asl.conf   [plain text]


##
# configuration file for syslogd and aslmanager
##

# redirect com.apple.message.domain to /var/log/DiagnosticMessages
? [T com.apple.message.domain] store_dir /var/log/DiagnosticMessages

# redirect com.apple.performance* messages to /var/log/performance
? [A= Facility com.apple.performance] store_dir /var/log/performance

# redirect com.apple.eventmonitor* messages to /var/log/eventmonitor
? [A= Facility com.apple.eventmonitor] store_dir /var/log/eventmonitor

# authpriv messages are root/admin readable
? [= Facility authpriv] access 0 80

# remoteauth critical, alert, and emergency messages are root/admin readable
? [= Facility remoteauth] [<= Level critical] access 0 80

# broadcast emergency messages
? [= Level emergency] broadcast

# save kernel [PID 0] and launchd [PID 1] messages
? [<= PID 1] store

# ignore "internal" facility
? [= Facility internal] ignore

# save everything from emergency to notice
? [<= Level notice] store

# Flat file configurations formerly in syslog.conf

# install messages get saved only in install.log
? [= Facility install] file /var/log/install.log format=bsd
? [= Facility install] ignore

# kernel messages get saved in system.log
? [= Sender kernel] file /var/log/system.log mode=0600 gid=80 format=bsd

# emergency - notice get saved in system.log
? [<= Level notice] file /var/log/system.log

# Facility auth to level info gets saved in system.log
? [= Facility auth] [<= Level info] file /var/log/system.log

# Facility authpriv gets saved in system.log
? [= Facility authpriv] file /var/log/system.log

# Facility mail gets saved in mail.log
? [= Facility mail] file /var/log/mail.log mode=0644 format=bsd

# Facility com.apple.alf.logging gets saved in appfirewall.log
? [= Facility com.apple.alf.logging] file /var/log/appfirewall.log