Suppose I wan't to know if a l33t haxxor tried to connect to my server, which logs do I need to watch often and which logs are less important? And I guess not every distro is the same, so what's the difference?
My guess there is some good hack (in the correct use of the word) to create a very logged system, I wonder if /g/ has a knowledgeable anon to tell how.
You need to ship your logs off the box for any real effectiveness. Otherwise watch wtmp btmp secure
>>54878960
I've heard every big company is does that without a question. Not sure if they use plain syslog for that.
>>54878936
Or you could just, you know, have a script that watches logs for intrusions...
>>54879012
No doubt about that, the question is how and which ones.
I'm guessing having a script doing a log abstract is a must.
Psad
>>54879025
https://duckduckgo.com/?q=script+watch+intrusions+linux&t=canonical&ia=web
Have fun kiddo
>>54879076
Are you mentally challenged?
>>54878936
/var/log/Auth
>>54879097
Sorry, wrong thread.