LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-14-2011, 12:41 PM   #1
kk1001
LQ Newbie
 
Registered: Feb 2011
Posts: 5

Rep: Reputation: 0
Smile Audit


Hi to all,
how should i know who has accessed /var/log folder except root. If anyone has tried to access any log files where will be the error message generated. As a admin, where should we can check. I also want to know who has modified what file on a daily basis.

Thanks
kk
 
Old 04-14-2011, 04:39 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by kk1001 View Post
how should i know who has accessed /var/log folder except root. If anyone has tried to access any log files where will be the error message generated.
MAC works on top of DAC so if the DAC doesn't allow it then the MAC doesn't need to be queried and doesn't need to generate any rejects. And if there's no audit rules specified then they won't be triggered.


Quote:
Originally Posted by kk1001 View Post
I also want to know who has modified what file on a daily basis.
Without any details I'd say a combination of a logging shell (Rootsh), Auditd rules (or LoggedFS?), remote syslog.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How can I read the audit time stamp? msg=audit(1213186256.105:20663) abefroman Linux - Software 3 04-21-2011 06:37 PM
[Linux Audit]: Which groups should be allowed to read audit log files? quanba Linux - Security 1 11-15-2010 10:09 AM
error in line 5 of /etc/audit/audit.rules RHEL5u3 abti Red Hat 1 04-06-2010 05:42 PM
/dev/audit bleunuit Linux - Software 0 05-11-2005 08:26 AM
Audit Pranesh Linux - Software 0 08-05-2003 09:13 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:45 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration