An rsyslog rule reads `mail.warning /var/log/mail-problems`. Which messages from the mail facility does this rule write to that file?

LPIC-1 Exam 102-500, objective 108. Essential system services hard

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Not correct Only messages whose severity is exactly warning.

Wrong for the plain form. To match one severity and nothing else you must write it as `mail.=warning`.

Correct Messages of severity warning and every more severe level: err, crit, alert and emerg.

Correct. A bare severity in a syslog selector means 'this level and everything more urgent'. warning, err, crit, alert and emerg all match; notice, info and debug do not.

Not correct Messages of severity warning and every less severe level: notice, info and debug.

Wrong, and the inverted reading. Severities count upward in number as they get less urgent (emerg 0 through debug 7), and a selector catches the named level plus the lower-numbered, more urgent ones.

Not correct All messages from the mail facility regardless of severity.

Wrong. That is what `mail.*` means. Naming a severity restricts the match.

Why

A syslog selector is facility.severity. The eight severities, most to least urgent, are emerg, alert, crit, err, warning, notice, info, debug. A bare severity matches that level and all more urgent ones. rsyslog adds modifiers: `=` for exactly one level (`mail.=info`), `!` for excluding one and above, and `none` for suppressing a facility inside a multi-selector line, as in the classic `*.info;mail.none;authpriv.none;cron.none` rule. Standard facilities include auth, authpriv, cron, daemon, kern, lpr, mail, news, syslog, user, uucp and local0 through local7.

Where this comes from

Cited
LPI exam objective 108.2
What it says
Understand standard syslog facilities, priorities and actions in rsyslog configuration.

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 108 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500

More questions on this objective

All questions on Essential system services

Practise LPIC-1 Exam 102-500