Linux

Where Does rsyslog Store Config and Logs?

Where rsyslog keeps its main config and drop-in snippets on Linux, and where the logs land by distro.

Last updated

rsyslog reads one main config plus a drop-in directory of snippets, with rules routing facilities to log files. Debian and Red Hat ship different defaults, so the same daemon writes different filenames per family. Custom rules belong in drop-ins that survive updates.

Both legacy selector lines and modern script syntax work side by side. The main file varies most between distros, which is why guides disagree. Put local policy in numbered snippet files and leave shipped files alone. Future updates will thank you.

Where rsyslog stores this, by platform

Linux
/etc/rsyslog.conf

Main config plus drop-in snippet directory for local rules. Debian defaults log to syslog; Red Hat splits across messages, secure, and friends. Custom rules belong in snippets that survive package updates.

Frequently asked questions

how do I add a custom log rule

Add a file under /etc/rsyslog.d/ with the rule instead of editing the main file. Distro updates overwrite main config but leave drop-ins alone. Restart the service afterward to apply.

which log file holds what

Debian writes /var/log/syslog while Red Hat splits messages, secure, maillog, and cron. Check the distro default file to confirm before tailing the wrong one. Custom rules can direct anything anywhere.

old vs new config syntax

Mix freely: legacy selector lines and modern RainerScript coexist by design. New rules should use the modern action syntax. Keep shipped defaults intact and layer custom files on top.

Notice an outdated path? Let us know.