<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Syslog edition in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/syslog-edition/m-p/4538170#M369010</link>
    <description>&amp;gt; i have checked with last -R root, but no root entry was there at that time.if somebody edited the /var/adm/wtmp file then last -R will not show&lt;BR /&gt; &lt;BR /&gt;last -R only shows logins and logouts. A root user may login and edit every file in the system. You can see these commands that were executed in the root user $HOME directory in the file .sh_history. If that file is not present, then there are no records of what root did when logged in. The .sh_history file is an absolute requirement (for all users) in a secure system. &lt;BR /&gt; &lt;BR /&gt;But giving the root password to anyone is always a security risk. The better choice is to use sudo (download from HP) and set rules for each user's capabilities.</description>
    <pubDate>Mon, 23 Nov 2009 16:45:25 GMT</pubDate>
    <dc:creator>Bill Hassell</dc:creator>
    <dc:date>2009-11-23T16:45:25Z</dc:date>
    <item>
      <title>Syslog edition</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/syslog-edition/m-p/4538164#M369004</link>
      <description>Is it possible to edit syslog.log file while system is running.if it is possible how to identify who is edited?&lt;BR /&gt;&lt;BR /&gt;Please help me i am in trable.</description>
      <pubDate>Mon, 23 Nov 2009 07:09:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/syslog-edition/m-p/4538164#M369004</guid>
      <dc:creator>Vijaya Ragavan_1</dc:creator>
      <dc:date>2009-11-23T07:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog edition</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/syslog-edition/m-p/4538165#M369005</link>
      <description>&amp;gt;&amp;gt;Is it possible to edit syslog.log file while system is running.if it is possible how to identify who is edited?&lt;BR /&gt;&lt;BR /&gt;Please help me i am in trable.&amp;lt;&amp;lt;&amp;lt;&lt;BR /&gt;&lt;BR /&gt;yes its possible.&lt;BR /&gt;&lt;BR /&gt;i will assume person who have "root" access or privilege user can on edit the syslog.log&lt;BR /&gt;&lt;BR /&gt;if syslog carried proper file permission as shown below&lt;BR /&gt;&lt;BR /&gt;-rw-r--r--   1 root       root        846035 Nov 23 15:09 /var/adm/syslog/syslog.log&lt;BR /&gt;&lt;BR /&gt;How to check ?&lt;BR /&gt;&lt;BR /&gt;if auditing as been enable you check, if not&lt;BR /&gt;&lt;BR /&gt;last -R root |more -&amp;gt; look for the IP address and the time when was the syslog.log has been edited. may give you clue :)&lt;BR /&gt;&lt;BR /&gt;Hope This helps,&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Johnson&lt;BR /&gt;</description>
      <pubDate>Mon, 23 Nov 2009 07:23:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/syslog-edition/m-p/4538165#M369005</guid>
      <dc:creator>Johnson Punniyalingam</dc:creator>
      <dc:date>2009-11-23T07:23:07Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog edition</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/syslog-edition/m-p/4538166#M369006</link>
      <description>yeh i think it can be edited while system is running [ i tried it, worked ], and regarding who edited it only root can edit it cause it has 644 permission,&lt;BR /&gt;&lt;BR /&gt;Now if you want to find which user logged in as root [ if you don give root passwd ] &lt;BR /&gt;then you may have to use some other s/w likes powerbroker etc.&lt;BR /&gt;&lt;BR /&gt;BR,&lt;BR /&gt;Kapil+</description>
      <pubDate>Mon, 23 Nov 2009 07:26:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/syslog-edition/m-p/4538166#M369006</guid>
      <dc:creator>Kapil Jha</dc:creator>
      <dc:date>2009-11-23T07:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog edition</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/syslog-edition/m-p/4538167#M369007</link>
      <description>i have checked with last -R root, but no root entry was there at that time.if somebody edited the /var/adm/wtmp file then last -R will not show.</description>
      <pubDate>Mon, 23 Nov 2009 07:32:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/syslog-edition/m-p/4538167#M369007</guid>
      <dc:creator>Vijaya Ragavan_1</dc:creator>
      <dc:date>2009-11-23T07:32:32Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog edition</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/syslog-edition/m-p/4538168#M369008</link>
      <description>if your user can directly enter root passwd, then its pretty difficult to figure it out.&lt;BR /&gt;&lt;BR /&gt;For future you can use 'script' command in profile file [ to capture everything a user do ] and then save it somewhere for your referemce.&lt;BR /&gt;&lt;BR /&gt;FOr the time being I think its not possible who edited.&lt;BR /&gt;&lt;BR /&gt;BR,&lt;BR /&gt;Kapil+</description>
      <pubDate>Mon, 23 Nov 2009 07:46:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/syslog-edition/m-p/4538168#M369008</guid>
      <dc:creator>Kapil Jha</dc:creator>
      <dc:date>2009-11-23T07:46:14Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog edition</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/syslog-edition/m-p/4538169#M369009</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;The best way who accessed this file use either a script with cronjob OR install HIDS software from HP. The second way is great of course. Go to this link to see first method:&lt;BR /&gt;&lt;A href="http://forums13.itrc.hp.com/service/forums/questionanswer.do?threadId=1377980" target="_blank"&gt;http://forums13.itrc.hp.com/service/forums/questionanswer.do?threadId=1377980&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;if prefer the second method:&lt;BR /&gt;&lt;A href="https://h20392.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=HPUX-HIDS" target="_blank"&gt;https://h20392.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=HPUX-HIDS&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;it is up to you,&lt;BR /&gt;</description>
      <pubDate>Mon, 23 Nov 2009 08:47:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/syslog-edition/m-p/4538169#M369009</guid>
      <dc:creator>Hakki Aydin Ucar</dc:creator>
      <dc:date>2009-11-23T08:47:05Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog edition</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/syslog-edition/m-p/4538170#M369010</link>
      <description>&amp;gt; i have checked with last -R root, but no root entry was there at that time.if somebody edited the /var/adm/wtmp file then last -R will not show&lt;BR /&gt; &lt;BR /&gt;last -R only shows logins and logouts. A root user may login and edit every file in the system. You can see these commands that were executed in the root user $HOME directory in the file .sh_history. If that file is not present, then there are no records of what root did when logged in. The .sh_history file is an absolute requirement (for all users) in a secure system. &lt;BR /&gt; &lt;BR /&gt;But giving the root password to anyone is always a security risk. The better choice is to use sudo (download from HP) and set rules for each user's capabilities.</description>
      <pubDate>Mon, 23 Nov 2009 16:45:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/syslog-edition/m-p/4538170#M369010</guid>
      <dc:creator>Bill Hassell</dc:creator>
      <dc:date>2009-11-23T16:45:25Z</dc:date>
    </item>
  </channel>
</rss>

