LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-23-2003, 05:11 PM   #1
pembo13
Member
 
Registered: May 2003
Location: Caribbean
Distribution: Fedora Core2
Posts: 403

Rep: Reputation: 30
Queston about logs, related to security


Hello to all,

My question is, is it possible in RedHat 9.0 to consolidate and gather log data on and from:

-Iptables
-Apache
-Remote Logins (ftp, ssh, telnet, etc.)

Preferably as an alternative from goign into my System log where it gets mingled with not as important yet more inquired upon data. And also so that when ever i'm worried about a threat I can simply check there.

Please advise me whether such or similar alternative is possible.
Thank you.
 
Old 09-23-2003, 05:39 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
First of all you can have separate logs if
- the application supports it. for instance Apache allows you to write logs to separate files, or if
- the application can use what's called "custom log facilities". "man syslog_conf" for more, else if
- the application doesn't support the options above, then run a logparser like Swatch or Logwatch.
 
Old 09-23-2003, 05:51 PM   #3
pembo13
Member
 
Registered: May 2003
Location: Caribbean
Distribution: Fedora Core2
Posts: 403

Original Poster
Rep: Reputation: 30
Thanks for your response. I'm aware of the 1st and 3rd alternative you suggeested.

But my main request is to haev all these in one file if possible. I'd like to confirm that as a possbilty or not.

Thank you
 
Old 09-25-2003, 04:40 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
But my main request is to haev all these in one file if possible.
If the app supports (custom) log facilities, or supports PAM, yes.
Btw, you shouldnt use telnet tho.
 
Old 09-25-2003, 05:16 PM   #5
pembo13
Member
 
Registered: May 2003
Location: Caribbean
Distribution: Fedora Core2
Posts: 403

Original Poster
Rep: Reputation: 30
Ok cool,

Any suggestiosn for custom log facilities?

And thanks, I know about telnet, just wanted to exaggerate my list since I've enver used rlogin. I have telnet on, but the port is blocked to the outside.

Oh.....any suggestions also for PAM docs and how to's?

Thanks alot.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
a queston about SSH.. jsnch Linux - Security 7 07-05-2005 06:59 PM
mandrake 10 security logs chil326 Linux - Security 1 09-10-2004 06:25 PM
Which OS is best for network security related..... phr0stbyt3 Linux - Security 6 03-09-2004 09:42 PM
Security-Related Question gauge73 Linux - Security 3 02-15-2003 05:20 PM
math queston linuxhelp Linux - General 3 12-17-2002 02:36 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:34 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration