Re: How can I get an alert if someone views or changes syslog.

phn_at_icke-reklam.ipsec.nu
Date: 12/14/04

  • Next message: David Wagner: "Re: [Lit.] Buffer overruns"
    Date: Tue, 14 Dec 2004 20:40:24 +0000 (UTC)
    
    

    Liam <liamhearne@hotmail.com> wrote:
    > I need to be able to identify if an individual views, changes or tries
    > to delete the syslog on an AIX or Solaris server.

    > Is there anything freeware available to monitor & alert, or monitor &
    > call something else (Tivoli) to alert.

    > I know we could pick up on changes to the file, but I can't find
    > anything that spots someome viewing it..

    Why do you give the users authority to read or change the syslog files & directories
    in the first place ? If you fill your machines with users you
    don't trust and don't implement "normal admin precautions" - well
    you got yourself into trouble.

    As a last resort, direct syslogs to a different machine.

    -- 
    Peter Håkanson         
            IPSec  Sverige      ( At Gothenburg Riverside )
               Sorry about my e-mail address, but i'm trying to keep spam out,
    	   remove "icke-reklam" if you feel for mailing me. Thanx.
    

  • Next message: David Wagner: "Re: [Lit.] Buffer overruns"

    Relevant Pages

    • Re: Belkin not-real-firewall?
      ... Belkin) to review the syslog or Syslog Daemon (free will work with the ... use your wireless to attack other networks or machines on the Internet. ... we agree if you consider Windows Firewall to be a PFW. ... unless one prefers to make a full-time hobby of home network ...
      (comp.security.firewalls)
    • Re: Syslog quiestion
      ... Redhat Linux Advanced Server 4, machine running as a log server.It collects logs from Windows, Linux, Freebsd and Cisco machines. ... Is there any way to make syslog write logs in different files? ... install syslog-ng on your loghost and modify the init and logrotate script so they don't conflict ...
      (RedHat)
    • syslogd DDoS
      ... All syslog entries are forwarded to the server. ... other service which uses syslog) to all 800 machines asynchronously. ...
      (SunManagers)
    • Re: Syslog issue
      ... MP> Is there a GNU or commercial syslogd for AIX which could collect logs ... MP> from remote machines in such manner that each machine has it's own log ... I don't know whether such software exists, but -- since the host ... name is part of a syslog entry -- it'd be pretty easy to separate ...
      (comp.unix.aix)
    • Re: Syslot server setup
      ... I need to setup Sol, HPUX and Win machines as Syslog receptors from other sources. ... Then what need to be done on the remote machine side and source side. ...
      (comp.unix.questions)