cancel
Showing results for 
Search instead for 
Did you mean: 
Trevor
Starfighter Starfighter
Starfighter
  • 328 Views

Log File for Event Recording

Jump to solution

Audience:  RHCE and below

 

Question:  Which log file is used on a Linux system to record login 
authentication?

 

Question:  Which log file is used on a Linux system to record the 
usage of sudo?

 

 

Trevor "Red Hat Evangelist" Chandler
Labels (3)
1 Solution

Accepted Solutions
ric
Flight Engineer Flight Engineer
Flight Engineer
  • 296 Views

Hi, @Trevor 

Your Question: Which log file is used on a Linux system to record login
authentication?

My Answer: I would say /var/log/secure records login authentication:

Nov 9 14:22:15 rhel93 systemd[2290]: pam_unix(systemd-user:session): session opened for user ric(uid=1000) by (uid=0)

 

Your Question:  Which log file is used on a Linux system to record the usage of sudo?

My answer: I would say /var/log/secure also fulfills that requirement:

Nov 9 14:22:32 rhel93 sudo[3118]: pam_unix(sudo-i:session): session opened for user root(uid=0) by (uid=1000)

 

View solution in original post

2 Replies
ric
Flight Engineer Flight Engineer
Flight Engineer
  • 297 Views

Hi, @Trevor 

Your Question: Which log file is used on a Linux system to record login
authentication?

My Answer: I would say /var/log/secure records login authentication:

Nov 9 14:22:15 rhel93 systemd[2290]: pam_unix(systemd-user:session): session opened for user ric(uid=1000) by (uid=0)

 

Your Question:  Which log file is used on a Linux system to record the usage of sudo?

My answer: I would say /var/log/secure also fulfills that requirement:

Nov 9 14:22:32 rhel93 sudo[3118]: pam_unix(sudo-i:session): session opened for user root(uid=0) by (uid=1000)

 

Trevor
Starfighter Starfighter
Starfighter
  • 265 Views

And ric, I would say, you are 100% correct!!!

Thank you for your response!

Trevor "Red Hat Evangelist" Chandler
Join the discussion
You must log in to join this conversation.