10.2. 为 BIND 自定义日志记录扩展 SELinux 策略
您可以扩展 SELinux 策略使其包含 BIND 日志。
步骤
创建日志目录:
mkdir -p /var/log/named chown named:named /var/log/named chmod 750 /var/log/named
# mkdir -p /var/log/named # chown named:named /var/log/named # chmod 750 /var/log/named
Copy to Clipboard Copied! Toggle word wrap Toggle overflow 将
named_log_t
SELinux 上下文分配给新目录和日志文件:semanage fcontext -a -t named_log_t "/var/log/named(/.)?"* restorecon -Rv /var/log/named
# semanage fcontext -a -t named_log_t "/var/log/named(/.)?"* # restorecon -Rv /var/log/named
Copy to Clipboard Copied! Toggle word wrap Toggle overflow 重启 BIND 服务器:
systemctl restart named
# systemctl restart named
Copy to Clipboard Copied! Toggle word wrap Toggle overflow
验证
显示自定义日志文件:
tail -f /var/log/named/ipa_dns_queries.log
$ tail -f /var/log/named/ipa_dns_queries.log
Copy to Clipboard Copied! Toggle word wrap Toggle overflow