12.07.2015 Views

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

520CHAPTER 25<strong>Linux</strong> Auditing SystemTABLE 25.3OptionContinuedDescription-te Show messages with timestamps equal to or before a givendate and time. The date and time formats depend on thesystem’s locale. Specify the time using a 24-hour clock suchas 23:00:00. For the en_US.UTF-8 locale, the date format isthe numerical equivalent of MM/DD/YY.-ts Show messages with timestamps equal to or after a giventime. Time and date format rules from the -te option apply.-tm Show messages with the specified terminal such as pts/6.Some executables such as cron and atd use the daemonname for the terminal.-ua Show messages whose user ID, effective user ID, or login UID(auid) matches the one specified.-ue Show messages whose effective user ID matches the onespecified.-ui Show messages whose user ID matches the one specified.-ul Show messages whose login UID matches the one specified.-v Display ausearch version.-w If a string to be matched is specified, only display results thatmatch the entire word.-x Show messages about an executable such as crond or sudo.The full path to the executable is provided after the exekeyword in the message such as “/bin/sudo” in Listing 25.8.Similar to aureport, the -i option can be used to make the output more human-readable,and the -if option can be used to provide an alternate log file in which tosearch.When the results are displayed, each record is separated by a line of four dashes, and atimestamp precedes each record as shown in Listing 25.8.LISTING 25.8Results from ausearch -x sudotime->Fri Dec 1 00:01:01 2006type=CRED_ACQ msg=audit(1145210930.022:2023): user pid=30718 uid=0auid=4294967295 msg=’PAM: setcred acct=root : exe=”/usr/bin/sudo”(hostname=?, addr=?, terminal=pts/3 res=success)’----time->Fri Dec 1 04:01:01 2006type=USER_START msg=audit(1145210930.022:2024): user pid=30718 uid=0auid=4294967295 msg=’PAM: session open acct=root : exe=”/usr/bin/sudo”(hostname=?, addr=?, terminal=pts/3 res=success)’----time->Fri Dec 1 04:42:01 2006

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!