/var/log/syslog(Debian)或/var/log/messages(CentOS)。/var/log/apache2/access.log(访问)、/var/log/apache2/error.log(错误)。/var/log/nginx/access.log(访问)、/var/log/nginx/error.log(错误)。/var/log/mysql/error.log(错误)、/var/log/mysql/general.log(通用)。/var/log/auth.log(用户认证)。cat:查看完整日志(适合小文件),如cat /var/log/syslog。tail -f:实时查看新增日志,如tail -f /var/log/apache2/error.log。grep:过滤关键字,如grep 'error' /var/log/syslog。logrotate管理日志压缩和清理,配置文件位于/etc/logrotate.conf。awk/sed:处理文本数据,如提取特定字段。sort/uniq:排序和去重,如sort access.log | uniq -c。journalctl -u apache2。auth.log中的登录失败记录,识别暴力破解尝试。top命令分析服务器负载。chmod 640 /var/log/apache2/*.log。参考来源: