Logcheck mi manda sempre questi messaggi:
codice:
Dec 18 14:59:50 vps sshd[8853]: lastlog_filetype: Couldn't stat /var/log/lastlog: No such file or directory
Dec 18 14:59:50 vps sshd[8853]: lastlog_openseek: /var/log/lastlog is not a file or directory!
Dec 18 14:59:50 vps sshd[8853]: lastlog_filetype: Couldn't stat /var/log/lastlog: No such file or directory
Dec 18 14:59:50 vps sshd[8853]: lastlog_openseek: /var/log/lastlog is not a file or directory!
Dec 18 14:59:50 vps sshd[8853]: (pam_unix) session opened for user root by root(uid=0)
Dec 18 15:00:01 vps CRON[8856]: (pam_unix) session opened for user root by (uid=0)
Dec 18 15:00:01 vps CRON[8858]: (pam_unix) session opened for user logcheck by (uid=0)
Dec 18 15:00:01 vps CRON[8856]: (pam_unix) session closed for user root
Mi spiegate il significato di queste righe?
E poi, quali altri log dovrei monitorare con logcheck? Attualmente monitoro (si può dire??) questi:
/var/log/syslog
/var/log/auth.log
/var/log/httpd/access_log
/var/log/httpd/error_log