Boston Linux & Unix (BLU) Home | Calendar | Mail Lists | List Archives | Desktop SIG | Hardware Hacking SIG
Wiki | Flickr | PicasaWeb | Video | Maps & Directions | Installfests | Keysignings
Linux Cafe | Meeting Notes | Blog | Linux Links | Bling | About BLU

BLU Discuss list archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Interpreting audit logs?



 Have you tried splunk? 


On 10/28/07, Scott Ehrlich <[hidden email]> wrote: 
> Whenever I review audit logs, it is difficult for me to determine if an 
> account 
> was logged in at an usual day/time because there is no timestamp next to any 
> entry, at least as I interpret the format.   How, then do I properly and 
> successfully review the audit log entries based on a date/time stamp? 
> 
> Also, how can I filter out root and sudo account entries, displaying 
> everyone 
> else in audit? 
> 
> Thanks. 
> 
> Scott 
> 
> -- 
> This message has been scanned for viruses and 
> dangerous content by MailScanner, and is 
> believed to be clean. 
> 
> _______________________________________________ 
> Discuss mailing list 
> [hidden email] 
> http://lists.blu.org/mailman/listinfo/discuss
> 


BLU is a member of BostonUserGroups
BLU is a member of BostonUserGroups
We also thank MIT for the use of their facilities.

Valid HTML 4.01! Valid CSS!



Boston Linux & Unix / webmaster@blu.org