# Services, systemctl आणि journalctl logs

Source: https://ravindrabagale.com/mr/cyber/part-02/ch06-linux-advanced-commands/6-6-services-and-logs-service-systemctl-enable.html
Language: mr (Marathi with English technical terms)

“Nginx start केला, पण reboot नंतर site बंद का?” कारण start म्हणजे आत्ता चालू करा आणि enable म्हणजे boot वेळी सुरू होण्यासाठी configure करा. ही दोन वेगळी कामं आहेत.

 | Command
 | उपयोग

 | sudo service nginx start
 | आत्ता start

 | sudo service nginx stop
 | आत्ता stop

 | sudo service nginx restart
 | थांबवून पुन्हा start

 | sudo service nginx reload
 | Supported config reload; exact behavior service वर अवलंबून

 | sudo service nginx status
 | Service status/logs (pager असेल तर q exit)

 | service --​status-​all
 | Services आणि state ची list (मुख्यतः Ubuntu)

 | Command
 | उपयोग

 | sudo systemctl enable nginx
 | Boot-time activation configure करणे

 | sudo systemctl disable nginx
 | Boot-time auto start disable

 | systemctl is-​active nginx / systemctl is-​enabled nginx
 | Active/enabled state तपासणे; scripts मध्ये उपयोगी

 | systemctl list-​units --​type=​service --​state=​running
 | सर्व running services

 | sudo systemctl daemon-​reload
 | .service unit बदलल्यावर systemd configuration पुन्हा वाचणे

 | journalctl मधून logs:
 | 

service commands start, stop, restart, reload आणि status साठी source मध्ये दिल्या आहेत. Systemd system वर systemctl नेही हीच कामं करता येतात. Reload supported असेल तर service config पुन्हा वाचतो; exact connection handling service वर ठरतं. Restart मध्ये थांबवून पुन्हा सुरू करतात.

systemctl enable boot-time activation configure करतो; plain enable ने आत्ता start होईलच असं नाही. disable केलं तरी चालू service थांबत नाही. is-active आणि is-enabled वेगळे प्रश्न विचारतात. Unit file बदलल्यावर daemon-reload systemd configuration पुन्हा वाचतो; हे app config reload पेक्षा वेगळं आहे.

journalctl ने logs वाचा

journalctl -u nginx                 # all logs of the nginx service
journalctl -u nginx -f              # follow live (Ctrl+C to stop)
journalctl -u nginx --since "1 hour ago"
journalctl -p err -b                # only errors since last boot
journalctl -u sshd -n 30 --no-pager # last 30 lines (service is 'ssh' on Ubuntu)
sudo journalctl --disk-usage

-u unit, -f live follow, --since वेळेची मर्यादा, -p err errors, -b boot आणि -n 30 शेवटच्या 30 entries. Service नाव Ubuntu मध्ये ssh, इतरत्र sshd असू शकतं.

Log files कुठे?

Amazon Linux 2023 वर rsyslog default setup मध्ये नसल्यास /var/log/messages किंवा /var/log/secure दिसणार नाहीत. Journal वापरा; गरजेनुसार rsyslog configure करता येतो.

 | Log (Ubuntu)
 | Log (Amazon Linux 2023)
 | काय दिसतं?

 | /var/log/auth.log
 | journalctl -u sshd
 | SSH activity; sudo साठी योग्य log/journal context तपासा

 | /var/log/syslog
 | journalctl
 | साधारण system messages

 | /​var/​log/​nginx/​access.​log
 | /​var/​log/​nginx/​access.​log
 | Configured web access log entries

 | /​var/​log/​apache2/​error.​log
 | /​var/​log/​httpd/​error_​log
 | Apache errors

Table सामान्य paths दाखवतो; installed logger आणि app config नुसार बदल होतात. SSH unit filter मध्ये SSH logs येतात; सर्व sudo activity त्याच filter मध्ये येईलच असं नाही. Sudo logs स्वतंत्र journal/syslog context मध्ये तपासा.

Security मध्ये logs म्हणजे evidence

Local logs बदलले/delete केले जाऊ शकतात. म्हणून अनेक environments मध्ये logs central system/SIEM कडे लवकर पाठवतात. Log location, retention आणि timestamps समजून घेणं आवश्यक आहे.

Practice

आपल्या lab वर Nginx install/start करा, boot साठी enable करा आणि reboot नंतर running आहे का तपासा. मग त्याच्या शेवटच्या 20 journal entries वाचा.

रवींद्र बागले यांची tip

Website बंद असेल तर आधी service status, शेवटच्या error-log lines आणि ss -tlnp पाहा. यामुळे service चालू आहे का, error काय आहे आणि port listen करतोय का हे लगेच समजतं.
