How to Configure Logwatch for Linux System Log Analysis: A Complete Setup Guide
To configure Logwatch for Linux system log analysis, install the package via your distribution's package manager, preview reports using command-line flags, and configure a daily cron job to email HTML summaries to root.
Setting up automated log monitoring is a critical step in securing any Linux server. This guide walks through the exact implementation details found in the imthenachoman/How-To-Secure-A-Linux-Server repository, demonstrating how to deploy Logwatch to scan system logs and deliver concise daily reports without manual intervention.
Install Logwatch on Your Linux Server
Logwatch is available in standard Debian-based repositories. Installation requires only a single package manager command.
Run the following to install Logwatch:
sudo apt install logwatch
This installs the log analyzer along with its default configuration templates and the daily cron script located at /etc/cron.daily/00logwatch.
Generate a Manual Report to Preview Output
Before automating reports, verify that Logwatch captures the expected log data by running it manually. The /usr/sbin/logwatch binary accepts several command-line flags that override default settings.
Execute this command to output yesterday's activity for all services to your terminal:
sudo /usr/sbin/logwatch --output stdout --format text --range yesterday --service all
This preview step confirms that the Output, Format, Range, and Service parameters are configured correctly before you commit to an automated email schedule.
Schedule Daily Automated Log Analysis
The repository recommends modifying the existing daily cron script rather than creating a new cron entry. This approach integrates cleanly with the system's existing log rotation schedule.
Back Up the Original Cron Script
Always preserve the original script before modification. Create a timestamped copy and disable execution permissions on the backup to prevent accidental runs:
sudo cp --archive /etc/cron.daily/00logwatch \
/etc/cron.daily/00logwatch-COPY-$(date +"%Y%m%d%H%M%S")
sudo chmod -x /etc/cron.daily/00logwatch-COPY*
Configure Email Delivery Settings
Edit the active script at /etc/cron.daily/00logwatch using your preferred text editor (e.g., sudo nano /etc/cron.daily/00logwatch). Replace the existing execution line with the following configuration:
/usr/sbin/logwatch --output mail --format html --mailto root --range yesterday --service all
This command instructs Logwatch to send an HTML-formatted email to the root user, covering all services for the previous day. The --output mail flag triggers email delivery rather than stdout output.
Verify the Cron Job Execution
Test your modified script manually to ensure email delivery functions correctly:
sudo /etc/cron.daily/00logwatch
Successful execution should result in an HTML email arriving at the root mailbox. If mail fails to deliver, the repository notes that line-length limits in your mail transfer agent may require separate troubleshooting.
Understand the Default Configuration Structure
Logwatch ships with comprehensive default configuration files that document available options. The master configuration file resides at:
/usr/share/logwatch/default.conf/logwatch.conf
This file defines default values for Output, Format, MailTo, Range, and Service parameters. While you can edit this file directly, the imthenachoman/How-To-Secure-A-Linux-Server guide recommends using command-line flags in the cron script instead, keeping your customizations isolated and upgrade-safe.
Summary
- Install Logwatch using
sudo apt install logwatchto begin Linux system log analysis. - Preview reports manually with
/usr/sbin/logwatch --output stdout --format text --range yesterday --service allbefore automating. - Back up
/etc/cron.daily/00logwatchusing timestamped copies andchmod -xbefore modifications. - Configure daily emails by editing the cron script to use
--output mail --format html --mailto root. - Test the configuration by running
sudo /etc/cron.daily/00logwatchto verify delivery.
Frequently Asked Questions
What does Logwatch do on a Linux server?
Logwatch is a log-analysis utility that automatically scans system log files, identifies patterns and anomalies, and generates summarized reports. According to the imthenachoman/How-To-Secure-A-Linux-Server repository, it filters noise from raw logs and presents actionable summaries either via stdout or email, making daily security monitoring feasible without manual log inspection.
Where is the Logwatch configuration file located?
The default configuration file is located at /usr/share/logwatch/default.conf/logwatch.conf. This file contains documentation for available parameters including Output, Format, MailTo, Range, and Service. However, the repository recommends passing these options via command-line arguments in the cron script rather than editing the global configuration directly.
How do I change the email recipient for Logwatch reports?
Modify the execution line in /etc/cron.daily/00logwatch and replace --mailto root with your desired email address. For example, use --mailto admin@example.com to route reports to a specific administrator mailbox instead of the local root user.
Why are my Logwatch emails not being delivered?
Email delivery failures typically stem from mail transfer agent (MTA) configuration issues or line-length limitations in the mail protocol. The repository references external troubleshooting resources for resolving these specific delivery problems, as they depend on your specific mail server setup rather than Logwatch configuration.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →