LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 05-06-2012, 04:41 AM   #1
catkin
LQ 5k Club
 
Registered: Dec 2008
Location: Tamil Nadu, India
Distribution: Debian
Posts: 8,578
Blog Entries: 31

Rep: Reputation: 1208Reputation: 1208Reputation: 1208Reputation: 1208Reputation: 1208Reputation: 1208Reputation: 1208Reputation: 1208Reputation: 1208
Samba audit logging not working as expected


This config does not put anything in /var/log/samba/log.audit as expected. The messages are triplicated into /var/log/{messages,syslog,user.log}.

smb.conf.source:
Code:
[global]
domain master = Yes
guest ok = Yes
load printers = No
map to guest = Bad User
netbios name = LS1
preferred master = Yes
remote announce = 10.8.0.6/ACUR 10.8.0.10/ACUR 10.8.0.14/ACUR 10.8.0.18/ACUR \
  10.8.0.22/ACUR 10.8.0.26/ACUR 10.8.0.30/ACUR 10.8.0.34/ACUR 10.8.0.38/ACUR \
  10.8.0.42/ACUR 10.8.0.46/ACUR 10.8.0.50/ACUR 10.8.0.54/ACUR 10.8.0.60/ACUR \
  10.8.0.64/ACUR 10.8.0.68/ACUR
server string = Server
smb ports = 139
syslog = 0
wins support = Yes
workgroup = ACUR

# Audit settings (order may matter)
vfs object = full_audit
vfs_full_audit:prefix = %u|%I|%S
vfs_full_audit:success = all
vfs_full_audit:failure = all
vfs_full_audit:facility = LOCAL7
vfs_full_audit:priority = NOTICE

[snip share definitions]
The smb.conf created from it by testparm smb.conf.source > smb.conf (no error messages)
Code:
[global]
        workgroup = ACUR
        netbios name = LS1
        server string = Server
        map to guest = Bad User
        syslog = 0
        smb ports = 139
        load printers = No
        preferred master = Yes
        domain master = Yes
        wins support = Yes
        remote announce = 10.8.0.6/ACUR 10.8.0.10/ACUR 10.8.0.14/ACUR 10.8.0.18/ACUR   10.8.0.22/ACUR 10.8.0.26/ACUR 10.8.0.30/ACUR 10.8.0.34/ACUR 10.8.0.38/ACUR   10.8.0.42/ACUR 10.8.0.46/ACUR 10.8.0.50/ACUR 10.8.0.54/ACUR 10.8.0.60/ACUR   10.8.0.64/ACUR 10.8.0.68/ACUR
        vfs_full_audit:priority = NOTICE
        vfs_full_audit:facility = LOCAL7
        vfs_full_audit:failure = all
        vfs_full_audit:success = all
        vfs_full_audit:prefix = %u|%I|%S
        guest ok = Yes
        vfs objects = full_audit
/etc/rsyslog.d/samba-audit.conf:
Code:
# rsyslog config fragment for samba audit logging

# Must be harmonised with the samba configuration

if $syslogfacility-text == 'local7' and $programname == 'smbd' then /var/log/samba/log.audit
& ~
The rsyslog and samba daemons were restarted.

After browsing a share using a WXP system, /var/log/{messages,syslog,user.log} got messages but /var/log/samba/log.audit was empty.

This on Debian squeeze with 2:3.5.6~dfsg-3squeeze6 and rsyslog 4.6.4-2.
 
Old 05-07-2012, 06:15 PM   #2
Tinkster
Moderator
 
Registered: Apr 2002
Location: earth
Distribution: slackware by choice, others too :} ... android.
Posts: 23,067
Blog Entries: 11

Rep: Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928Reputation: 928
W/o having tried to set-up audit_logging on samba myself I notice only that LOCAL7 many
not be the same as local7, just a wild guess, but as you don't mention whether you tried
that or not I thought it may be worth putting it out there ...

Also (again, just poking in the dark) I'm not sure whether the syslog = 0 (only errors)
would override the the notice in the audit section ...
 
Old 05-07-2012, 10:49 PM   #3
catkin
LQ 5k Club
 
Registered: Dec 2008
Location: Tamil Nadu, India
Distribution: Debian
Posts: 8,578

Original Poster
Blog Entries: 31

Rep: Reputation: 1208Reputation: 1208Reputation: 1208Reputation: 1208Reputation: 1208Reputation: 1208Reputation: 1208Reputation: 1208Reputation: 1208
Thanks for the suggestions Tinkster

Yes -- I tried both local7 (the way *syslog has it) and LOCAL7 (the way samba has it, as shown by the testparm output. Why did the Samba team choose something different from *syslog?!).

I also tried with and without syslog = 0.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Samba/LDAP groups not working as expected. i2ambler Linux - Server 0 02-23-2012 10:52 AM
Samba write list not working as expected axedre Linux - Newbie 4 11-26-2009 08:17 AM
samba with mulriple configurations not working as expected nass Linux - Server 2 12-13-2008 08:03 AM
syslog-ng on FC5 only logging audit weisso5 Linux - Software 1 01-07-2008 01:50 PM
Audit Logging Phaethar Linux - Software 0 11-07-2007 03:31 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 05:20 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration