LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-08-2010, 10:24 AM   #1
goodgame
LQ Newbie
 
Registered: Mar 2010
Posts: 2

Rep: Reputation: 0
Filter pam_rhosts_auth messages to prevent the logs filling up


I have a batch job which logs in to the server every 10 minutes via windows rsh. The job checks to see is there are any files that need to be send via a EDI server to a supplier.

The following logwatch report is swamped with the login messages and would like to either suppress the logging in PAM? or suppress the entry in the logwatch report?

But I still want logging id the username is not username1.

--------------------- Connections (secure-log) Begin ------------------------
rshd[1754]: pam_rhosts_auth(rsh:auth): allowed to username1@10.0.0.1 as myedi

Does anyone know of a way round this?

Thanks in advance..
 
Old 03-08-2010, 03:01 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by goodgame View Post
I have a batch job which logs in to the server every 10 minutes via windows rsh. The job checks to see is there are any files that need to be send via a EDI server to a supplier.
By Jove! Shouldn't you use push instead of pull?..


Quote:
Originally Posted by goodgame View Post
suppress the logging in PAM? or suppress the entry in the logwatch report? (..) still want logging id the username is not username1.
What you don't log you won't see. So don't try to suppress in logfiles. The daemon and service files Logwatch uses will have a line saying "# Ignore these entries", so just add your one-liner regex for the daemon/service+logline+username there.
 
Old 03-09-2010, 03:25 AM   #3
goodgame
LQ Newbie
 
Registered: Mar 2010
Posts: 2

Original Poster
Rep: Reputation: 0
Thumbs up Fixed

Quote:
Originally Posted by unSpawn View Post
By Jove! Shouldn't you use push instead of pull?..



What you don't log you won't see. So don't try to suppress in logfiles. The daemon and service files Logwatch uses will have a line saying "# Ignore these entries", so just add your one-liner regex for the daemon/service+logline+username there.
I added a regex to the file /etc/logwatch/conf/ignore.conf. and now the report is great. I now see '3772 Ignored Lines'. Thank you for your help.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] BIND Messages filling up SysLog lomax0990 Linux - Server 1 12-09-2009 10:31 AM
conntrack messages are filling my screen! drakebasher Debian 7 02-12-2006 12:57 PM
IRQ Errors with DLINK DGE-530T filling logs phowarth Linux - Hardware 0 12-27-2005 10:34 PM
ndiswrapper kernel messages filling my logs... TOO MUCH! jkassemi Linux - Wireless Networking 4 11-08-2005 02:12 AM
message logs filling up w/ wlan0 buffer too small error sordomudo11 Linux - Hardware 0 04-13-2004 09:13 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:54 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration