openSUSE Forums > Archives > SLS Archives > ARCHIVES - SuSE Linux > ARCHIVES - Network & Security > ARCHIVES - Security » Logging Settings: Real-time Reporting Of User Access?

Go Back   openSUSE Forums > Archives > SLS Archives > ARCHIVES - SuSE Linux > ARCHIVES - Network & Security > ARCHIVES - Security
Forums FAQ Members List Search Today's Posts Mark Forums Read


ARCHIVES - Security Want to know if you should really apply the latest kernel patch? Want to know how to configure your firewall? Discuss any Security related topics in here!

 
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 22-May-2007, 10:47
sduncan
Guest
 
Posts: n/a
Default

This seems like something that should be relatively straight forward, but we have not found a solution on google or by searching the forums Any help would be appreciated.

We'd like to turn on additional logging that would allow real time reporting of login/logoff events. We know that these events are stored binary files, but in several other Unix systems these events are also reported textually by syslog to /var/log/messages, /var/log/secure, etc. But OpenSUSE 10.2 only seems to report logfails, or remote accesses such as from ssh. Logins from the console, or from xdm are not reported and we'd like them to be. So how do we turn this reporting on? We presumed that we should be able to change some pam or syslog settings to turn on reporting of these events but, unfortunately, the various things we have tried have all failed. Any recommendations on how to do this? Thanks.
  #2 (permalink)  
Old 12-Aug-2007, 05:57
skipper1001
Guest
 
Posts: n/a
Default

i know its a pretty simple way but maybe tcp wrappers for some servers? let me know if you find something else. ;)
  #3 (permalink)  
Old 12-Aug-2007, 06:16
eberhard
Guest
 
Posts: n/a
Default

Quote:
This seems like something that should be relatively straight forward, but we have not found a solution on google or by searching the forums Any help would be appreciated.

We'd like to turn on additional logging that would allow real time reporting of login/logoff events.
[/b]
Use last and lastb to display logins and failed login attempts (lastb). This displays the information stored in /var/log/wtmp and /var/log/btmp resp. Since logging of bad logins is not switched on by deafault, you have to enable it by touch /var/log/btmp first.
  #4 (permalink)  
Old 22-Dec-2007, 12:07
hulleyrob
Guest
 
Posts: n/a
Default

Has anyone every successfully got lastb working on a suse box?

Ive tried many times with failed logins but nothing gets logged there.

Rob
  #5 (permalink)  
Old 23-Dec-2007, 20:00
broch
Guest
 
Posts: n/a
Default

..then try
faillog -a
assuming that faillog is on:
faillog -u root

explanation
man faillog (so you would know why root only if set as above)
 

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




 

Search Engine Friendly URLs by vBSEO 3.3.0 RC2