Re: Missing auth.log

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



On 16/11/2018 00:43, Maxe wrote:
> Hi,
> 
> One of our systems, running ARCH Linux, was compromised (a
> non-privileged account, fortunately). But, we could not find
> /var/log/auth.log or similar for investigation. Does the journal keep
> track of login attempts?

Yes.

journalctl allows access to the logs from sshd, `journalctl -u sshd`

Also,

https://classic.startpage.com/do/search?q=arch+auth.log

points to:

https://wiki.archlinux.org/index.php/systemd#Facility

which says:

> * Show auth.log equivalent by filtering on syslog facility:
>
> # journalctl SYSLOG_FACILITY=10

which is worth a go.

Attachment: signature.asc
Description: OpenPGP digital signature


[Index of Archives]     [Linux Wireless]     [Linux Kernel]     [ATH6KL]     [Linux Bluetooth]     [Linux Netdev]     [Kernel Newbies]     [Share Photos]     [IDE]     [Security]     [Git]     [Netfilter]     [Bugtraq]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Linux ATA RAID]     [Samba]     [Device Mapper]

  Powered by Linux