<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ssh log in syslog in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-log-in-syslog/m-p/4791313#M391802</link>
    <description>When ever someone logs in to the system using ssh there is an entry in the syslog. I want to disable this for a particular user. &lt;BR /&gt;&lt;BR /&gt;I want sshd to log every one except that user in syslog. Can it be done.&lt;BR /&gt;</description>
    <pubDate>Tue, 24 May 2011 04:53:36 GMT</pubDate>
    <dc:creator>Khashru</dc:creator>
    <dc:date>2011-05-24T04:53:36Z</dc:date>
    <item>
      <title>ssh log in syslog</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-log-in-syslog/m-p/4791313#M391802</link>
      <description>When ever someone logs in to the system using ssh there is an entry in the syslog. I want to disable this for a particular user. &lt;BR /&gt;&lt;BR /&gt;I want sshd to log every one except that user in syslog. Can it be done.&lt;BR /&gt;</description>
      <pubDate>Tue, 24 May 2011 04:53:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-log-in-syslog/m-p/4791313#M391802</guid>
      <dc:creator>Khashru</dc:creator>
      <dc:date>2011-05-24T04:53:36Z</dc:date>
    </item>
    <item>
      <title>Re: ssh log in syslog</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-log-in-syslog/m-p/4791314#M391803</link>
      <description>&lt;P&gt;Hi:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://h30499.www3.hp.com/t5/System-Administration/how-to-filter-sshd-in-syslog-log-to-other-file/m-p/3125831#M151983" target="_blank"&gt;http://h30499.www3.hp.com/t5/System-Administration/how-to-filter-sshd-in-syslog-log-to-other-file/m-p/3125831#M151983&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;rgs,&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jul 2011 15:51:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-log-in-syslog/m-p/4791314#M391803</guid>
      <dc:creator>rariasn</dc:creator>
      <dc:date>2011-07-07T15:51:07Z</dc:date>
    </item>
    <item>
      <title>Re: ssh log in syslog</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-log-in-syslog/m-p/4791315#M391804</link>
      <description>As the thread referenced in the first response explains, you can change the log file of the sshd to something other than syslog.log but this change is global to all ssh users not only to a single one.&lt;BR /&gt;&lt;BR /&gt;What you are doing is quite suspicious and will raise eyebrows when you go through an audit and your scheme gets found out. As if you are trying to hide the actions of some user, by hiding his/her logins to the system. Very bad idea in my opinion, despite how good your intentions might be (don't know how can there be any good intentions for such a setup though but giving it the benefit of the doubt here)</description>
      <pubDate>Tue, 24 May 2011 13:58:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-log-in-syslog/m-p/4791315#M391804</guid>
      <dc:creator>Mel Burslan</dc:creator>
      <dc:date>2011-05-24T13:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: ssh log in syslog</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-log-in-syslog/m-p/4791316#M391805</link>
      <description>We use nagis monitoring to monitor the system and it uses ssh login. It logs in to the system tousands times a day. I donot want unnecessary information in the syslog. This will reduce the size of syslog and i will be able to find the important information from syslog.</description>
      <pubDate>Tue, 24 May 2011 22:35:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-log-in-syslog/m-p/4791316#M391805</guid>
      <dc:creator>Khashru</dc:creator>
      <dc:date>2011-05-24T22:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: ssh log in syslog</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ssh-log-in-syslog/m-p/4791317#M391806</link>
      <description>So the entries come from check_by_ssh Nagios checks I suppose.&lt;BR /&gt;Running local checks via nrpe wouldn't be an option?&lt;BR /&gt;Or you could reverse from Nagios actively polling the host a thousand times a day to sending only non-ok check results a few times a month via nsca to the nagios server.&lt;BR /&gt;Maybe you could also SyslogFacility in your sshd's sshd_config to some localX facility and configure the host's syslogd to pipe it into a filter which would strip off check_by_ssh connects from the nagios server?</description>
      <pubDate>Wed, 25 May 2011 12:18:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ssh-log-in-syslog/m-p/4791317#M391806</guid>
      <dc:creator>Ralph Grothe</dc:creator>
      <dc:date>2011-05-25T12:18:49Z</dc:date>
    </item>
  </channel>
</rss>

