# How to Configure Logwatch for Linux System Log Analysis: A Complete Setup Guide

> Configure Logwatch for Linux system log analysis with this complete setup guide. Learn to install, preview reports, and schedule email summaries.

- Repository: [IMTheNachoMan/How-To-Secure-A-Linux-Server](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server)
- Tags: how-to-guide
- Published: 2026-05-14

---

**To configure Logwatch for Linux system log analysis, install the package via your distribution's package manager, preview reports using command-line flags, and configure a daily cron job to email HTML summaries to root.**

Setting up automated log monitoring is a critical step in securing any Linux server. This guide walks through the exact implementation details found in the `imthenachoman/How-To-Secure-A-Linux-Server` repository, demonstrating how to deploy **Logwatch** to scan system logs and deliver concise daily reports without manual intervention.

## Install Logwatch on Your Linux Server

Logwatch is available in standard Debian-based repositories. Installation requires only a single package manager command.

Run the following to install Logwatch:

```bash
sudo apt install logwatch

```

This installs the log analyzer along with its default configuration templates and the daily cron script located at `/etc/cron.daily/00logwatch`.

## Generate a Manual Report to Preview Output

Before automating reports, verify that Logwatch captures the expected log data by running it manually. The `/usr/sbin/logwatch` binary accepts several command-line flags that override default settings.

Execute this command to output yesterday's activity for all services to your terminal:

```bash
sudo /usr/sbin/logwatch --output stdout --format text --range yesterday --service all

```

This preview step confirms that the **Output**, **Format**, **Range**, and **Service** parameters are configured correctly before you commit to an automated email schedule.

## Schedule Daily Automated Log Analysis

The repository recommends modifying the existing daily cron script rather than creating a new cron entry. This approach integrates cleanly with the system's existing log rotation schedule.

### Back Up the Original Cron Script

Always preserve the original script before modification. Create a timestamped copy and disable execution permissions on the backup to prevent accidental runs:

```bash
sudo cp --archive /etc/cron.daily/00logwatch \
    /etc/cron.daily/00logwatch-COPY-$(date +"%Y%m%d%H%M%S")
sudo chmod -x /etc/cron.daily/00logwatch-COPY*

```

### Configure Email Delivery Settings

Edit the active script at `/etc/cron.daily/00logwatch` using your preferred text editor (e.g., `sudo nano /etc/cron.daily/00logwatch`). Replace the existing execution line with the following configuration:

```bash
/usr/sbin/logwatch --output mail --format html --mailto root --range yesterday --service all

```

This command instructs Logwatch to send an **HTML-formatted** email to the **root** user, covering **all services** for the **previous day**. The `--output mail` flag triggers email delivery rather than stdout output.

### Verify the Cron Job Execution

Test your modified script manually to ensure email delivery functions correctly:

```bash
sudo /etc/cron.daily/00logwatch

```

Successful execution should result in an HTML email arriving at the root mailbox. If mail fails to deliver, the repository notes that line-length limits in your mail transfer agent may require separate troubleshooting.

## Understand the Default Configuration Structure

Logwatch ships with comprehensive default configuration files that document available options. The master configuration file resides at:

```

/usr/share/logwatch/default.conf/logwatch.conf

```

This file defines default values for **Output**, **Format**, **MailTo**, **Range**, and **Service** parameters. While you can edit this file directly, the `imthenachoman/How-To-Secure-A-Linux-Server` guide recommends using command-line flags in the cron script instead, keeping your customizations isolated and upgrade-safe.

## Summary

- **Install Logwatch** using `sudo apt install logwatch` to begin Linux system log analysis.
- **Preview reports manually** with `/usr/sbin/logwatch --output stdout --format text --range yesterday --service all` before automating.
- **Back up `/etc/cron.daily/00logwatch`** using timestamped copies and `chmod -x` before modifications.
- **Configure daily emails** by editing the cron script to use `--output mail --format html --mailto root`.
- **Test the configuration** by running `sudo /etc/cron.daily/00logwatch` to verify delivery.

## Frequently Asked Questions

### What does Logwatch do on a Linux server?

Logwatch is a log-analysis utility that automatically scans system log files, identifies patterns and anomalies, and generates summarized reports. According to the `imthenachoman/How-To-Secure-A-Linux-Server` repository, it filters noise from raw logs and presents actionable summaries either via stdout or email, making daily security monitoring feasible without manual log inspection.

### Where is the Logwatch configuration file located?

The default configuration file is located at [`/usr/share/logwatch/default.conf/logwatch.conf`](https://github.com/imthenachoman/How-To-Secure-A-Linux-Server/blob/main//usr/share/logwatch/default.conf/logwatch.conf). This file contains documentation for available parameters including `Output`, `Format`, `MailTo`, `Range`, and `Service`. However, the repository recommends passing these options via command-line arguments in the cron script rather than editing the global configuration directly.

### How do I change the email recipient for Logwatch reports?

Modify the execution line in `/etc/cron.daily/00logwatch` and replace `--mailto root` with your desired email address. For example, use `--mailto admin@example.com` to route reports to a specific administrator mailbox instead of the local root user.

### Why are my Logwatch emails not being delivered?

Email delivery failures typically stem from mail transfer agent (MTA) configuration issues or line-length limitations in the mail protocol. The repository references external troubleshooting resources for resolving these specific delivery problems, as they depend on your specific mail server setup rather than Logwatch configuration.