Syslog is crap - or at least I thought so

I have been playing around with syslog for an hour or two, trying to figure out how to log sshd related messages in a separate file. When I found out that it is impossible to specify a log-file for the ssh daemon only I thought: “What CRAP!”.

… but only for a short while until an intelligent person pointed out the obvious:

debian:~# grep sshd /var/log/auth.log > /tmp/sshd

Original Goolge Groups message