LinuxQuestions.org
Latest LQ Deal: Linux Power User Bundle
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 04-08-2013, 06:56 AM   #1
RiotSloth
LQ Newbie
 
Registered: Apr 2013
Posts: 1

Rep: Reputation: Disabled
Logging a samba share using rsyslog.d on ubuntu 12.04 - not working, help!


Hi guys

Sorry, this is a real noob question I'm sure. I am trying to log full_audit on my samba windows shares so I know who is creating, deleting, renaming, moving etc. files and directories in the samba/windows share.

In my etc/samba/smb.conf file, under [global] I have:


# Audit settings
full_audit: prefix = %u|%I|%S
full_audit:failure = connect
full_audit:success = connect disconnect opendir mkdir rmdir closedir open close read pread write pwrite sendfile rename unlink chmodfchmod chown fchown chdir ftruncate lock symlink readlink link mknod realpath
full_audit:facility = local5
full_audit: priority = notice

And under my [file share name] I have:

vfs object = full_audit

I created a new file in etc/rsyslog.d called 00-samba-audit.conf with these two lines in:

local5.notice /var/log/samba/audit.log
&~

And in the file /etc/rsyslog.d/50-default.conf I changed the following line:

*.*;auth,authpriv.none -/var/log/syslog

to read:

*.*;local5,auth,authpriv.none -/var/log/syslog

with this below it:

local5.notice /var/log/samba/audit.log

I then restarted samba and rsyslog. (This all comes from this web page: http://a32.me/2009/10/samba-audit-trail/)It creates the audit.log file in my /var/log/samba/ directory but nothing else happens; it remains empty.
What am I doing wrong?! I would be really grateful if someone could help me to audit my windows/samba share so I know who is creating, moving, deleting, renaming files etc.

Would be hugely grateful if anyone could help me?!

Thanks!

The RiotSloth
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
rsyslog not logging to a correct file packets Linux - Newbie 2 03-10-2012 09:11 AM
rsyslog logging tftpd-hpa logs to mysql realnoname Linux - General 0 11-06-2011 12:12 PM
[SOLVED] syslog remote logging with rsyslog server Chenchu Linux - Newbie 3 09-17-2011 02:34 PM
Rsyslog not logging routers messages dman777 Linux - Software 9 01-31-2011 06:08 AM
Login Window Does Not Disappear After Logging Into A Samba Share kaplan71 Fedora 1 02-09-2009 07:32 PM


All times are GMT -5. The time now is 11:01 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration