Question about logs
Hello all,
I have some newbie question. I have lots of logs in /var/log. I have noticed some logs, for example, ssh log are not updating. And have no idea why. I have files: ssh.log ssh.log.0 ssh.log.1.gz ssh.log.2.gz and so on As I understand my current log is ssh.log and all other files are just archives. Last entry in ssh.log is two days old, but I login and logout to linux via SSH 10-15 times a day every day, but I don't see logs of it. Have you any idea why ? Best regards, alpha |
Depends on the settings. iirc, default is only to log certain types of failures.
Google sshd.conf settings, then check your /etc/sshd.conf. |
Quote:
Quote:
|
Hi,
Thank you both for answers. I'm experiencing the same problem not only with SSH logging, but also with proftpd FTP server. Problem is the same. Also I can see that for example ssh.log file last entry is unfinished. I mean something like this: Code:
Oct 22 17:27:33 someserver sshd[230 Quote:
Code:
SyslogFacility LOCAL7 Code:
local7.* -/var/log/ssh.log Quote:
/var/log/ssh.log: syslog 2250 F.... syslogd Now I'm going to restart syslog. ... it seems it won't help :( Regards, alpha |
If you undo your sshd_config changes and go back to defaults, does that log SSH related messages in /var/log/{secure,auth.log,messages}?
Also some Syslogd implementations don't like spaces where tabs are expected between the facility/priority and logfile name. Can you check if that's the case? And if that doesn't give any clues, can you verify the integrity of your klogd and syslog binaries? |
Hi,
I restarted my system and everything goes well again. It would be nice to find the cause of the problem anyway. Regards, alpha |
Quote:
|
All times are GMT -5. The time now is 06:06 AM. |