<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Linux log in Operating System - Linux</title>
    <link>https://community.hpe.com/t5/operating-system-linux/linux-log/m-p/5015525#M47951</link>
    <description>Thanks for the feedback. I went with sudo.&lt;BR /&gt;R,&lt;BR /&gt;D</description>
    <pubDate>Tue, 26 Feb 2008 16:07:27 GMT</pubDate>
    <dc:creator>Duffs</dc:creator>
    <dc:date>2008-02-26T16:07:27Z</dc:date>
    <item>
      <title>Linux log</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-log/m-p/5015517#M47943</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I am using RedHat AS4 and I need to capture the ssh login details of different users including the commands they use whilst logged in. So far this level of detail does not get logged in either the messages file or the secure log file.&lt;BR /&gt;&lt;BR /&gt;Does anybody know of additional software or possibe ssh logging options that might enable me capture this amount of detail?&lt;BR /&gt;&lt;BR /&gt;Rgds,&lt;BR /&gt;D.</description>
      <pubDate>Thu, 23 Nov 2006 04:40:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-log/m-p/5015517#M47943</guid>
      <dc:creator>Duffs</dc:creator>
      <dc:date>2006-11-23T04:40:49Z</dc:date>
    </item>
    <item>
      <title>Re: Linux log</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-log/m-p/5015518#M47944</link>
      <description>Hello!&lt;BR /&gt;&lt;BR /&gt;Usually you can see the ssh log connection into /var/log/secure.&lt;BR /&gt;&lt;BR /&gt;If i remember, iptables write into this log files and you can see there.</description>
      <pubDate>Thu, 23 Nov 2006 04:59:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-log/m-p/5015518#M47944</guid>
      <dc:creator>Alpha977</dc:creator>
      <dc:date>2006-11-23T04:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: Linux log</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-log/m-p/5015519#M47945</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I know that the secure log provides limited ssh detail but it does not include the commands that are used by individual users while logged in. I am not using iptabes and have SElinux disabled so this is of no use to me.&lt;BR /&gt;&lt;BR /&gt;R,&lt;BR /&gt;D.</description>
      <pubDate>Thu, 23 Nov 2006 05:36:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-log/m-p/5015519#M47945</guid>
      <dc:creator>Duffs</dc:creator>
      <dc:date>2006-11-23T05:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: Linux log</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-log/m-p/5015520#M47946</link>
      <description>You can use process accounting (accton, lastcomm, etc). &lt;BR /&gt;&lt;BR /&gt;Another option is to use the script command. Add the script command to the /etc/profile catching selected user (if). See man script for details.</description>
      <pubDate>Thu, 23 Nov 2006 08:05:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-log/m-p/5015520#M47946</guid>
      <dc:creator>Ivan Ferreira</dc:creator>
      <dc:date>2006-11-23T08:05:27Z</dc:date>
    </item>
    <item>
      <title>Re: Linux log</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-log/m-p/5015521#M47947</link>
      <description>If you need that level of auditing you can't rely on /etc/profile or any other login script because they're too easy to bypass. If you only want to audit shared accounts like oracle a locked password and proper sudo access would do it. Another option is to use a special auditing shell such as EASH that captures all keystrokes, but that is extremely invasive and may log sensitive information such as passwords.</description>
      <pubDate>Mon, 27 Nov 2006 17:35:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-log/m-p/5015521#M47947</guid>
      <dc:creator>Heironimus</dc:creator>
      <dc:date>2006-11-27T17:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: Linux log</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-log/m-p/5015522#M47948</link>
      <description>Hi Duffs,&lt;BR /&gt;&lt;BR /&gt; Power Broker is the software you are looking for. It can do more than just loging the activities of the user.&lt;BR /&gt;You can get more details on this site.&lt;BR /&gt;&lt;A href="http://www.symark.com/powerbroker.htm" target="_blank"&gt;http://www.symark.com/powerbroker.htm&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;SUDO also can help you in this case.&lt;BR /&gt;&lt;A href="http://www.gratisoft.us/sudo/sudo.html" target="_blank"&gt;http://www.gratisoft.us/sudo/sudo.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;Silju</description>
      <pubDate>Tue, 28 Nov 2006 04:03:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-log/m-p/5015522#M47948</guid>
      <dc:creator>Silju</dc:creator>
      <dc:date>2006-11-28T04:03:28Z</dc:date>
    </item>
    <item>
      <title>Re: Linux log</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-log/m-p/5015523#M47949</link>
      <description>Change &lt;BR /&gt;LogLevel&lt;BR /&gt;in /etc/ssh/sshd_config&lt;BR /&gt;&lt;BR /&gt;The possible values are: QUIET, FATAL, ERROR, INFO,VERBOSE, DEBUG, DEBUG1, DEBUG2 and DEBUG3.  The default is INFO.</description>
      <pubDate>Tue, 28 Nov 2006 14:15:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-log/m-p/5015523#M47949</guid>
      <dc:creator>George Liu_4</dc:creator>
      <dc:date>2006-11-28T14:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: Linux log</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-log/m-p/5015524#M47950</link>
      <description>See also:&lt;BR /&gt;&lt;BR /&gt;Enterprise Audit Shell (eash)</description>
      <pubDate>Tue, 28 Nov 2006 15:41:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-log/m-p/5015524#M47950</guid>
      <dc:creator>Ivan Ferreira</dc:creator>
      <dc:date>2006-11-28T15:41:43Z</dc:date>
    </item>
    <item>
      <title>Re: Linux log</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-log/m-p/5015525#M47951</link>
      <description>Thanks for the feedback. I went with sudo.&lt;BR /&gt;R,&lt;BR /&gt;D</description>
      <pubDate>Tue, 26 Feb 2008 16:07:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-log/m-p/5015525#M47951</guid>
      <dc:creator>Duffs</dc:creator>
      <dc:date>2008-02-26T16:07:27Z</dc:date>
    </item>
  </channel>
</rss>

