10.2. 为 BIND 自定义日志记录扩展 SELinux 策略
您可以扩展 SELinux 策略使其包含 BIND 日志。
步骤
创建日志目录:
Copy to Clipboard Copied! Toggle word wrap Toggle overflow mkdir -p /var/log/named chown named:named /var/log/named chmod 750 /var/log/named
# mkdir -p /var/log/named # chown named:named /var/log/named # chmod 750 /var/log/named
将
named_log_t
SELinux 上下文分配给新目录和日志文件:Copy to Clipboard Copied! Toggle word wrap Toggle overflow semanage fcontext -a -t named_log_t "/var/log/named(/.)?"* restorecon -Rv /var/log/named
# semanage fcontext -a -t named_log_t "/var/log/named(/.)?"* # restorecon -Rv /var/log/named
重启 BIND 服务器:
Copy to Clipboard Copied! Toggle word wrap Toggle overflow systemctl restart named
# systemctl restart named
验证
显示自定义日志文件:
Copy to Clipboard Copied! Toggle word wrap Toggle overflow tail -f /var/log/named/ipa_dns_queries.log
$ tail -f /var/log/named/ipa_dns_queries.log