- Journald logs the whole boot process
- Journald can make sure that an item really came from some process. It also tries to seal the journal so that it can't be tempered with.
- It's built into the other systemd tools. For example, when you notice a daemon doesn't start through systemctl, it'll show you the error messages in systemctl status.
http://www.freedesktop.org/software/systemd/man/sd-journal.h...
It's so far been adopted by redhat, suse, arch, coreos and with some consideration by debian. The only big name not thinking about it is Ubuntu.
I don't think that many of the journald drivers could have been solved by better syslogd configuration, for example journald cryptographically signs each log entry. Even if you get root on my box, you can't edit an entry without me knowing. That's not possible in any meaningful way with syslog.
I don't share the view of a hack, the speed improvements of introducing journald have been tremendous and usability is mostly better.
For example, the number 1 thing done with syslog output is probably either grep it, so journald improves on this:
journalctl _COMM=sshd --since yesterday --until "08:30"
OR
journalctl /usr/sbin/sshd --since yesterday --until "08:30"
Or tail it journalctl -F
The places i don't like the user interface are around starting and stopping services. However the old interfaces work fine for now.[1] http://www.freedesktop.org/software/systemd/man/systemd.serv... [2] http://www.freedesktop.org/software/systemd/man/journald.con...
it can filter even better than before, because fail2ban usually does not care about everything in `auth.log`. i guess i don't see the problem.
I don't get what you're complaining about, the fragmentation has been reduced :P
How does this affect something like a remote syslog? Could I send the syslog output of my router to journalctl?
It's good to be dropping things like syslogd from the default distribution, and the only reason it was ditched was because syslogd is behind the times.
Yes, syslogd does more. If you want those features, install it. Forcing it on everyone, regardless, serves no purpose.
WTF? Is that because Linux was becoming too easy to use? They have to keep changing it up, so the certification classes have new material to teach. Why wouldn't they keep the command around and wrap whatever re-invented mousetrap replaces it so millions of people can keep typing ifconfig?
Change is how you abandon things that are holding you back. It's how you get rid of the various albatrosses, of which there are many, and clean up the environment for new users.
ifconfig is absolutely not easy to use.
`ip` really is a better tool, and you're doing yourself a disservice if you're not using it, especially if you have anything more than the basic single IP/default gateway network.
Long ago? Centos 6.4 still has it. My Mac (BSD) has it. I never suggested that it is stupid to add software (ip) that is better, but why would they deliberately remove it when it is such an expected command and works across other unixes? I have trouble believing that it consumes much disk space.
See: http://en.wikipedia.org/wiki/Ifconfig#Current_status
"Modern Linux distributions are in the process of deprecating ifconfig and route..."
Deliberately removing something means you don't have to maintain it any more and can spend your time improving the better tool rather than bug-fixing the legacy one.
There are ways to handle it that make it backwards compatible and user friendly without only a little extra effort. It's not a sexy task, so who cares about usability.
One needs to look no further than what their plans for cgroups are to see the future. Not to mention the plans to get rid of /bin/login and VTs.
Anyway, your entire complaint is explained at every systemd presentation. The maintainers want to have something which can be used as the basic building block for Linux. Various other projects now rely on that.
So systemd is successful, but surely it is a conspiracy! hahaha
Personally, I uninstalled syslog and enabled binary log retention back when I was running F18, and I'm wishing my Ubuntu and Debian boxes had the same ability.