Hello Everybody,
Currently i have iwatch configured to send its messages to syslog, unfortunately i do not know who performed what item from this output, it is as follows:
Feb 22 10:23:18 hostname iWatch[18873]: IN_CLOSE_WRITE /srv/www/staff/test6/tester/m.ses
Feb 22 10:23:18 hostname iWatch[18873]: * /srv/www/staff/test6/tester/m.ses is closed
Feb 22 10:23:18 hostname iWatch[18873]: * Send email to root@localhost
Is there a way i can configure this log to show who the real user was? Regardless of which user accesses the server it currently shows “test6” for all events including ftp connections.
This is a school server so at any time during semesters there is a minimum of 40 ftp accounts.