An rsyslog rule reads `mail.warning /var/log/mail-problems`. Which messages from the mail facility does this rule write to that file?
LPIC-1 Exam 102-500, objective 108. Essential system services hard
Draft — not checked yet. This question was written from the published exam objectives and cites the clause it comes from, but nobody has yet read it against that clause and signed for it.
It is kept out of search results and out of mock exams until they have. Read the source below before you take the answer as settled.
The options
Not correct Only messages whose severity is exactly warning.
Wrong for the plain form. To match one severity and nothing else you must write it as `mail.=warning`.
Correct Messages of severity warning and every more severe level: err, crit, alert and emerg.
Correct. A bare severity in a syslog selector means 'this level and everything more urgent'. warning, err, crit, alert and emerg all match; notice, info and debug do not.
Not correct Messages of severity warning and every less severe level: notice, info and debug.
Wrong, and the inverted reading. Severities count upward in number as they get less urgent (emerg 0 through debug 7), and a selector catches the named level plus the lower-numbered, more urgent ones.
Not correct All messages from the mail facility regardless of severity.
Wrong. That is what `mail.*` means. Naming a severity restricts the match.
Why
A syslog selector is facility.severity. The eight severities, most to least urgent, are emerg, alert, crit, err, warning, notice, info, debug. A bare severity matches that level and all more urgent ones. rsyslog adds modifiers: `=` for exactly one level (`mail.=info`), `!` for excluding one and above, and `none` for suppressing a facility inside a multi-selector line, as in the classic `*.info;mail.none;authpriv.none;cron.none` rule. Standard facilities include auth, authpriv, cron, daemon, kern, lpr, mail, news, syslog, user, uucp and local0 through local7.
Where this comes from
- Cited
- LPI exam objective 108.2
- What it says
- Understand standard syslog facilities, priorities and actions in rsyslog configuration.
Practise this
Reading one question is not practice. The trainer will draw a set from objective 108 and space the ones you get wrong.