way to duplicate logs?

From: Bob Ababurko (ababurko_at_adelphia.net)
Date: 12/11/04

  • Next message: randall ehren: "Re: way to duplicate logs?"
    Date: Fri, 10 Dec 2004 19:22:46 -0500
    To: freebsd-security@freebsd.org
    
    

    Hello-

    I am bit confused here. I have just had some issues with my box and I
    am looking for some opinions. I just had been denied access to my
    box...supposedly from a memory shortage in reference to my NIC....more
    specifically, mbuf clusters exhausted. Now I am looking in my
    /var/log/messages for when this started and I notice a discrepancy in my
    logs. Now from where I am looking, I see time in the logs go backwards.
      You can see it as soon as the box is rebooted. Is there an
    explanation for this?

    bash-2.05b# tail -200 /var/log/messages
    Dec 7 19:01:03 additional su: bob to root on /dev/ttyp0
    Dec 8 10:19:35 additional su: bob to root on /dev/ttyp1
    Dec 8 18:09:24 additional su: BAD SU bob to root on /dev/ttyp0
    Dec 8 18:09:29 additional su: bob to root on /dev/ttyp0
    Dec 10 17:36:45 additional /kernel: All mbuf clusters exhausted, please
    see tuning(7).
    Dec 10 17:37:16 additional last message repeated 31 times
    Dec 10 17:39:17 additional last message repeated 121 times
    Dec 10 17:49:18 additional last message repeated 575 times
    Dec 10 17:59:19 additional last message repeated 545 times
    Dec 10 14:08:10 additional /kernel: Copyright (c) 1992-2003 The FreeBSD
    Project.
    Dec 10 14:08:10 additional /kernel: Copyright (c) 1979, 1980, 1983,
    1986, 1988, 1989, 1991, 1992, 1993, 1994
    Dec 10 14:08:10 additional /kernel: The Regents of the University of
    California. All rights reserved.
    Dec 10 14:08:10 additional /kernel: FreeBSD 4.9-RELEASE #0: Tue Nov 30
    01:20:25 AST 2004

    The date on the box should not have changed during that reboot, as it
    was in sync with ntp and still is.

    Also, is there a way to make more than one copy of these logs?....I am
    not sure how this is set up and but I would like to possibly have
    another set of logs in place so if someone is editing them, I can catch
    it. I know there is a chance that I may be overreacting., but just in
    case I want to know.

    Thanks,
    Bob
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: randall ehren: "Re: way to duplicate logs?"

    Relevant Pages

    • Re: some attack to fedora machine .
      ... I monitor my system for intrusion attacks ... Its very true as most informed people don't run as root, however you gotta be root to delete,modify, or even look at the logs. ... A sys admin will have to make trade offs to ensure people can get their work done but a saavy user can often get around things because its a trade off, ...
      (Fedora)
    • Re: some attack to fedora machine .
      ... I monitor my system for intrusion attacks ... the interesting information isn't owned by root at all but by the users. ... gotta be root to delete,modify, or even look at the logs. ... that it really depends on your perspective, user vs. sys admin. ...
      (Fedora)
    • Re: / filling up
      ... fuser gives a list of over 150 processes.. ... Bob Booth ... apparently filling up my root directory - holding on to an inode. ...
      (AIX-L)
    • Re: my log files-is there any problem
      ... >I am little concerned with these 2 means are these the normal entries ... >root 313 times isn't it too much. ... For the sendmail logs, nothing much to worry as a relaying attempt was ...
      (Fedora)
    • Re: Sarge system now refusing all login attempts
      ... > sudo attempt just hung forever. ... > sign on as either root or a user, at any prompt including VT's (which ... :-) try ls -lrt to see which logs were changed last (right after you do ... lilo prompt, type the lilo label followed by init=...), you get a root ...
      (Debian-User)