Hi Sai,
 
We know that selinux messages get logged to /var/log/messages. But what we want is to configure syslog such that the selinux messages go to a dedicated file
e.g /var/log/selinux.log instead of getting logged to /var/log/messages .. etc. In other words we want to find out if there is a well defined syslog facility for the selinux
related messages.
 
Thanks
Anamitra


From: sai ganesh [mailto:ganesai@gmail.com]
Sent: Wednesday, March 17, 2010 5:57 AM
To: Anamitra Dutta Majumdar (anmajumd)
Subject: Re: Directing SElinux related logs to a dedicated log file



On Wed, Mar 17, 2010 at 5:18 AM, Anamitra Dutta Majumdar (anmajumd) <anmajumd@cisco.com> wrote:
Hello All,
 
We are trying to ascertain if there is a way to make changes to the syslog configuration file and direct all selinux related messages including sealerts to a separate dedicated log file for SElinux.
 
Any pointers would be greatly appreciated.

Check the audit log which is /var/log/audit/audit.log if auditd is running, all the logs related to se-linux must be appended there,otherwise /var/log/messages. 
--
s.saiganesh
“<--------May the source be with you, but remember the KISS principle ;-)-------------->. <-Fighting 4 Freedom->"