Also there is syslogd / syslog-ng / rsyslog whcih is being used to monitor syslog event and parse / make actions based on some rules

This prevents the need to maintain large log files on peer nodes. You can sign-in using OpenID credentials, or register a traditional username and password. However, it is beyond the scope of this implementation to describe all of the log files that you might want to inspect for your specific Solaris installation. Because log files often Look for entries where an unauthorized user has used the command inappropriately.

Solaris 10 System Logs

You can view which of these events are written to this directory (or any other log files) by reviewing the syslog config file /etc/syslog.conf. The input must come from the default console. For example, add the following entry to the /etc/user_attr file to grant user andy the ability to use the logadm command:andy::::profiles=Log Management Customizing System Message Logging You can capture additional error Then there's the annoying ones like wtmp that are binary.

The file is formatted as an ASCII text file and entries are usually one record per line with new entries appended to the end of the file. ABUSE: IPs or network segments from which we detect a stream of probes might be blocked for no less then 90 days. An entry is added to the sulog file every time the su command is executed. Solaris Messages Log Rotation The /var directory is thus often on a partition that is local to the system. All of the log files described below can be found in subdirectories under /var.

You can use the logadm command as superuser or by assuming an equivalent role (with Log Management rights). This task can be automated by using log analysis tools or a simple grep command.

compile ttyp1 0.35 secs Mon Mar 31 12:59

/var/adm/aculog This log keeps track of dial-out modems. By default, the /etc/syslog.conf file directs many system process messages to the /var/adm/messages files. Select one of the following steps: Disable the auxiliary console. # consadm -d devicenameor Disable the auxiliary console and remove it from the list of persistent auxiliary consoles.# consadm -p -d

Solaris 10 System Messages

The messages can be processed by client programs or by the Node Management Agent (NMA) on Solaris systems (NMA is not provided for Linux systems). If the message originated in the kernel, the kernel module name is displayed.

On the specified node, the messages are logged to a file called logfile, specified in the /etc/syslog.conf file. Look for unexpected system reboots.

SU 03/31 12:52 + pts/0 -root Look for failed su attempts. Process accounting must be turned on before this file is generated.

sysidtool Log The sysidtool log, found in /var/sadm/system/logs/sysidtool.log, is generated by the sysidtool tool suite, itself run automatically at system installation time or when the system is unconfigured with sys-unconfig. The following example shows sample lines from a default /etc/syslog.conf file.

Create a file: # touch myfile # chmod 777 myfile Log in to node A and examine myfile: # echo TEST myfile Examine the log files on the master node: #

Also look for unauthorized use of the dial-out modems Solaris includes Basic Security Module (BSM), but it is not turned on by default. For GUI you could use logzilla or splunk as free frameworks. To see what kind of messages go to /var/adm/messages and which go to /var/log/syslog, check /etc/syslog.conf

This message indicates which device has become the console by accepting a correct superuser password. But with these different growth rates, the tendency is to age some of them daily, others weekly, others yearly(!).

root-uucp SU 11/06 10:24 + pts/5 mcevoyg-root SU 11/06 10:44 + pts/6 mcevoyg-root SU 11/06 11:30 + pts/2 mcevoyg-root SU 11/07 14:07 + pts/2 mcevoyg-root SU 11/07 14:24 + pts/5 mcevoyg-root