mirror of
https://github.com/PowerShell/Win32-OpenSSH.git
synced 2025-07-26 23:44:35 +02:00
Updated Logging Facilities (markdown)
parent
8bfa54b756
commit
ea75f79bde
@ -1,4 +1,18 @@
|
|||||||
### Logging facilities
|
### Logging facilities
|
||||||
Prior to v7.6.1.0 SSHD supported only 1 default logging facility (file based at logs/sshd.log).
|
Prior to v7.6.1.0, server side components supported only 1 logging facility (file based at logs\sshd.log).
|
||||||
In v7.6.1.0 and later, ETW logging is the default.
|
In v7.6.1.0 and later, ETW logging is added and is the default. You can view these logs under event viewer as follows:
|
||||||
|
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
|
The admin channel is for CRITICAL and ERROR events, operational is for INFO and debug is for DEBUG* variants.
|
||||||
|
The payload would mimic what users would otherwise see in a typical syslog entry.
|
||||||
|
|
||||||
|
File based logging option (useful for quickly collecting debug traces) can be turned on by setting the following in sshd_config
|
||||||
|
|
||||||
|
`LogFacility LOCAL0 `
|
||||||
|
|
||||||
|
With this option, the logs would be collected at %programdata%\ssh\logs.
|
||||||
|
sftp-server would follow similar semantics for logging (by default to ETW) and to files using the following as subsystem path in sshd_config:
|
||||||
|
|
||||||
|
`sftp-server -f LOCAL0`
|
||||||
|
Loading…
x
Reference in New Issue
Block a user