1 |
On 21 Dec 2005, at 12:32, Gavin Seddon wrote: |
2 |
> I have been looking in '/var/log' for users logging on. The files and |
3 |
> directories in there are fastidiously organised (to say the least). |
4 |
> Better than usual UNIX distros. What is the best place to look for |
5 |
> logins/hacks. |
6 |
|
7 |
Which syslog daemon do you use? How is it configured? |
8 |
|
9 |
I use metalog and I get password failure notices in /var/log/pwdfail/* |
10 |
|
11 |
You could also run |
12 |
lastlog |grep -v '**Never logged in**' |
13 |
to see when people last logged in. |
14 |
|
15 |
Yours, |
16 |
Craig |
17 |
-- |
18 |
Craig Webster | t: +44 (0)131 516 8595 | e: craig@××××××.net |
19 |
Xeriom.NET | f: +44 (0)709 287 1902 | w: http://xeriom.net |
20 |
|
21 |
|
22 |
|
23 |
-- |
24 |
gentoo-amd64@g.o mailing list |