Where Does rsyslog Store Config and Logs?
Where rsyslog keeps its main config and drop-in snippets on Linux, and where the logs land by distro.
Last updated
rsyslog reads one main config plus a drop-in directory of snippets, with rules routing facilities to log files. Debian and Red Hat ship different defaults, so the same daemon writes different filenames per family. Custom rules belong in drop-ins that survive updates.
Both legacy selector lines and modern script syntax work side by side. The main file varies most between distros, which is why guides disagree. Put local policy in numbered snippet files and leave shipped files alone. Future updates will thank you.
Where rsyslog stores this, by platform
/etc/rsyslog.conf
Main config plus drop-in snippet directory for local rules. Debian defaults log to syslog; Red Hat splits across messages, secure, and friends. Custom rules belong in snippets that survive package updates.
Frequently asked questions
how do I add a custom log rule
Add a file under /etc/rsyslog.d/ with the rule instead of editing the main file. Distro updates overwrite main config but leave drop-ins alone. Restart the service afterward to apply.
which log file holds what
Debian writes /var/log/syslog while Red Hat splits messages, secure, maillog, and cron. Check the distro default file to confirm before tailing the wrong one. Custom rules can direct anything anywhere.
old vs new config syntax
Mix freely: legacy selector lines and modern RainerScript coexist by design. New rules should use the modern action syntax. Keep shipped defaults intact and layer custom files on top.
Notice an outdated path? Let us know.