zoukankan      html  css  js  c++  java
  • linux audit审计(8)--ausearch搜索audit日志文件

    ausearch这个工具,可以针对指定的事件来搜索audit日志文件。默认情况下,ausearch搜索/var/log/audit/audit.log这个文件。

    The ausearch utility allows you to search Audit log files for specific events. By default, ausearch searches the /var/log/audit/audit.log file. You can specify a different file using the ausearch options -if file_name command. Supplying multiple options in one ausearch command is equivalent to using the AND operator between field types and the ORoperator between multiple instances of the same field type.

     Using ausearch to Search Audit Log Files

    To search the /var/log/audit/audit.log file for failed login attempts, use the following command:
    ~]# ausearch --message USER_LOGIN --success no --interpret
    To search for all account, group, and role changes, use the following command:
    ~]# ausearch -m ADD_USER -m DEL_USER -m ADD_GROUP -m USER_CHAUTHTOK -m DEL_GROUP -m CHGRP_ID -m ROLE_ASSIGN -m ROLE_REMOVE -i
    To search for all logged actions performed by a certain user, using the user's login ID (auid), use the following command:
    ~]# ausearch -ua 1000 -i
    To search for all failed system calls from yesterday up until now, use the following command:
    ~]# ausearch --start yesterday --end now -m SYSCALL -sv no -i

    For a full listing of all ausearch options, see the ausearch(8) man page.

  • 相关阅读:
    JDBC批量删除某一用户下的触发器
    DWZ框架修改默认主页(转)
    JSP页面中的js方法遍历后台传来的自定义对象的List
    JDBC获取表注释
    你的显示方式安全么?JSTL中c:out标签介绍
    tomcat启动报错
    PPP协议体系的实现
    Linux下的虚拟Bridge实现
    三皇五帝
    贴近原理层的科技发展
  • 原文地址:https://www.cnblogs.com/xingmuxin/p/8872549.html
Copyright © 2011-2022 走看看