<?xml version="1.0" encoding="ISO-8859-1"?>

<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>LinuxQuestions.org - Blogs - wasim_jd</title>
		<link>http://www.linuxquestions.org/questions/blog/wasim_jd-623573/</link>
		<description>LinuxQuestions.org offers a free Linux forum where Linux newbies can ask questions and Linux experts can offer advice. Topics include security, installation, networking and much more.</description>
		<language>en</language>
		<lastBuildDate>Sun, 26 May 2013 01:13:06 GMT</lastBuildDate>
		<generator>vBulletin</generator>
		<ttl>60</ttl>
		<image>
			<url>https://lqo-thequestionsnetw.netdna-ssl.com/questions/images/misc/rss.jpg</url>
			<title>LinuxQuestions.org - Blogs - wasim_jd</title>
			<link>http://www.linuxquestions.org/questions/blog/wasim_jd-623573/</link>
		</image>
		<item>
			<title>Log management</title>
			<link>http://www.linuxquestions.org/questions/blog/wasim_jd-623573/log-management-34558/</link>
			<pubDate>Wed, 07 Mar 2012 13:37:49 GMT</pubDate>
			<description>May I request to assist me in knowing whether all these are recorded in logs and if yes where the logs are located??? 
What Activity was performed ?...</description>
			<content:encoded><![CDATA[<div>May I request to assist me in knowing whether all these are recorded in logs and if yes where the logs are located???<br />
What Activity was performed ? (eg: login of user or enable/ disable network port etc)<br />
What were tool(s) activity was performed with ? (eg. Administrator tool, Windows tools, rlogin, Gzip etc)<br />
What is the status of the activity (Success or Failure), outcome or result of activity ? <br />
Who performed the activity, including where or what system the activity was performed? (eg root, admin or application system)<br />
Why was the activity performed? <br />
When was the Activity performed? <br />
&quot;Create, read, update, or delete confidential information, including <br />
confidential authentication information such as passwords;&quot;<br />
Create, update, or delete information not covered in #7;<br />
Initiate a network connection;<br />
Accept a network connection;<br />
 User authentication and authorization for activities covered in #7 or #8 such as user login and logout;<br />
Grant, modify, or revoke access rights, including adding a new user or group, changing user privilege levels, changing file permissions, changing database object permissions, changing firewall rules, and user password changes;<br />
 System, network, or services configuration changes, including installation of software patches and updates, or other installed software changes;<br />
Application process startup, shutdown, or restart;<br />
&quot;Application process abort, failure, or abnormal end, especially due to resource<br />
 exhaustion or reaching a resource limit or threshold (such as for CPU, memory, <br />
network connections, network bandwidth, disk space, or hardware fault; and&quot;<br />
Detection of Suspicious/ malicious activity from the IPS or IDS <br />
Detection of Suspicious/malicious activity from the Antivirus or Antispyware system.<br />
&quot; Type of action – examples include authorize, create, read, update, delete, and <br />
accept network connection.&quot;<br />
&quot; Subsystem performing the action – examples include process or transaction<br />
 name, process or transaction identifier.&quot;<br />
&quot;Identifiers (as many as available) for the subject requesting the action – examples<br />
 include user name, computer name, IP address, and MAC address.&quot;<br />
&quot; Identifiers (as many as available) for the object the action was performed on <br />
– examples include file names accessed, unique identifiers of records accessed in a database, query parameters used to determine records accessed in a database, computer name,&quot;<br />
 Before and after values when action involves updating a data element, if feasible<br />
 Date and time the action was performed, including relevant time-zone<br />
Whether the action was allowed or denied by access-control mechanisms.<br />
Description and/or reason-codes of why the action was denied by the access-control mechanism, if applicable<br />
<br />
<br />
Thanks a lot.....</div>

]]></content:encoded>
			<dc:creator>wasim_jd</dc:creator>
			<guid isPermaLink="true">http://www.linuxquestions.org/questions/blog/wasim_jd-623573/log-management-34558/</guid>
		</item>
	</channel>
</rss>
