Latest LQ Deal: Linux Power User Bundle
Go Back > Forums > Linux Forums > Linux - Security
User Name
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.


  Search this Thread
Old 04-02-2005, 11:53 AM   #1
Registered: Mar 2005
Distribution: Slackware 10.1, Kernel (custom)
Posts: 166

Rep: Reputation: 30
Keylogger / session monitoring in real time?

I'm looking for a keylogger/real-time SSH session monitor (if there is such util) for Slackware 10.1.

Kind of like a Terminal Server/VNC for SSH sessions. Where I don't have to 'cat log' or 'pico log', everytime.


Something like reading log files in real-time and seeing it update.

For What? :

This is for Administrative reasons. I want some people to ssh to my slackware 10.1 box, and I want to monitor them. Also, it's a part-time hobby of mine trying to be a Linux admin.

So far I tried Vlogger 2.1.1:

It's a great utility, but I don't know how to shut it off when I want it to. when I do ./vlogctrl unload, it says something like "rmmod: vlogger module is not loaded". When I go to the log file, I see it keeps on logging. I Wish I could turn it off when I want it to shut off. It also seems to crash my box causing a reboot and going through that disk check utility (when it does crash, vlogger won't run, so that's one way of shutting if off...heh). When I don't want it to shut it off, it works pretty well. Not sure if it produces output as if it were real time. (eg. vnc, terminal server)

I've been doing 'cat log' everytime to see the contents of the log file, which gets pretty cumbersome after a while,


I also tried using "TTYRPLD" but I couldn't get the patch to work (syntax was exactly the same in the instructions, but pertaining to my kernel) and it gave me some bogus error which I ignored, then later deleted the files, because I didn't know how to fix it.

Another program I looked into is LKL0.1.0, but it looks like it's used only for local purposes (correct me if im wrong).

Any other key/session logger I should try out?

Last edited by houler; 04-02-2005 at 12:18 PM.
Old 04-03-2005, 05:10 AM   #2
Registered: Aug 2004
Location: Norway
Distribution: Gentoo
Posts: 96

Rep: Reputation: 18
Not really a proggie, and you probably know about it, but I use tail -f /var/log/<logfile> to get a realtime view of the log...

Last edited by TylerD75; 04-03-2005 at 05:11 AM.
Old 04-06-2005, 10:21 PM   #3
LQ Addict
Registered: Dec 2001
Location: Brooklyn, NY
Distribution: *NIX
Posts: 3,704

Rep: Reputation: 56
You can also use roottail, it is a simple utility that will tail the log files and output them to your desktop, you can costumize it for diffrent log files and diffrent color scheme to alert you (visually) of what is going on log-wise.


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
SSH Session Monitoring? totalrockage Linux - Networking 1 04-08-2005 02:01 AM
Just discovered sensors - near-real-time hardware monitoring BrianK Linux - General 1 03-25-2004 07:23 PM
Real Time Equalizer st00 Linux - Software 1 03-20-2004 07:00 PM
real-time OS h/w Programming 11 01-24-2004 09:28 PM
Real Time Plot... DaFrEQ Linux - Software 0 08-27-2002 09:25 AM > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:46 AM.

Main Menu
Write for LQ is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration