<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: log analysis in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/log-analysis/m-p/3664399#M242585</link>
    <description>It's fairly easy: only root can change the parameters and rebuild the kernel. Now if untrained people have the root password, or worse, you have created additional UID=0 user accounts, you will have to look at the .sh_history file for each root user. The last command and sulog will tell you when suspicious users login. If tghe user ran sam to change the parameters, you can look at sam logs but these logs will state what wa done and when--not the name of the root user running sam. It's also possible that during the last reboot, someone decided to use vmunix.prev  for the kernel which is the previous kernel.&lt;BR /&gt; &lt;BR /&gt;With this type of a mystery, I would assume that system security has been compromised, or at the very least, too many people have the root password or root access.</description>
    <pubDate>Fri, 04 Nov 2005 09:34:26 GMT</pubDate>
    <dc:creator>Bill Hassell</dc:creator>
    <dc:date>2005-11-04T09:34:26Z</dc:date>
    <item>
      <title>log analysis</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/log-analysis/m-p/3664395#M242581</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;  On my HP-UX server 6 months back I have changed few kernel parameters. &lt;BR /&gt;  But now when I checked I found few parameters are changed again.&lt;BR /&gt;  Shutdownlog shows system is rebooted thru sam nearly 3 months back.&lt;BR /&gt;  Can any one tell me how to check the following thru system logs;&lt;BR /&gt;&amp;gt;&amp;gt; when &amp;amp; who has changed these kernel parametres.&lt;BR /&gt;&lt;BR /&gt;  Thanks in advance ....&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;Varian</description>
      <pubDate>Fri, 04 Nov 2005 03:52:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/log-analysis/m-p/3664395#M242581</guid>
      <dc:creator>varian_1</dc:creator>
      <dc:date>2005-11-04T03:52:41Z</dc:date>
    </item>
    <item>
      <title>Re: log analysis</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/log-analysis/m-p/3664396#M242582</link>
      <description>Are you having user history details? If the parameter is changed by command line using kmtune or kctune then, HISTFILE is only option.&lt;BR /&gt;&lt;BR /&gt;By sam, then have to see sam log file.&lt;BR /&gt;&lt;BR /&gt;-Muthu</description>
      <pubDate>Fri, 04 Nov 2005 03:56:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/log-analysis/m-p/3664396#M242582</guid>
      <dc:creator>Muthukumar_5</dc:creator>
      <dc:date>2005-11-04T03:56:11Z</dc:date>
    </item>
    <item>
      <title>Re: log analysis</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/log-analysis/m-p/3664397#M242583</link>
      <description>hi,&lt;BR /&gt;&lt;BR /&gt;you've got the time of reboot, check the OLDsulog, OLDsyslog, last may give you some hint.&lt;BR /&gt;&lt;BR /&gt;GOOD LUCK!!</description>
      <pubDate>Fri, 04 Nov 2005 04:38:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/log-analysis/m-p/3664397#M242583</guid>
      <dc:creator>Warren_9</dc:creator>
      <dc:date>2005-11-04T04:38:01Z</dc:date>
    </item>
    <item>
      <title>Re: log analysis</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/log-analysis/m-p/3664398#M242584</link>
      <description>Check your log rotation policy and check /var/adm/syslog/ folder for OLDsyslog.log &lt;BR /&gt;&lt;BR /&gt;There are changes of getting that file back and its depends on your admin policy of log rotate. &lt;BR /&gt;&lt;BR /&gt;-Arun</description>
      <pubDate>Fri, 04 Nov 2005 04:48:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/log-analysis/m-p/3664398#M242584</guid>
      <dc:creator>Arunvijai_4</dc:creator>
      <dc:date>2005-11-04T04:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: log analysis</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/log-analysis/m-p/3664399#M242585</link>
      <description>It's fairly easy: only root can change the parameters and rebuild the kernel. Now if untrained people have the root password, or worse, you have created additional UID=0 user accounts, you will have to look at the .sh_history file for each root user. The last command and sulog will tell you when suspicious users login. If tghe user ran sam to change the parameters, you can look at sam logs but these logs will state what wa done and when--not the name of the root user running sam. It's also possible that during the last reboot, someone decided to use vmunix.prev  for the kernel which is the previous kernel.&lt;BR /&gt; &lt;BR /&gt;With this type of a mystery, I would assume that system security has been compromised, or at the very least, too many people have the root password or root access.</description>
      <pubDate>Fri, 04 Nov 2005 09:34:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/log-analysis/m-p/3664399#M242585</guid>
      <dc:creator>Bill Hassell</dc:creator>
      <dc:date>2005-11-04T09:34:26Z</dc:date>
    </item>
  </channel>
</rss>

