
Practical Linux Security Cookbook
By :

As an administrator, while checking for malicious activity on the system or any software issue, log files play a very important role. However, with the increasing number of software, the number of log files being created has also increased. This makes it very difficult for an administrator to analyze log files properly.
In such scenarios, Logcheck is a really nice tool that's available to help administrators in analyzing and scanning log files. Logcheck scans the logs for interesting lines as per its documentation.
These interesting lines"mainly refer to the security issues detected by the tool.
No specific requirements are needed to use Logcheck on a Linux system.
In this section, we will see how to install and configure Logcheck so that we can use it, as per our requirements: