifier is one of sudo, su; text incorrect password or NOT in sudoers |
High |
| Nginx |
Web attacks, blocked requests, password-protected pages |
Files by default. Add to the http block (Nginx allows several error_log and access_log lines, so the files can stay): error_log syslog:server=unix:/dev/log,nohostname; and access_log syslog:server=unix:/dev/log,nohostname,tag=nginx_access combined;. nohostname is required (section 0.5). The default tag is nginx; a tag may use only letters, digits and underscore, 32 at most (ngx_syslog.c). |
Yes, after a setting on the app |
log.syslogIdentifier is one of nginx, nginx_access |
High |
| Apache httpd |
Web attacks, errors, password-protected pages |
Files by default. Error log: ErrorLog syslog:local7:httpd (the tag syntax exists since 2.4.28; without it the tag is the binary name, apache2 on Debian and Ubuntu, httpd on RHEL). Set it in the main config and in every <VirtualHost> that has its own ErrorLog; Debian's default site does. Access log (Apache has no syslog option for it): CustomLog "|/usr/bin/logger -t httpd_access -p local6.info --size 4096" combined. util-linux logger writes the header journald expects; its default size limit is 1 KiB. |
Yes, after a setting on the app |
log.syslogIdentifier is one of httpd, httpd_access |
High |
| MySQL 8.0 and 8.4 |
Database logins and failed access |
Files by default (Ubuntu log_error = /var/log/mysql/error.log; RHEL family log-error=/var/log/mysql/mysqld.log; Debian ships MariaDB instead). In [mysqld]: log_error_services = 'log_filter_internal; log_sink_syseventlog' (add log_sink_internal to keep the file too; before 8.0.30 run INSTALL COMPONENT 'file://component_log_sink_syseventlog'; first) and log_error_verbosity = 3, because Access denied for user ... is only logged at verbosity 3 (the default is 2). |
Yes, after a setting on the app |
log.syslogIdentifier is mysqld; text Access denied |
High |
| MariaDB 10.11 and 11.x |
Database logins and failed access |
Error log: Debian and Ubuntu leave log_error unset, so errors already reach the journal through stderr (identifier mariadbd); the RHEL family sets log-error=/var/log/mariadb/mariadb.log, so delete that line. log_warnings defaults to 2, which logs Access denied for user .... For connections and admin statements add the audit plugin: plugin_load_add = server_audit, server_audit_logging = ON, server_audit_output_type = SYSLOG, server_audit_events = CONNECT,QUERY_DDL,QUERY_DCL (identifier mysql-server_auditing; failed logins show as FAILED_CONNECT). |
Debian and Ubuntu error log: Yes. RHEL, and the audit plugin anywhere: Yes, after a setting on the app |
log.syslogIdentifier is one of mariadbd, mysql-server_auditing; text Access denied or FAILED_CONNECT |
High |
| PostgreSQL |
Database logins and failed passwords |
Files by default: Debian and Ubuntu start it with pg_ctl -l (files under /var/log/postgresql/), the RHEL family turns on logging_collector. In postgresql.conf: log_destination = 'syslog', log_connections = on, log_disconnections = on. Failed passwords are logged by default: FATAL: password authentication failed for user "alice". Long messages are split at 1024 bytes (syslog_split_messages). |
Yes, after a setting on the app |
log.syslogIdentifier is postgres; text password authentication failed |
High |
| OpenVPN (community server) |
VPN logins and failed connections |
Journal by default: the upstream openvpn-server@.service starts OpenVPN without a log option (the sample server.conf leaves ;log openvpn.log commented out), so its output goes to the journal under the process name openvpn (Debian's older openvpn@NAME unit uses --daemon ovpn-NAME, which logs to syslog as ovpn-NAME). Remove any log or log-append line that was added. verb 3, the sample default, logs connections and TLS errors such as TLS Error: TLS handshake failed and TLS Auth Error: Auth Username/Password verification failed for peer. |
Yes (unless log or log-append is set) |
log.syslogIdentifier is openvpn (or ovpn-<name>); text TLS Error or verification failed |
High |
| Samba file shares |
Who opened, changed or deleted files on Linux shares |
Add the audit module to each share or to [global]: vfs objects = full_audit, full_audit:success = connect disconnect openat renameat unlinkat mkdirat, full_audit:failure = connect, full_audit:prefix = %u|%I|%S. It logs to syslog by default (full_audit:syslog = yes, facility USER, priority NOTICE) under the name smbd_audit. Nothing is logged until success or failure lists operations (source3/modules/vfs_full_audit.c), and openat on a busy share is very chatty. The module calls syslog itself, so Debian's logging = file does not stop it. For domain-controller logins add log level = 1 auth_audit:3 and logging = syslog@3 file (identifier samba or smbd; failures are level 2, so syslog@1 would drop them). |
Yes, after a setting on the app |
log.syslogIdentifier is one of smbd_audit, samba, smbd |
High |
| Proxmox VE |
Hypervisor web and API logins, including failures |
Journal by default. Failed logins to the web interface and API are logged by pvedaemon as authentication failure; rhost=<ip> user=<user> msg=... (the official Proxmox fail2ban recipe matches exactly this in the journal); successes read successful auth for user '<user>', and tasks starting task UPID:.... Proxmox Backup Server logs password failures under proxmox-backup-api and bad tickets under proxmox-backup-proxy (read from source, not seen on a host). Install the Linux agent on each node. |
Yes |
log.syslogIdentifier is pvedaemon; text authentication failure |
High |
| Local account changes (useradd, usermod, userdel, groupadd, passwd) |
New or changed local accounts, password changes |
The shadow tools log to syslog under their own names: new user: name=... (useradd), change user ... (usermod), delete user ... (userdel), new group: ... (groupadd), password for 'x' changed by 'y' (passwd). Debian's adduser calls useradd. |
Yes |
log.syslogIdentifier is one of useradd, usermod, userdel, groupadd, passwd |
Medium |
| Postfix |
Mail relay abuse, SASL login failures, rejected mail |
Syslog by default on Debian, Ubuntu and RHEL (maillog_file is empty; Postfix 3.4 and later can log to a file instead, so leave it empty). Each program logs as postfix/<program>, for example postfix/smtpd or postfix/qmgr (a syslog_name override in master.cf gives names such as postfix/submission/smtpd). Connections and rejects (NOQUEUE: reject: ...) are logged by default; with SASL on, failures read warning: host[ip]: SASL LOGIN authentication failed: <reason>, sasl_username=<name>. |
Yes |
log.syslogIdentifier contains postfix/; text authentication failed or NOQUEUE: reject |
Medium |
| HAProxy |
Load balancer requests and errors |
Debian and Ubuntu: nothing to change; the shipped config has log /dev/log local0 and the service binds /dev/log into its chroot. RHEL family: the shipped log 127.0.0.1 local2 goes to a UDP port nothing listens on by default; replace it with log stdout format short daemon (HAProxy's documented systemd mode). option httplog is in both default configs; add no option dontlognull on internet-facing frontends, or scans are not logged. |
Debian and Ubuntu: Yes. RHEL: Yes, after a setting on the app |
log.syslogIdentifier is haproxy |
Medium |
| Host firewalls: UFW (Ubuntu) and firewalld (RHEL family) |
Blocked connections to the host |
Both log through the kernel. UFW: lines with prefix [UFW BLOCK] (also [UFW ALLOW], [UFW AUDIT], [UFW LIMIT BLOCK]); the shipped /etc/ufw/ufw.conf has LOGLEVEL=low, so blocks are logged as soon as UFW is enabled (ufw logging on turns it back on if someone set it off). firewalld: denied packets are not logged by default (LogDenied=off); firewall-cmd --set-log-denied=all makes the kernel log them with prefixes such as filter_IN_public_REJECT: or filter_IN_public_DROP: (zone name in the middle), FINAL_REJECT: and STATE_INVALID_DROP: (nftables backend, the default). |
UFW: Yes (when enabled). firewalld: Yes, after a setting on the host |
log.syslogIdentifier is kernel; text UFW BLOCK, or _REJECT: and _DROP: for firewalld |
Medium |
| Docker containers |
Output of the applications that run in containers |
Container output goes to json-file by default; the daemon's own logs already reach the journal (identifier dockerd). In /etc/docker/daemon.json: {"log-driver": "journald", "log-opts": {"tag": "{{.Name}}"}}, then restart Docker; only containers created afterwards use it. With that tag the identifier is the container name (otherwise the first 12 characters of the container ID); the name is also in log.CONTAINERNAME (underscores are stripped, section 0.5). |
Yes, after a setting on the host |
log.syslogIdentifier is <container name>, or log.CONTAINERNAME is <container name> |
Medium |
| Squid proxy |
Web access through the proxy; denied requests |
Debian and Ubuntu run squid --foreground -sYC, so important cache.log messages already reach the journal; RHEL family: set SQUID_OPTS="-s" in /etc/sysconfig/squid. Access log: access_log syslog:local4.info logformat=squid. Denied requests carry TCP_DENIED. One journal entry per request, so a busy proxy can hit the journald limit (raise LogRateLimitBurst= for the unit). |
Yes, after a setting on the app |
log.syslogIdentifier is squid; text TCP_DENIED |
Medium |
| BIND 9 (DNS server) |
Refused queries and zone transfers; optional query log |
Syslog by default through default_syslog, identifier named. The security category logs denied queries and zone transfers by default (query (cache) '<name>/<type>/<class>' denied, zone transfer '<zone>/AXFR/IN' denied). Query log: rndc querylog on, or logging { channel q { syslog daemon; severity info; }; category queries { q; }; }; (high volume). |
Yes (query log after a setting on the app) |
log.syslogIdentifier is named; text denied |
Medium |
| Dovecot (IMAP and POP3) |
Mailbox logins and password guessing |
Syslog by default (log_path = syslog, facility mail) in the Dovecot 2.3 and 2.4 packages. Identifier dovecot; each message starts with the process, for example imap-login:. Failed logins are logged at info by default: 2.3 Disconnected: ... (auth failed, 1 attempts in 2 secs): user=<bob>, method=PLAIN, rip=<ip>, 2.4 Login aborted: ... (auth_failed): user=<bob>. auth_verbose = yes adds the reason; keep auth_verbose_passwords = no. |
Yes |
log.syslogIdentifier is dovecot; text auth failed or auth_failed |
Medium |
| fail2ban |
Which addresses were banned, and when |
Its own file by default (logtarget = /var/log/fail2ban.log on Debian, Ubuntu and EPEL). In /etc/fail2ban/fail2ban.local, section [DEFAULT]: logtarget = SYSTEMD-JOURNAL (needs python3-systemd); the identifier is then fail2ban. Lines: [sshd] Found <ip>, [sshd] Ban <ip>, [sshd] Unban <ip>. |
Yes, after a setting on the app |
log.syslogIdentifier is fail2ban; text Ban |
Medium |
| FreeRADIUS |
Wi-Fi (802.1X) and VPN logins through RADIUS |
Files by default (destination = files, auth = no in the log {} section of radiusd.conf). Change to destination = syslog, syslog_facility = daemon, auth = yes; keep auth_badpass = no and auth_goodpass = no, which would log passwords. Identifier radiusd on Debian and RHEL. Failures: Login incorrect (<reason>): [<user>] (from client <name> port <n> cli <station>); successes Login OK. |
Yes, after a setting on the app |
log.syslogIdentifier is radiusd; text Login incorrect |
Medium |
| MongoDB 7 and 8 |
Database logins |
Files by default (destination: file). In mongod.conf: systemLog: with destination: syslog, and remove path. Versions 7 and 8 log "msg":"Failed to authenticate" by default. Output is JSON, and long lines can pass 4 KB and arrive with an empty log.message (section 0.5). |
Yes, after a setting on the app |
log.syslogIdentifier is mongod; text Failed to authenticate |
Medium |
| osquery |
Scheduled host queries (processes, users, packages, listening ports) |
Files by default (/var/log/osquery/). Add --logger_plugin=filesystem,syslog in the flags file; identifier osqueryd. Results are JSON; a large result can pass 4 KB and arrive with an empty log.message (section 0.5). Installed from osquery's own packages (not in Debian or Fedora). |
Yes, after a setting on the app |
log.syslogIdentifier is osqueryd |
Medium |
| OpenLDAP (slapd) |
Directory logins and failed binds |
Syslog (facility LOCAL4) under slapd, but Debian and Ubuntu ship olcLogLevel: none, so no connection or bind lines are logged. Set olcLogLevel: stats on cn=config with ldapmodify. Failed binds end with RESULT tag=97 err=49 (invalid credentials). |
Yes, after a setting on the app |
log.syslogIdentifier is slapd; text err=49 |
Medium |
| Redis and Valkey |
Weak source: failed logins are never logged |
Files by default. syslog-enabled yes (identifier redis or valkey, from syslog-ident). Failed AUTH attempts go only to the in-memory ACL LOG; the default level still logs Possible SECURITY ATTACK detected for cross-protocol attacks. |
Yes, after a setting on the app (little security value) |
log.syslogIdentifier is one of redis, valkey |
Low |
| Traefik and Caddy |
Reverse proxy access logs |
Both write to stdout or stderr, which systemd sends to the journal (identifier traefik or caddy, the process name). Access logs are opt-in: Traefik --accesslog=true with --accesslog.format=json (leave filePath unset); Caddy a log directive inside the site block. Output is JSON. |
Yes (access logs after a setting on the app) |
log.syslogIdentifier is one of traefik, caddy |
Low |
Part of: #2731 · Needs first: #2732 (where the entries live, the shared guide templates and the "View logs" link)
Section numbers in the tables (for example "section 0.4" or "4(c)(7)") point to the research notes. The sections this list relies on are at the bottom of this issue; the others are in #2732.
Why
The Linux agent already streams the whole system journal. Any service that logs to the journal or to syslog on the host is collected today; services that write only files need one setting, given per row below. Each needs a card and a guide.
Checklist, most valuable first
logorlog-appendis set)The list in detail
Rules for every row (section 0.5):
/var/log/audit/audit.log, nothing else. A program that writes only files needs the setting shown in its row. "syslog" below means the local/dev/logsocket, which journald owns on systemd distributions, so no rsyslog change is needed.log.syslogIdentifierstays empty (Nginxnohostname).log.message, and journald drops a service's messages above 10,000 in 30 seconds (the limit scales with free disk space). Busy access logs can hit that limit; send errors only, or raiseRateLimitBurstinjournald.conf.dataTypeislinux. The column shows the rest.sshdbefore OpenSSH 9.8 (Debian 12: 9.2, Ubuntu 22.04: 8.9, Ubuntu 24.04: 9.6). From 9.8 the per-connection process logs assshd-session(Debian 13: 10.0, Ubuntu 25.10: 10.0, CentOS Stream 10 and current CentOS Stream 9: 9.9). Login lines come from that process:Accepted <method> for <user> from <ip> port <n> ssh2andFailed <method> for ...(auth.c); pre-login lines end with[preauth](monitor.c).log.syslogIdentifieris one ofsshd, sshd-session; textFailed passwordorAcceptedlog_allowedandlog_deniedare on by default) with identifiersudo; failures readN incorrect password attempts,user NOT in sudoers,command not allowed. su logs with identifiersu(runuserfor runuser).log.syslogIdentifieris one ofsudo, su; textincorrect passwordorNOT in sudoershttpblock (Nginx allows severalerror_logandaccess_loglines, so the files can stay):error_log syslog:server=unix:/dev/log,nohostname;andaccess_log syslog:server=unix:/dev/log,nohostname,tag=nginx_access combined;.nohostnameis required (section 0.5). The default tag isnginx; a tag may use only letters, digits and underscore, 32 at most (ngx_syslog.c).log.syslogIdentifieris one ofnginx, nginx_accessErrorLog syslog:local7:httpd(the tag syntax exists since 2.4.28; without it the tag is the binary name,apache2on Debian and Ubuntu,httpdon RHEL). Set it in the main config and in every<VirtualHost>that has its ownErrorLog; Debian's default site does. Access log (Apache has no syslog option for it):CustomLog "|/usr/bin/logger -t httpd_access -p local6.info --size 4096" combined. util-linuxloggerwrites the header journald expects; its default size limit is 1 KiB.log.syslogIdentifieris one ofhttpd, httpd_accesslog_error = /var/log/mysql/error.log; RHEL familylog-error=/var/log/mysql/mysqld.log; Debian ships MariaDB instead). In[mysqld]:log_error_services = 'log_filter_internal; log_sink_syseventlog'(addlog_sink_internalto keep the file too; before 8.0.30 runINSTALL COMPONENT 'file://component_log_sink_syseventlog';first) andlog_error_verbosity = 3, becauseAccess denied for user ...is only logged at verbosity 3 (the default is 2).log.syslogIdentifierismysqld; textAccess deniedlog_errorunset, so errors already reach the journal through stderr (identifiermariadbd); the RHEL family setslog-error=/var/log/mariadb/mariadb.log, so delete that line.log_warningsdefaults to 2, which logsAccess denied for user .... For connections and admin statements add the audit plugin:plugin_load_add = server_audit,server_audit_logging = ON,server_audit_output_type = SYSLOG,server_audit_events = CONNECT,QUERY_DDL,QUERY_DCL(identifiermysql-server_auditing; failed logins show asFAILED_CONNECT).log.syslogIdentifieris one ofmariadbd, mysql-server_auditing; textAccess deniedorFAILED_CONNECTpg_ctl -l(files under/var/log/postgresql/), the RHEL family turns onlogging_collector. Inpostgresql.conf:log_destination = 'syslog',log_connections = on,log_disconnections = on. Failed passwords are logged by default:FATAL: password authentication failed for user "alice". Long messages are split at 1024 bytes (syslog_split_messages).log.syslogIdentifierispostgres; textpassword authentication failedopenvpn-server@.servicestarts OpenVPN without alogoption (the sampleserver.confleaves;log openvpn.logcommented out), so its output goes to the journal under the process nameopenvpn(Debian's olderopenvpn@NAMEunit uses--daemon ovpn-NAME, which logs to syslog asovpn-NAME). Remove anylogorlog-appendline that was added.verb 3, the sample default, logs connections and TLS errors such asTLS Error: TLS handshake failedandTLS Auth Error: Auth Username/Password verification failed for peer.logorlog-appendis set)log.syslogIdentifierisopenvpn(orovpn-<name>); textTLS Errororverification failed[global]:vfs objects = full_audit,full_audit:success = connect disconnect openat renameat unlinkat mkdirat,full_audit:failure = connect,full_audit:prefix = %u|%I|%S. It logs to syslog by default (full_audit:syslog = yes, facility USER, priority NOTICE) under the namesmbd_audit. Nothing is logged untilsuccessorfailurelists operations (source3/modules/vfs_full_audit.c), andopenaton a busy share is very chatty. The module calls syslog itself, so Debian'slogging = filedoes not stop it. For domain-controller logins addlog level = 1 auth_audit:3andlogging = syslog@3 file(identifiersambaorsmbd; failures are level 2, sosyslog@1would drop them).log.syslogIdentifieris one ofsmbd_audit, samba, smbdpvedaemonasauthentication failure; rhost=<ip> user=<user> msg=...(the official Proxmox fail2ban recipe matches exactly this in the journal); successes readsuccessful auth for user '<user>', and tasksstarting task UPID:.... Proxmox Backup Server logs password failures underproxmox-backup-apiand bad tickets underproxmox-backup-proxy(read from source, not seen on a host). Install the Linux agent on each node.log.syslogIdentifierispvedaemon; textauthentication failurenew user: name=...(useradd),change user ...(usermod),delete user ...(userdel),new group: ...(groupadd),password for 'x' changed by 'y'(passwd). Debian'saddusercallsuseradd.log.syslogIdentifieris one ofuseradd, usermod, userdel, groupadd, passwdmaillog_fileis empty; Postfix 3.4 and later can log to a file instead, so leave it empty). Each program logs aspostfix/<program>, for examplepostfix/smtpdorpostfix/qmgr(asyslog_nameoverride inmaster.cfgives names such aspostfix/submission/smtpd). Connections and rejects (NOQUEUE: reject: ...) are logged by default; with SASL on, failures readwarning: host[ip]: SASL LOGIN authentication failed: <reason>, sasl_username=<name>.log.syslogIdentifiercontainspostfix/; textauthentication failedorNOQUEUE: rejectlog /dev/log local0and the service binds/dev/loginto its chroot. RHEL family: the shippedlog 127.0.0.1 local2goes to a UDP port nothing listens on by default; replace it withlog stdout format short daemon(HAProxy's documented systemd mode).option httplogis in both default configs; addno option dontlognullon internet-facing frontends, or scans are not logged.log.syslogIdentifierishaproxy[UFW BLOCK](also[UFW ALLOW],[UFW AUDIT],[UFW LIMIT BLOCK]); the shipped/etc/ufw/ufw.confhasLOGLEVEL=low, so blocks are logged as soon as UFW is enabled (ufw logging onturns it back on if someone set it off). firewalld: denied packets are not logged by default (LogDenied=off);firewall-cmd --set-log-denied=allmakes the kernel log them with prefixes such asfilter_IN_public_REJECT:orfilter_IN_public_DROP:(zone name in the middle),FINAL_REJECT:andSTATE_INVALID_DROP:(nftables backend, the default).log.syslogIdentifieriskernel; textUFW BLOCK, or_REJECT:and_DROP:for firewallddockerd). In/etc/docker/daemon.json:{"log-driver": "journald", "log-opts": {"tag": "{{.Name}}"}}, then restart Docker; only containers created afterwards use it. With that tag the identifier is the container name (otherwise the first 12 characters of the container ID); the name is also inlog.CONTAINERNAME(underscores are stripped, section 0.5).log.syslogIdentifieris<container name>, orlog.CONTAINERNAMEis<container name>squid --foreground -sYC, so important cache.log messages already reach the journal; RHEL family: setSQUID_OPTS="-s"in/etc/sysconfig/squid. Access log:access_log syslog:local4.info logformat=squid. Denied requests carryTCP_DENIED. One journal entry per request, so a busy proxy can hit the journald limit (raiseLogRateLimitBurst=for the unit).log.syslogIdentifierissquid; textTCP_DENIEDdefault_syslog, identifiernamed. Thesecuritycategory logs denied queries and zone transfers by default (query (cache) '<name>/<type>/<class>' denied,zone transfer '<zone>/AXFR/IN' denied). Query log:rndc querylog on, orlogging { channel q { syslog daemon; severity info; }; category queries { q; }; };(high volume).log.syslogIdentifierisnamed; textdeniedlog_path = syslog, facility mail) in the Dovecot 2.3 and 2.4 packages. Identifierdovecot; each message starts with the process, for exampleimap-login:. Failed logins are logged at info by default: 2.3Disconnected: ... (auth failed, 1 attempts in 2 secs): user=<bob>, method=PLAIN, rip=<ip>, 2.4Login aborted: ... (auth_failed): user=<bob>.auth_verbose = yesadds the reason; keepauth_verbose_passwords = no.log.syslogIdentifierisdovecot; textauth failedorauth_failedlogtarget = /var/log/fail2ban.logon Debian, Ubuntu and EPEL). In/etc/fail2ban/fail2ban.local, section[DEFAULT]:logtarget = SYSTEMD-JOURNAL(needs python3-systemd); the identifier is thenfail2ban. Lines:[sshd] Found <ip>,[sshd] Ban <ip>,[sshd] Unban <ip>.log.syslogIdentifierisfail2ban; textBandestination = files,auth = noin thelog {}section ofradiusd.conf). Change todestination = syslog,syslog_facility = daemon,auth = yes; keepauth_badpass = noandauth_goodpass = no, which would log passwords. Identifierradiusdon Debian and RHEL. Failures:Login incorrect (<reason>): [<user>] (from client <name> port <n> cli <station>); successesLogin OK.log.syslogIdentifierisradiusd; textLogin incorrectdestination: file). Inmongod.conf:systemLog:withdestination: syslog, and removepath. Versions 7 and 8 log"msg":"Failed to authenticate"by default. Output is JSON, and long lines can pass 4 KB and arrive with an emptylog.message(section 0.5).log.syslogIdentifierismongod; textFailed to authenticate/var/log/osquery/). Add--logger_plugin=filesystem,syslogin the flags file; identifierosqueryd. Results are JSON; a large result can pass 4 KB and arrive with an emptylog.message(section 0.5). Installed from osquery's own packages (not in Debian or Fedora).log.syslogIdentifierisosquerydslapd, but Debian and Ubuntu shipolcLogLevel: none, so no connection or bind lines are logged. SetolcLogLevel: statsoncn=configwithldapmodify. Failed binds end withRESULT tag=97 err=49(invalid credentials).log.syslogIdentifierisslapd; texterr=49syslog-enabled yes(identifierredisorvalkey, fromsyslog-ident). Failed AUTH attempts go only to the in-memoryACL LOG; the default level still logsPossible SECURITY ATTACK detectedfor cross-protocol attacks.log.syslogIdentifieris one ofredis, valkeytraefikorcaddy, the process name). Access logs are opt-in: Traefik--accesslog=truewith--accesslog.format=json(leavefilePathunset); Caddy alogdirective inside the site block. Output is JSON.log.syslogIdentifieris one oftraefik, caddyLeft out on purpose, to keep the table at 25 rows (all checked): Apache Tomcat (the Debian and Ubuntu
tomcat10unit setsSyslogIdentifier=tomcat10, so server messages already reach the journal; the HTTP access log is files only), Nextcloud ('log_type' => 'syslog'inconfig.php, tagNextcloud; failed logins readLogin failed: <user> (Remote IP: <ip>)), Keycloak (console output reaches the journal under the process name unless the unit setsSyslogIdentifier=; its syslog handler sends over the network, which journald does not accept), Zabbix server (LogType=system, identifierzabbix_server) and GitLab (files only; its UDP log forwarding is a paid feature and was not checked against the Collector); and, from the mail, network and security group: ClamAV (Debian runsclamdin the foreground, so<path>: <signature> FOUNDlines should already reach the journal underclamd, not confirmed on a live host; EPEL usesLogSyslog yes), vsftpd (syslog_enable=YES; failures readFAIL LOGIN), ProFTPD (remove Debian'sSystemLogline), Pure-FTPd (syslog by default), Exim (log_file_path = :syslog, identifierexim), Cockpit (journal by default; failures come from PAM insidecockpit-session), HashiCorp Vault (vault audit enable syslog tag="vault" facility="AUTH"; large entries can fail), Asterisk (syslog.local0 => notice,warning,error,securityinlogger.conf, identifierasterisk), SSSD (its journal entries carry no identifier; login results appear under the calling program, such assshd) and the Duo Authentication Proxy (Duo says its authentication events do not go to syslog).Sources checked for this list (24 Sep 2026)
Sources for 3c (checked 2026-09-24):
sshd.c,sshd-session.c,sshd-auth.c,auth.c,monitor.c,log.c); versions from sources.debian.org, packages.ubuntu.com and mirror.stream.centos.org (CentOS Stream 9 and 10 ship openssh-server 9.9p1).syslog,log_allowed,log_deniedoptions. su: util-linuxsu-common.c. Account tools: github.com/shadow-maint/shadowsrc/useradd.c,usermod.c,userdel.c,groupadd.c,passwd.c.src/core/ngx_syslog.c(default tag,nohostname, tag characters).server/log.c; Debianapache22.4.68000-default.conf; util-linux logger(1) andlogger.c(local header, 1 KiB default size).journald-syslog.c(syslog_parse_identifier), journald.conf(5) (rate limits), journalctl(1) (fields over 4096 bytes become null).conf/ufw.confandsrc/backend_iptables.py. firewalld: firewalld.conf(5) (LogDenied), github.com/firewalld/firewalldsrc/firewall/core/nftables.pyandbase.py.haproxy3.0.11debian/haproxy.cfgand the patch that binds/dev/loginto the chroot; gitlab.com/redhat/centos-stream/rpms/haproxyhaproxy.cfg; haproxy.org configuration manual 3.0.sql/auth/sql_authentication.cc; Ubuntumysqld.cnf; CentOS Streammysql8.4server.cnf.in.mariadb11.8.650-server.cnfandmariadb.service.in; mariadb.com error log and audit plugin documentation; CentOS Streammariadb10.11.src/backend/libpq/auth.c; postgresql-commonpg_ctlcluster; CentOS Streampostgresql16logging patch.debian/mongod.conf.redis.confandvalkey.conf; CentOS Stream packages; redissrc/acl.c,src/server.c; redis.io ACL LOG.access_logandlogformat; Debian and CentOS Streamsquid.service.logdirective; caddyserver/distcaddy.service.distro/systemd/openvpn-server@.service.inandsample/sample-config-files/server.conf(release 2.6),src/openvpn/ssl_verify.candssl.c; Debianopenvpn@.service.source3/modules/vfs_full_audit.c(openlog("smbd_audit", ...), operation names).pve-access-controlAccessControl.pm;proxmox-rest-serverenvironment.rs.syslog_nameandmaillog_file; postfix.org/MAILLOG_README.html; Debian postfix 3.10src/smtpd/smtpd_sasl_glue.c.client-common.c.querylog).config/fail2ban.confandfail2ban/server/server.py(JournalHandler(SYSLOG_IDENTIFIER='fail2ban')).raddb/radiusd.conf.in,src/main/auth.c,src/main/mainconfig.cand Debian's rename patch.plugins/logger/syslog_logger.cpp.slapd.init.ldif;servers/slapd/result.c.Done per technology
Research notes this list relies on
0.5 Linux field names (data type
linux)The agent streams
journalctl -f -o json --no-pager(agent/collector/platform/linux_amd64.go) and tails the audit log. Afterlinux.yaml:SYSLOG_IDENTIFIER, the syslog tag)log.syslogIdentifier_SYSTEMD_UNIT)log.systemdUnitUNIT)log.unit_COMM)origin.process_CMDLINE)origin.command_HOSTNAME)origin.host_TRANSPORT: syslog, journal, stdout, kernel)log.transportlog.messagelog.priority,severitydataSourceLimits a Linux guide must mention:
journalctl -o jsonwithout--allturns every field longer than 4096 bytes intonull(systemdjournalctldocumentation, "json" output). A message longer than 4 KB arrives with an emptylog.message; the rest of the entry still arrives.RateLimitIntervalSec=30s,RateLimitBurst=10000). Busy access logs sent through syslog can hit it.log.type = auditd.name:orname[pid]:(systemdjournald-syslog.c,syslog_parse_identifier). A program that writes its own syslog header with a host name in that place arrives with nolog.syslogIdentifier, and the host name and tag stay insidelog.message;origin.processstill holds the process name. glibcsyslog()and util-linuxloggerwrite the expected form. Nginx needs itsnohostnameoption (table 3c).