Gentoo Archives: gentoo-amd64

From: Gavin Seddon <gavin.m.seddon@×××××××××××××.uk>
To: gentoo-amd64@l.g.o
Subject: Re: [gentoo-amd64] /var/log
Date: Wed, 21 Dec 2005 12:54:35
Message-Id: 1135169441.9142.10.camel@linuxstation
In Reply to: Re: [gentoo-amd64] /var/log by Craig Webster
1 Sorry,
2 I also use 'metalog.
3
4
5 On Wed, 2005-12-21 at 12:45 +0000, Craig Webster wrote:
6 > On 21 Dec 2005, at 12:32, Gavin Seddon wrote:
7 > > I have been looking in '/var/log' for users logging on. The files and
8 > > directories in there are fastidiously organised (to say the least).
9 > > Better than usual UNIX distros. What is the best place to look for
10 > > logins/hacks.
11 >
12 > Which syslog daemon do you use? How is it configured?
13 >
14 > I use metalog and I get password failure notices in /var/log/pwdfail/*
15 >
16 > You could also run
17 > lastlog |grep -v '**Never logged in**'
18 > to see when people last logged in.
19 >
20 > Yours,
21 > Craig
22 > --
23 > Craig Webster | t: +44 (0)131 516 8595 | e: craig@××××××.net
24 > Xeriom.NET | f: +44 (0)709 287 1902 | w: http://xeriom.net
25 >
26 >
27 >
28 --
29 Dr Gavin Seddon
30 School of Pharmacy and Pharmaceutical Sciences
31 University of Manchester
32 Oxford Road, Manchester
33 M13 9PL, U.K.
34
35 --
36 gentoo-amd64@g.o mailing list

Replies

Subject Author
Re: [gentoo-amd64] /var/log Brett Johnson <brett@××××.com>