LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 06-26-2014, 05:15 AM   #1
niraj.vara
LQ Newbie
 
Registered: May 2009
Posts: 27

Rep: Reputation: 0
Rootsh stopped log in /var/log/message


Hi

I have installed the rootsh and its working fine in centos 6.
But problem is its all the log stored in /var/log/messages and /var/log/rootsh/ also.

Now I want to stop the log in /var/log/messages when I run the command from root I am able to stop the log in /var/log/messages.

rootsh --no-syslog --- but same thing I want to do with normal user also.

for that logged into the normal user login and vi .bashrc and add the following line
rootsh --no-syslog

Its creating a 225 process

[root@testing ~]# ps aux | grep rootsh | wc -l
225

[root@testing ~]# ps aux | grep rootsh | less

code 16521 0.0 0.0 8256 832 pts/1 S+ 14:43 0:00 /usr/bin/rootsh --no-syslog
code 16535 0.0 0.0 8256 816 pts/3 S+ 14:43 0:00 /usr/bin/rootsh --no-syslog
code 16549 0.0 0.0 8256 820 pts/5 S+ 14:43 0:00 /usr/bin/rootsh --no-syslog
code 16563 0.0 0.0 8256 816 pts/6 S+ 14:43 0:00 /usr/bin/rootsh --no-syslog
code 16577 0.0 0.0 8256 820 pts/7 S+ 14:43 0:00 /usr/bin/rootsh --no-syslog
code 16591 0.0 0.0 8256 820 pts/8 S+ 14:43 0:00 /usr/bin/rootsh --no-syslog
code 16605 0.0 0.0 8256 820 pts/9 S+ 14:43 0:00 /usr/bin/rootsh --no-syslog
code 16619 0.0 0.0 8256 824 pts/10 S+ 14:43 0:00 /usr/bin/rootsh --no-syslog
code 16633 0.0 0.0 8256 820 pts/11 S+ 14:43 0:00 /usr/bin/rootsh --no-syslog
code 16647 0.0 0.0 8256 820 pts/12 S+ 14:43 0:00 /usr/bin/rootsh --no-sysl



Please help to solve this issue.
 
Old 06-27-2014, 05:11 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3590Reputation: 3590Reputation: 3590Reputation: 3590Reputation: 3590Reputation: 3590Reputation: 3590Reputation: 3590Reputation: 3590Reputation: 3590Reputation: 3590
Quote:
Originally Posted by niraj.vara View Post
for that logged into the normal user login and vi .bashrc and add the following line
rootsh --no-syslog

Its creating a 225 process

Code:
[root@testing ~]# ps aux | grep rootsh | wc -l
225
If you need continuous auditing don't set the shell in a users resource files but consider setting the users shell to rootsh globally. Also consider using the audit service in conjunction with rootsh. *BTW 'ps|grep' means you don't know 'pgrep' yet ;-p



Quote:
Originally Posted by niraj.vara View Post
But problem is its all the log stored in /var/log/messages and /var/log/rootsh/ also.

Now I want to stop the log in /var/log/messages when I run the command from root I am able to stop the log in /var/log/messages.
See if you can filter those messages out in /etc/(r)syslog(-ng).conf?
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] No /var/log/messages , syslog , kern.log -but cat /var/spool/octopussy/octo_fifo masuch Linux - Newbie 4 06-13-2012 09:05 PM
Can Samhain log my entries in /var/log/secure and /var/log/mesage to a central server abefroman Linux - Software 2 04-13-2008 05:13 PM
neat command not working azx_get_response timeout message in /var/log/message ninadshaha Red Hat 1 02-19-2008 03:32 PM
Strange Repeating Error message in /var/log/message lucktsm Linux - Security 2 10-27-2006 09:29 AM
/var/log/kern.log message dimkal Linux - Hardware 1 05-08-2004 07:57 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 10:27 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration