Différences
Ci-dessous, les différences entre deux révisions de la page.
Prochaine révision | Révision précédente | ||
elearning:workbooks:centos:8:junior:l114 [2021/06/02 15:34] – created admin | elearning:workbooks:centos:8:junior:l114 [2024/09/12 09:15] (Version actuelle) – admin | ||
---|---|---|---|
Ligne 1: | Ligne 1: | ||
~~PDF: | ~~PDF: | ||
+ | |||
+ | Version : **2024.01** | ||
Dernière mise-à-jour : ~~LASTMOD~~ | Dernière mise-à-jour : ~~LASTMOD~~ | ||
- | ======LCF208 | + | ======LCF508 |
=====Contenu du Module===== | =====Contenu du Module===== | ||
- | * **LCF208 | + | * **LCF508 |
- | * Contenu du Module | + | |
* Présentation | * Présentation | ||
* La Commande dmesg | * La Commande dmesg | ||
- | * Surveillance Sécuritaire | + | * LAB #1 - Surveillance Sécuritaire |
- | * La Commande last | + | * 1.1 - La Commande last |
- | * La Commande lastlog | + | * 1.2 - La Commande lastlog |
- | * La Commande lastb | + | * 1.3 - La Commande lastb |
- | * Le Fichier / | + | * 1.4 - Le Fichier / |
- | * Le fichier / | + | * 1.5 - Gestion des évènements audit |
- | * Gestion des événements audit | + | |
* auditd | * auditd | ||
* auditctl | * auditctl | ||
* audispd | * audispd | ||
- | | + | |
- | * La Commande aureport | + | * La Commande aureport |
- | * La Commande ausearch | + | * La Commande ausearch |
* Le fichier / | * Le fichier / | ||
* Applications | * Applications | ||
- | * rsyslog | + | * LAB #2 - rsyslog |
- | * Priorités | + | * 2.1 - Priorités |
- | * Sous-systèmes applicatifs | + | * 2.2 - Sous-systèmes applicatifs |
- | * / | + | * 2.3 - / |
* Modules | * Modules | ||
* Directives Globales | * Directives Globales | ||
Ligne 39: | Ligne 40: | ||
* n Sous-systèmes avec la même priorité | * n Sous-systèmes avec la même priorité | ||
* n Sélecteurs avec la même Action | * n Sélecteurs avec la même Action | ||
- | * La Commande logger | + | * LAB #3 - La Commande logger |
- | * La Commande logrotate | + | * LAB #4 - La Commande logrotate |
- | * La Journalisation avec journald | + | * LAB #5 - La Journalisation avec journald |
- | * Consultation des Journaux | + | * 5.1 - Consultation des Journaux |
- | * Consultation des Journaux d'une Application Spécifique | + | * 5.2 - Consultation des Journaux d'une Application Spécifique |
- | * Consultation des Journaux depuis le Dernier Démarrage | + | * 5.3 - Consultation des Journaux depuis le Dernier Démarrage |
- | * Consultation des Journaux d'une Priorité Spécifique | + | * 5.4 - Consultation des Journaux d'une Priorité Spécifique |
- | * Consultation des Journaux d'une Plage de Dates ou d' | + | * 5.5 - Consultation des Journaux d'une Plage de Dates ou d' |
- | * Consultation des Journaux en Live | + | * 5.6 - Consultation des Journaux en Live |
- | * Consultation des Journaux avec des Mots Clefs | + | * 5.7 - Consultation des Journaux avec des Mots Clefs |
=====Présentation===== | =====Présentation===== | ||
Ligne 54: | Ligne 55: | ||
La majorité des journaux du système et des applications se trouve dans le répertoire **/ | La majorité des journaux du système et des applications se trouve dans le répertoire **/ | ||
- | <WRAP center round important> | + | <WRAP center round important |
**Important** : Il est conseillé de déplacer le point de montage du répertoire **/ | **Important** : Il est conseillé de déplacer le point de montage du répertoire **/ | ||
</ | </ | ||
Ligne 63: | Ligne 64: | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
- | [ 0.000000] Initializing cgroup subsys cpuset | + | [ 0.000000] Linux version |
- | [ 0.000000] Initializing cgroup subsys cpu | + | CC)) #1 SMP Thu Apr 8 19:01:30 UTC 2021 |
- | [ 0.000000] Initializing cgroup subsys cpuacct | + | [ 0.000000] Command line: BOOT_IMAGE=(hd0, |
- | [ 0.000000] Linux version | + | shkernel=auto resume=UUID=c8bb3f47-d67f-4b21-b781-766899dc83d4 |
- | Wed May 13 10:06:09 UTC 2015 | + | [ 0.000000] |
- | [ 0.000000] Command line: BOOT_IMAGE=/ | + | [ 0.000000] x86/fpu: Supporting XSAVE feature 0x002: 'SSE registers' |
- | ernel=auto vconsole.font=latarcyrheb-sun16 rhgb quiet | + | [ 0.000000] x86/fpu: Supporting XSAVE feature 0x004: 'AVX registers' |
- | [ 0.000000] | + | [ 0.000000] x86/fpu: xstate_offset[2]: |
+ | [ 0.000000] x86/fpu: Enabled xstate features 0x7, context size is 832 bytes, using ' | ||
+ | [ 0.000000] | ||
[ 0.000000] BIOS-e820: [mem 0x0000000000000000-0x000000000009fbff] usable | [ 0.000000] BIOS-e820: [mem 0x0000000000000000-0x000000000009fbff] usable | ||
[ 0.000000] BIOS-e820: [mem 0x000000000009fc00-0x000000000009ffff] reserved | [ 0.000000] BIOS-e820: [mem 0x000000000009fc00-0x000000000009ffff] reserved | ||
[ 0.000000] BIOS-e820: [mem 0x00000000000f0000-0x00000000000fffff] reserved | [ 0.000000] BIOS-e820: [mem 0x00000000000f0000-0x00000000000fffff] reserved | ||
- | [ 0.000000] BIOS-e820: [mem 0x0000000000100000-0x000000005ffeffff] usable | + | [ 0.000000] BIOS-e820: [mem 0x0000000000100000-0x00000000dffeffff] usable |
- | [ 0.000000] BIOS-e820: [mem 0x000000005fff0000-0x000000005fffffff] ACPI data | + | [ 0.000000] BIOS-e820: [mem 0x00000000dfff0000-0x00000000dfffffff] ACPI data |
+ | [ 0.000000] BIOS-e820: [mem 0x00000000fec00000-0x00000000fec00fff] reserved | ||
+ | [ 0.000000] BIOS-e820: [mem 0x00000000fee00000-0x00000000fee00fff] reserved | ||
[ 0.000000] BIOS-e820: [mem 0x00000000fffc0000-0x00000000ffffffff] reserved | [ 0.000000] BIOS-e820: [mem 0x00000000fffc0000-0x00000000ffffffff] reserved | ||
+ | [ 0.000000] BIOS-e820: [mem 0x0000000100000000-0x000000011fffffff] usable | ||
[ 0.000000] NX (Execute Disable) protection: active | [ 0.000000] NX (Execute Disable) protection: active | ||
[ 0.000000] SMBIOS 2.5 present. | [ 0.000000] SMBIOS 2.5 present. | ||
[ 0.000000] DMI: innotek GmbH VirtualBox/ | [ 0.000000] DMI: innotek GmbH VirtualBox/ | ||
- | [ 0.000000] | + | [ 0.000000] |
- | [ 0.000000] e820: remove [mem 0x000a0000-0x000fffff] usable | + | |
- | [ 0.000000] No AGP bridge found | + | |
- | [ 0.000000] e820: last_pfn = 0x5fff0 max_arch_pfn = 0x400000000 | + | |
- | [ 0.000000] MTRR default type: uncachable | + | |
- | [ 0.000000] MTRR variable ranges disabled: | + | |
- | [ 0.000000] x86 PAT enabled: cpu 0, old 0x7040600070406, | + | |
- | [ 0.000000] CPU MTRRs all blank - virtualized system. | + | |
- | [ 0.000000] found SMP MP-table at [mem 0x0009fff0-0x0009ffff] mapped at [ffff88000009fff0] | + | |
- | [ 0.000000] Base memory trampoline at [ffff880000099000] 99000 size 24576 | + | |
- | [ 0.000000] init_memory_mapping: | + | |
- | [ 0.000000] | + | |
--More-- | --More-- | ||
</ | </ | ||
- | |||
- | ====Options de la Commande==== | ||
Les option de cette commande sont : | Les option de cette commande sont : | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
Usage: | Usage: | ||
dmesg [options] | dmesg [options] | ||
+ | |||
+ | Display or control the kernel ring buffer. | ||
Options: | Options: | ||
Ligne 110: | Ligne 105: | ||
-c, --read-clear | -c, --read-clear | ||
-D, --console-off | -D, --console-off | ||
- | -d, --show-delta | ||
- | -e, --reltime | ||
-E, --console-on | -E, --console-on | ||
-F, --file < | -F, --file < | ||
Ligne 117: | Ligne 110: | ||
-H, --human | -H, --human | ||
-k, --kernel | -k, --kernel | ||
- | -L, --color | + | -L, --color[=< |
+ | | ||
-l, --level < | -l, --level < | ||
-n, --console-level < | -n, --console-level < | ||
-P, --nopager | -P, --nopager | ||
+ | -p, --force-prefix | ||
-r, --raw print the raw message buffer | -r, --raw print the raw message buffer | ||
-S, --syslog | -S, --syslog | ||
-s, --buffer-size < | -s, --buffer-size < | ||
- | -T, --ctime | ||
- | | ||
- | -t, --notime | ||
-u, --userspace | -u, --userspace | ||
-w, --follow | -w, --follow | ||
-x, --decode | -x, --decode | ||
+ | -d, --show-delta | ||
+ | -e, --reltime | ||
+ | -T, --ctime | ||
+ | -t, --notime | ||
+ | | ||
+ | | ||
+ | Suspending/ | ||
- | -h, --help | + | -h, --help |
- | -V, --version | + | -V, --version |
Supported log facilities: | Supported log facilities: | ||
Ligne 154: | Ligne 153: | ||
debug - debug-level messages | debug - debug-level messages | ||
- | + | For more details see dmesg(1). | |
- | For more details see dmesg(q). | + | |
</ | </ | ||
- | =====Surveillance Sécuritaire===== | + | =====LAB #1 - Surveillance Sécuritaire===== |
- | ====La Commande last==== | + | ====1.1 - La Commande last==== |
Cette commande indique les dates et heures des connexions des utilisateurs à partir du contenu du fichier **/ | Cette commande indique les dates et heures des connexions des utilisateurs à partir du contenu du fichier **/ | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
- | trainee | + | trainee |
- | trainee | + | reboot |
- | (unknown :0 : | + | trainee |
- | reboot | + | trainee |
- | trainee | + | reboot |
- | trainee | + | trainee |
- | trainee | + | reboot |
- | trainee | + | trainee |
- | trainee | + | reboot |
- | trainee | + | trainee |
- | (unknown :0 : | + | trainee |
- | reboot | + | reboot |
- | trainee | + | trainee |
- | trainee | + | trainee |
- | trainee | + | trainee |
- | (unknown :0 : | + | trainee |
- | reboot | + | reboot |
- | trainee | + | trainee |
- | trainee | + | trainee |
- | (unknown :0 : | + | trainee |
- | reboot | + | trainee |
- | trainee | + | trainee |
- | trainee | + | trainee |
- | (unknown :0 : | + | trainee |
- | reboot | + | trainee |
- | trainee | + | trainee |
- | trainee | + | reboot |
- | (unknown :0 : | + | trainee |
- | reboot | + | reboot |
- | trainee | + | trainee |
- | (unknown :0 : | + | reboot |
- | reboot | + | reboot |
- | (unknown :0 : | + | |
- | reboot | + | |
- | trainee | + | |
- | trainee | + | |
- | trainee | + | |
- | trainee | + | |
- | trainee | + | |
- | trainee | + | |
- | (unknown :0 : | + | |
- | reboot | + | |
- | trainee | + | |
- | trainee | + | |
- | trainee | + | |
- | (unknown :0 : | + | |
- | reboot | + | |
- | trainee | + | |
- | trainee | + | |
- | trainee | + | |
- | trainee | + | |
- | trainee | + | |
- | trainee | + | |
- | (unknown :0 : | + | |
- | reboot | + | |
- | trainee | + | |
- | trainee | + | |
- | (unknown :0 : | + | |
- | reboot | + | |
- | trainee | + | |
- | trainee | + | |
- | (unknown :0 : | + | |
- | reboot | + | |
- | trainee | + | |
- | (unknown :0 : | + | |
- | reboot | + | |
- | wtmp begins | + | wtmp begins |
</ | </ | ||
- | |||
- | ===Options de la Commande=== | ||
Les option de cette commande sont : | Les option de cette commande sont : | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
- | last: invalid option -- ' | + | |
- | Usage: last [-num | -n num] [-f file] [-t YYYYMMDDHHMMSS] [-R] [-adioxFw] [username..] [tty..] | + | Usage: |
+ | last [options] [<username>...] [<tty>...] | ||
+ | |||
+ | Show a listing of last logged in users. | ||
+ | |||
+ | Options: | ||
+ | | ||
+ | -a, --hostlast | ||
+ | -d, --dns translate the IP number back into a hostname | ||
+ | -f, --file < | ||
+ | -F, --fulltimes | ||
+ | -i, --ip | ||
+ | -n, --limit < | ||
+ | -R, --nohostname | ||
+ | -s, --since < | ||
+ | -t, --until < | ||
+ | -p, --present < | ||
+ | -w, --fullnames | ||
+ | -x, --system | ||
+ | | ||
+ | | ||
+ | |||
+ | -h, --help | ||
+ | -V, --version | ||
+ | |||
+ | For more details see last(1). | ||
</ | </ | ||
- | ====La Commande lastlog==== | + | ====1.2 - La Commande lastlog==== |
Cette commande indique les dates et heures de la connexion au système la plus récente des utilisateurs : | Cette commande indique les dates et heures de la connexion au système la plus récente des utilisateurs : | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
Username | Username | ||
- | root | + | root |
bin **Never logged in** | bin **Never logged in** | ||
daemon | daemon | ||
Ligne 267: | Ligne 254: | ||
nobody | nobody | ||
dbus | dbus | ||
+ | systemd-coredump | ||
+ | systemd-resolve | ||
+ | tss **Never logged in** | ||
polkitd | polkitd | ||
unbound | unbound | ||
- | colord | ||
- | usbmuxd | ||
- | avahi **Never logged in** | ||
- | avahi-autoipd | ||
- | saslauth | ||
- | qemu | ||
libstoragemgmt | libstoragemgmt | ||
+ | cockpit-ws | ||
+ | sssd | ||
+ | setroubleshoot | ||
+ | sshd | ||
+ | chrony | ||
+ | tcpdump | ||
+ | trainee | ||
+ | cockpit-wsinstance | ||
+ | rngd | ||
+ | gluster | ||
+ | qemu | ||
rpc **Never logged in** | rpc **Never logged in** | ||
rpcuser | rpcuser | ||
- | nfsnobody | + | saslauth |
- | rtkit | + | |
radvd **Never logged in** | radvd **Never logged in** | ||
- | ntp | + | dnsmasq |
- | chrony | + | fenestros2 |
- | abrt | + | fenestros1 |
- | pulse **Never logged in** | + | apache |
- | gdm :0 Wed Oct 28 09:41:03 +0100 2015 | + | |
- | gnome-initial-setup | + | |
- | postfix | + | |
- | sshd | + | |
- | tcpdump | + | |
- | trainee | + | |
- | vboxadd | + | |
- | tss | + | |
</ | </ | ||
- | |||
- | ===Options de la Commande=== | ||
Les option de cette commande sont : | Les option de cette commande sont : | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
Usage: lastlog [options] | Usage: lastlog [options] | ||
Options: | Options: | ||
-b, --before DAYS print only lastlog records older than DAYS | -b, --before DAYS print only lastlog records older than DAYS | ||
+ | -C, --clear | ||
-h, --help | -h, --help | ||
-R, --root CHROOT_DIR | -R, --root CHROOT_DIR | ||
+ | -S, --set set lastlog record to current time (usable only with -u) | ||
-t, --time DAYS print only lastlog records more recent than DAYS | -t, --time DAYS print only lastlog records more recent than DAYS | ||
-u, --user LOGIN print lastlog record of the specified LOGIN | -u, --user LOGIN print lastlog record of the specified LOGIN | ||
</ | </ | ||
- | ====La Commande lastb==== | + | ====1.3 - La Commande lastb==== |
- | Cette commande indique les dates et heures des connexions | + | Cette commande indique les dates et heures des connexions |
< | < | ||
- | [root@centos7 | + | [root@centos8 |
- | trainee | + | trainee |
- | trainee | + | trainee |
- | root | + | trqinee |
- | trainee | + | |
- | btmp begins Thu Oct 15 15:01:57 2015 | + | btmp begins Thu Jun 3 09:51:07 2021 |
</ | </ | ||
- | |||
- | ===Options de la Commande=== | ||
Les options de cette commande sont : | Les options de cette commande sont : | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
- | lastb: invalid option -- ' | + | |
- | Usage: lastb [-num | -n num] [-f file] [-t YYYYMMDDHHMMSS] [-R] [-adioxFw] [username..] [tty..] | + | Usage: |
+ | lastb [options] [<username>...] [<tty>...] | ||
+ | |||
+ | Show a listing of last logged in users. | ||
+ | |||
+ | Options: | ||
+ | | ||
+ | -a, --hostlast | ||
+ | -d, --dns translate the IP number back into a hostname | ||
+ | -f, --file < | ||
+ | -F, --fulltimes | ||
+ | -i, --ip | ||
+ | -n, --limit < | ||
+ | -R, --nohostname | ||
+ | -s, --since < | ||
+ | -t, --until < | ||
+ | -p, --present < | ||
+ | -w, --fullnames | ||
+ | -x, --system | ||
+ | | ||
+ | | ||
+ | |||
+ | -h, --help | ||
+ | -V, --version | ||
+ | |||
+ | For more details see last(1). | ||
</ | </ | ||
- | ====Le Fichier / | + | ====1.4 - Le Fichier / |
Sous RHEL/CentOS ce fichier contient la journalisation des opérations de gestion des authentifications : | Sous RHEL/CentOS ce fichier contient la journalisation des opérations de gestion des authentifications : | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
- | Oct 27 17:31:02 centos7 polkitd[625]: <no filename> | + | Jun 3 09:01:20 centos8 sshd[905]: Server listening on :: port 22. |
- | Oct 27 17:31:02 centos7 polkitd[625]: Error evaluating authorization rules | + | Jun 3 09:01:39 centos8 sshd[1585]: Accepted |
- | Oct 27 17:48:27 centos7 gdm-password]: gkr-pam: unlocked login keyring | + | Jun 3 09:01:39 centos8 systemd[1590]: pam_unix(systemd-user:session): session opened for user trainee by (uid=0) |
- | Oct 28 09:40:43 centos7 polkitd[586]: | + | Jun 3 09:01:39 centos8 sshd[1585]: pam_unix(sshd:session): session opened for user trainee by (uid=0) |
- | Oct 28 09:40:43 centos7 polkitd[586]: Loading rules from directory / | + | Jun 3 09:01:46 centos8 su[1627]: pam_systemd(su-l:session): Cannot create session: Already running in a session or user slice |
- | Oct 28 09:40:44 centos7 polkitd[586]: | + | Jun 3 09:01:46 centos8 su[1627]: pam_unix(su-l:session): session opened for user root by trainee(uid=1000) |
- | Oct 28 09:40:44 centos7 polkitd[586]: Acquired the name org.freedesktop.PolicyKit1 on the system bus | + | Jun 3 09:51:05 centos8 login[1158]: pam_unix(login:auth): check pass; user unknown |
- | Oct 28 09:40:55 centos7 sshd[1217]: Server listening on 0.0.0.0 port 22. | + | Jun 3 09:51:05 centos8 login[1158]: pam_unix(login:auth): authentication failure; logname=LOGIN |
- | Oct 28 09:40:55 centos7 sshd[1217]: Server listening on :: port 22. | + | Jun 3 09:51:07 centos8 login[1158]: FAILED LOGIN 1 FROM tty1 FOR trqinee, |
- | Oct 28 09:41:03 centos7 gdm-launch-environment]: pam_unix(gdm-launch-environment:session): session opened for user gdm by (uid=0) | + | Jun 3 09:51:18 centos8 unix_chkpwd[2400]: |
- | Oct 28 09:41:18 centos7 polkitd[586]: Registered Authentication Agent for unix-session: | + | Jun 3 09:51:18 centos8 login[1158]: pam_unix(login:auth): authentication failure; logname=LOGIN uid=0 euid=0 tty=tty1 ruser= rhost= |
- | Oct 28 09:41:31 centos7 gdm-password]: pam_unix(gdm-password:session): session opened for user trainee by (unknown)(uid=0) | + | Jun 3 09:51:20 centos8 login[1158]: FAILED LOGIN 2 FROM tty1 FOR trainee, Authentication failure |
- | Oct 28 09:41:32 centos7 polkitd[586]: Unregistered | + | Jun 3 09:51:45 centos8 login[1158]: pam_unix(login:auth): check pass; user unknown |
- | Oct 28 09:41:43 centos7 polkitd[586]: Registered Authentication Agent for unix-session: | + | Jun 3 09:51:45 centos8 login[1158]: |
- | Oct 28 09:48:43 centos7 su: pam_unix(su-l:session): session opened for user root by trainee(uid=1000) | + | Jun 3 09:51:47 centos8 login[1158]: |
</ | </ | ||
- | =====Le fichier /var/log/audit/audit.log===== | + | ====1.5 - Gestion des Evénements |
- | Ce fichier contient les messages du système d' | + | ===Le fichier / |
+ | |||
+ | Ce fichier contient les messages du système d' | ||
* des appels système, | * des appels système, | ||
Ligne 369: | Ligne 379: | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
- | type=CRED_ACQ | + | type=PROCTITLE |
- | type=LOGIN msg=audit(1443519601.488: | + | type=USER_START msg=audit(1622728321.901:456): pid=2420 uid=0 auid=1000 ses=53 subj=system_u: |
- | type=USER_START msg=audit(1443519601.563:403): pid=3596 uid=0 auid=0 ses=3 subj=system_u: | + | type=CRED_REFR msg=audit(1622728321.902:457): pid=2420 uid=0 auid=1000 ses=53 subj=system_u: |
- | type=CRED_REFR msg=audit(1443519601.568:404): pid=3596 uid=0 auid=0 ses=3 subj=system_u: | + | type=CRED_DISP msg=audit(1622728321.908:458): pid=2420 uid=0 auid=1000 ses=53 subj=system_u: |
- | type=CRED_DISP msg=audit(1443519601.646:405): pid=3596 uid=0 auid=0 ses=3 subj=system_u: | + | type=USER_END msg=audit(1622728321.910:459): pid=2420 uid=0 auid=1000 ses=53 subj=system_u: |
- | type=USER_END msg=audit(1443519601.654:406): pid=3596 uid=0 auid=0 ses=3 subj=system_u: | + | type=SERVICE_STOP |
- | type=SERVICE_START | + | type=USER_ACCT |
- | type=SERVICE_STOP | + | type=CRED_ACQ |
- | type=SERVICE_START | + | type=LOGIN msg=audit(1622728381.954:463): pid=2439 uid=0 subj=system_u:system_r:crond_t: |
- | type=USER_AUTH | + | type=SYSCALL |
- | type=USER_ACCT | + | type=PROCTITLE |
- | type=CRED_ACQ | + | type=USER_START msg=audit(1622728381.960: |
- | type=USER_START | + | type=CRED_REFR |
- | type=SERVICE_STOP | + | type=CRED_DISP |
- | type=SERVICE_STOP | + | type=USER_END |
</ | </ | ||
- | ====Gestion des évènements audit==== | + | La gestion des événements |
- | + | ||
- | La gestion des évènements | + | |
===auditd=== | ===auditd=== | ||
Ligne 396: | Ligne 404: | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
# | # | ||
# This file controls the configuration of the audit daemon | # This file controls the configuration of the audit daemon | ||
# | # | ||
+ | local_events = yes | ||
+ | write_logs = yes | ||
log_file = / | log_file = / | ||
- | log_format = RAW | ||
log_group = root | log_group = root | ||
- | priority_boost | + | log_format |
- | flush = INCREMENTAL | + | flush = INCREMENTAL_ASYNC |
- | freq = 20 | + | freq = 50 |
+ | max_log_file = 8 | ||
num_logs = 5 | num_logs = 5 | ||
- | disp_qos | + | priority_boost |
- | dispatcher = / | + | |
name_format = NONE | name_format = NONE | ||
##name = mydomain | ##name = mydomain | ||
- | max_log_file = 6 | ||
max_log_file_action = ROTATE | max_log_file_action = ROTATE | ||
space_left = 75 | space_left = 75 | ||
space_left_action = SYSLOG | space_left_action = SYSLOG | ||
+ | verify_email = yes | ||
action_mail_acct = root | action_mail_acct = root | ||
admin_space_left = 50 | admin_space_left = 50 | ||
Ligne 421: | Ligne 430: | ||
disk_full_action = SUSPEND | disk_full_action = SUSPEND | ||
disk_error_action = SUSPEND | disk_error_action = SUSPEND | ||
- | ## | + | use_libwrap = yes |
+ | ## | ||
tcp_listen_queue = 5 | tcp_listen_queue = 5 | ||
tcp_max_per_addr = 1 | tcp_max_per_addr = 1 | ||
## | ## | ||
tcp_client_max_idle = 0 | tcp_client_max_idle = 0 | ||
- | enable_krb5 | + | transport |
krb5_principal = auditd | krb5_principal = auditd | ||
## | ## | ||
+ | distribute_network = no | ||
+ | q_depth = 400 | ||
+ | overflow_action = SYSLOG | ||
+ | max_restarts = 10 | ||
+ | plugin_dir = / | ||
</ | </ | ||
- | |||
- | ==Options de la Commande== | ||
Les option de cette commande sont : | Les option de cette commande sont : | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
- | auditd: | + | auditd: |
- | Usage: auditd [-f] [-l] [-n] [-s disable|enable|nochange] | + | Usage: auditd [-f] [-l] [-n] [-s disable|enable|nochange] [-c < |
</ | </ | ||
Ligne 446: | Ligne 459: | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
## This file is automatically generated from / | ## This file is automatically generated from / | ||
-D | -D | ||
- | -b 320 | + | -b 8192 |
+ | -f 1 | ||
+ | --backlog_wait_time 60000 | ||
</ | </ | ||
- | |||
- | ==Options de la Commande== | ||
Les options de cette commande sont : | Les options de cette commande sont : | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
usage: auditctl [options] | usage: auditctl [options] | ||
-a < | -a < | ||
Ligne 492: | Ligne 505: | ||
-w < | -w < | ||
-W < | -W < | ||
- | --loginuid-immutable | + | --loginuid-immutable |
- | --backlog_wait_time | + | --backlog_wait_time |
+ | --reset-lost | ||
</ | </ | ||
- | ===audispd=== | + | ===La consultation des événements audit=== |
- | Cet exécutable est responsable de la distribution | + | La consultation |
- | < | + | ==La Commande aureport== |
- | [root@centos7 ~]# ls / | + | |
- | af_unix.conf | + | |
- | </ | + | |
- | + | ||
- | Le contenu de ces fichiers suit un format précis : | + | |
- | + | ||
- | < | + | |
- | [root@centos7 ~]# cat / | + | |
- | # This file controls the configuration of the syslog plugin. | + | |
- | # It simply takes events and writes them to syslog. The | + | |
- | # arguments provided can be the default priority that you | + | |
- | # want the events written with. And optionally, you can give | + | |
- | # a second argument indicating the facility that you want events | + | |
- | # logged to. Valid options are LOG_LOCAL0 through 7. | + | |
- | + | ||
- | active = no | + | |
- | direction = out | + | |
- | path = builtin_syslog | + | |
- | type = builtin | + | |
- | args = LOG_INFO | + | |
- | format = string | + | |
- | </ | + | |
- | + | ||
- | ====La consultation des évènements audit==== | + | |
- | + | ||
- | La consultation des évènements audit se fait en utilisant les commandes **ausearch** et **aureport** : | + | |
- | + | ||
- | ===La Commande aureport=== | + | |
Cette commande est utilisée pour générer des rapports : | Cette commande est utilisée pour générer des rapports : | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
Summary Report | Summary Report | ||
====================== | ====================== | ||
- | Range of time in logs: 03/08/2015 14:23:34.354 - 09/29/2015 11:44:11.018 | + | Range of time in logs: 05/08/2020 08:13:52.320 - 06/03/2021 10:20:02.028 |
- | Selected time for report: | + | Selected time for report: |
- | Number of changes in configuration: | + | Number of changes in configuration: |
- | Number of changes to accounts, groups, or roles: | + | Number of changes to accounts, groups, or roles: |
- | Number of logins: | + | Number of logins: |
- | Number of failed logins: | + | Number of failed logins: |
- | Number of authentications: | + | Number of authentications: |
- | Number of failed authentications: | + | Number of failed authentications: |
Number of users: 3 | Number of users: 3 | ||
- | Number of terminals: | + | Number of terminals: |
- | Number of host names: | + | Number of host names: |
- | Number of executables: | + | Number of executables: |
- | Number of commands: | + | Number of commands: |
- | Number of files: | + | Number of files: |
- | Number of AVC' | + | Number of AVC' |
- | Number of MAC events: | + | Number of MAC events: |
Number of failed syscalls: 0 | Number of failed syscalls: 0 | ||
- | Number of anomaly events: | + | Number of anomaly events: |
Number of responses to anomaly events: 0 | Number of responses to anomaly events: 0 | ||
- | Number of crypto events: | + | Number of crypto events: |
Number of integrity events: 0 | Number of integrity events: 0 | ||
Number of virt events: 0 | Number of virt events: 0 | ||
Number of keys: 0 | Number of keys: 0 | ||
- | Number of process IDs: 1414 | + | Number of process IDs: 616 |
- | Number of events: | + | Number of events: |
</ | </ | ||
- | |||
- | ==Options de la Commande== | ||
Les options de cette commande sont : | Les options de cette commande sont : | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
usage: aureport [options] | usage: aureport [options] | ||
-a, | -a, | ||
Ligne 609: | Ligne 593: | ||
</ | </ | ||
- | ===La Commande ausearch=== | + | ==La Commande ausearch== |
- | Cette commande est utilisée pour rechercher des évènements. Par exemple, pour rechercher les évènements | + | Cette commande est utilisée pour rechercher des événements. Par exemple, pour rechercher les événements |
< | < | ||
- | [root@centos7 | + | [root@centos8 |
---- | ---- | ||
- | time->Sun Mar 8 14:26:43 2015 | + | time->Tue Sep 1 11:05:28 2020 |
- | type=ANOM_ABEND | + | type=USER_AUTH |
- | comm="yelp" | + | omain addr=? terminal=pts/ |
---- | ---- | ||
- | time->Sun Mar 8 14:36:33 2015 | + | time->Tue Sep 1 11:05:28 2020 |
- | type=USER_AUTH | + | type=USER_ACCT |
- | :authentication | + | ost.localdomain |
---- | ---- | ||
- | time->Sun Mar 8 14:36:33 2015 | + | time->Tue Sep 1 11:05:28 2020 |
- | type=USER_ACCT | + | type=CRED_ACQ |
- | :accounting | + | dr=? terminal=pts/ |
---- | ---- | ||
- | time->Sun Mar 8 14:36:33 2015 | + | time->Tue Sep 1 11:05:28 2020 |
- | type=CRED_ACQ | + | type=USER_START |
- | setcred | + | , |
---- | ---- | ||
- | time->Sun Mar 8 14:36:33 2015 | + | time->Tue Sep 1 11:10:13 2020 |
- | type=USER_START | + | type=USER_END |
- | M:session_open | + | pam_xauth |
---- | ---- | ||
- | time->Mon Jun | + | time->Tue Sep |
- | type=USER_AUTH | + | type=CRED_DISP |
- | authentication | + | ddr=? terminal=pts/ |
---- | ---- | ||
- | time-> | + | time-> |
- | type=USER_ACCT msg=audit(1433172011.330:506): pid=466 uid=1000 auid=1000 ses=1 subj=unconfined_u: | + | type=USER_AUTH msg=audit(1618847281.847: |
- | accounting acct=" | + | ng.loc addr=? terminal=pts/ |
+ | ---- | ||
+ | time-> | ||
+ | type=USER_ACCT msg=audit(1618847281.847:78): pid=1768 uid=1000 auid=1000 ses=1 subj=unconfined_u: | ||
+ | 8.ittraining.loc addr=? terminal=pts/ | ||
+ | ---- | ||
+ | time-> | ||
+ | type=CRED_ACQ msg=audit(1618847281.847: | ||
+ | ddr=? terminal=pts/ | ||
+ | ---- | ||
+ | time-> | ||
+ | type=USER_START msg=audit(1618847281.883: | ||
+ | ,pam_xauth acct=" | ||
+ | ---- | ||
+ | time-> | ||
+ | type=USER_END msg=audit(1618848279.544: | ||
+ | ,pam_xauth acct=" | ||
+ | ---- | ||
+ | time-> | ||
+ | type=CRED_DISP msg=audit(1618848279.544: | ||
+ | | ||
+ | ---- | ||
+ | time-> | ||
+ | type=USER_AUTH msg=audit(1618848357.204: | ||
+ | addr=? terminal=pts/ | ||
+ | ---- | ||
+ | time-> | ||
+ | type=USER_AUTH msg=audit(1618848363.134: | ||
+ | ng.loc | ||
---- | ---- | ||
--More-- | --More-- | ||
</ | </ | ||
- | |||
- | ==Options de la Commande== | ||
Les options de cette commande sont : | Les options de cette commande sont : | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
usage: ausearch [options] | usage: ausearch [options] | ||
-a,--event <Audit event id> | -a,--event <Audit event id> | ||
Ligne 661: | Ligne 671: | ||
-e, | -e, | ||
-f, | -f, | ||
+ | --format [raw|default|interpret|csv|text] results format options | ||
-ga, | -ga, | ||
-ge, | -ge, | ||
Ligne 703: | Ligne 714: | ||
</ | </ | ||
- | <WRAP center round important> | + | <WRAP center round important |
**Important** : Pour plus d' | **Important** : Pour plus d' | ||
</ | </ | ||
Ligne 712: | Ligne 723: | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
- | Sep 29 11:40:01 centos7 | + | Jun 3 10:15:01 centos8 |
- | Sep 29 11:40:01 centos7 | + | Jun 3 10:16:01 centos8 |
- | Sep 29 11:40:01 centos7 | + | Jun 3 10:16:01 centos8 |
- | Sep 29 11:40:09 centos7 | + | Jun 3 10:17:01 centos8 systemd[1]: Started Session |
- | Sep 29 11:40:10 centos7 | + | Jun 3 10:17:01 centos8 |
- | Sep 29 11:42:17 centos7 dbus-daemon: dbus[526]: [system] Activating via systemd: service name=' | + | Jun 3 10:18:01 centos8 |
- | Sep 29 11:42:17 centos7 dbus[526]: [system] Activating via systemd: service name=' | + | Jun 3 10:18:01 centos8 systemd[1]: session-79.scope: Succeeded. |
- | Sep 29 11:42:17 centos7 | + | Jun 3 10:19:01 centos8 systemd[1]: Started Session 80 of user trainee. |
- | Sep 29 11:42:17 centos7 dbus-daemon: | + | Jun 3 10:19:01 centos8 |
- | Sep 29 11:42:17 centos7 dbus[526]: [system] Successfully activated service 'net.reactivated.Fprint' | + | Jun 3 10:20:02 centos8 systemd[1]: Started Session 81 of user trainee. |
- | Sep 29 11:42:17 centos7 | + | Jun 3 10:20:02 centos8 systemd[1]: session-81.scope: Succeeded. |
- | Sep 29 11:42:17 centos7 fprintd: Launching FprintObject | + | Jun 3 10:21:01 centos8 |
- | Sep 29 11:42:17 centos7 fprintd: ** Message: D-Bus service launched with name: net.reactivated.Fprint | + | Jun 3 10:21:01 centos8 systemd[1]: session-82.scope: Succeeded. |
- | Sep 29 11:42:17 centos7 fprintd: ** Message: entering main loop | + | Jun 3 10:22:01 centos8 systemd[1]: Started Session 83 of user trainee. |
- | Sep 29 11:42:20 centos7 su: (to root) trainee on pts/0 | + | Jun 3 10:22:01 centos8 systemd[1]: session-83.scope: |
</ | </ | ||
Ligne 740: | Ligne 751: | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
- | total 1332 | + | total 2448 |
- | drwxr-xr-x. 2 root | + | drwxr-xr-x. 2 root |
- | drwxr-x---. 2 root | + | drwx------. 2 root |
- | -rw-r--r--. 1 root | + | -rw-------. 1 root |
- | -rw-------. 1 root utmp 0 Jun 4 09:54 btmp | + | -rw-------. 1 root root 19710 Apr 19 13:44 boot.log-20210419 |
- | drwxr-xr-x. 2 chrony chrony | + | -rw-------. 1 root |
- | -rw-r--r--. 1 root | + | -rw-------. 1 root |
- | -rw-r--r--. 1 root | + | -rw-------. 1 root |
- | -rw-r--r--. 1 root | + | -rw-rw----. 1 root utmp 1152 Jun 3 09:51 btmp |
- | drwxr-xr-x. 2 lp | + | -rw-rw----. 1 root utmp 384 May 26 10:37 btmp-20210602 |
- | -rw-r--r--. 1 root root 33323 Sep 29 11:25 dmesg | + | drwxr-xr-x. 2 chrony chrony |
- | -rw-r--r--. 1 root root 33322 Sep 28 14:46 dmesg.old | + | -rw-------. 1 root |
- | drwx--x--x. 2 root | + | -rw-------. 1 root |
- | drwxr-xr-x. 2 root | + | -rw-------. |
- | -rw-------. 1 root | + | -rw-------. 1 root |
- | -rw-r--r--. 1 root | + | -rw-------. 1 root |
- | drwx------. | + | -rw-r--r--. 1 root |
- | -rw-------. 1 root | + | -rw-------. 1 root |
- | -rw-------. 1 root | + | -rw-------. 1 root |
- | -rw-------. 1 root | + | -rw-r--r--. 1 root |
- | -rw-------. 1 root | + | -rw-r--r--. 1 root |
- | -rw-------. 1 root | + | -rw-r-----. |
- | -rw-------. 1 root | + | drwxr-xr-x. 2 root |
- | drwxr-xr-x. 3 root | + | -rw-------. 1 root |
- | -rw-r--r--. 1 root | + | -rw-r--r--. 1 root |
- | drwx------. | + | -rw-------. 1 root |
- | drwxr-xr-x. 2 root | + | -rw-------. 1 root |
- | drwxr-xr-x. 2 root | + | -rw-rw-r--. 1 root |
- | drwx------. | + | drwx------. |
- | -rw-------. 1 root | + | -rw-------. |
- | -rw-------. 1 root | + | -rw-------. 1 root |
- | -rw-------. | + | -rw-------. 1 root |
- | drwx------. | + | -rw-------. 1 root |
- | -rw-------. 1 root | + | -rw-------. 1 root |
- | -rw-------. 1 root | + | -rw-------. 1 root |
- | drwxr-xr-x. 2 root | + | -rw-------. 1 root |
- | -rw-r--r--. 1 root | + | -rw-------. 1 root |
- | -rw-r--r--. 1 root | + | drwx------. 2 root |
- | -rw-r--r--. 1 root | + | drwx------. 3 root |
- | -rw-r--r--. 1 root | + | -rw-------. 1 root |
- | -rw-rw-r--. 1 root utmp 50304 Sep 29 11:42 wtmp | + | -rw-------. 1 root root 10835 Apr 19 12:07 secure-20210419 |
- | -rw-r--r--. 1 root | + | -rw-------. 1 root |
- | -rw-r--r--. 1 root | + | -rw-------. 1 root |
- | -rw-r--r--. 1 root | + | -rw-------. 1 root |
- | -rw-r--r--. 1 root | + | -rw-------. 1 root |
- | -rw-------. 1 root | + | -rw-------. 1 root |
+ | -rw-------. 1 root | ||
+ | drwxr-x---. 2 sssd | ||
+ | drwxr-xr-x. 3 root | ||
+ | drwxr-xr-x. 2 root | ||
+ | -rw-rw-r--. 1 root | ||
</ | </ | ||
- | =====rsyslog===== | + | =====LAB #2 - rsyslog===== |
**rsyslog**, | **rsyslog**, | ||
Ligne 813: | Ligne 829: | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
# Options for rsyslogd | # Options for rsyslogd | ||
# Syslogd options are deprecated since rsyslog v3. | # Syslogd options are deprecated since rsyslog v3. | ||
Ligne 828: | Ligne 844: | ||
| SYSLOGD_OPTIONS=" | | SYSLOGD_OPTIONS=" | ||
- | <WRAP center round important> | + | ====2.1 - Priorités==== |
- | **Important** : Notez que l' | + | |
- | </ | + | |
- | + | ||
- | ====Priorités==== | + | |
La **Priorité** permet d' | La **Priorité** permet d' | ||
Ligne 846: | Ligne 858: | ||
| 7 | debug | Condition normale - message de débogage | | | 7 | debug | Condition normale - message de débogage | | ||
- | ====Sous-systèmes applicatifs==== | + | ====2.2 - Sous-systèmes applicatifs==== |
Le **Sous-système applicatif**, | Le **Sous-système applicatif**, | ||
Ligne 864: | Ligne 876: | ||
- | ====/ | + | ====2.3 - / |
rsyslog est configuré par le fichier **/ | rsyslog est configuré par le fichier **/ | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
# rsyslog configuration file | # rsyslog configuration file | ||
# For more information see / | # For more information see / | ||
+ | # or latest version online at http:// | ||
# If you experience problems, see http:// | # If you experience problems, see http:// | ||
#### MODULES #### | #### MODULES #### | ||
- | # The imjournal | + | module(load=" |
- | $ModLoad | + | SysSock.Use=" |
- | $ModLoad | + | # local messages are retrieved through imjournal now. |
- | #$ModLoad | + | module(load=" |
- | #$ModLoad | + | StateFile=" |
+ | # | ||
+ | #module(load=" | ||
# Provides UDP syslog reception | # Provides UDP syslog reception | ||
- | #$ModLoad | + | # for parameters see http:// |
- | #$UDPServerRun | + | #module(load=" |
+ | # | ||
# Provides TCP syslog reception | # Provides TCP syslog reception | ||
- | #$ModLoad | + | # for parameters see http:// |
- | #$InputTCPServerRun 514 | + | #module(load=" |
+ | # | ||
#### GLOBAL DIRECTIVES #### | #### GLOBAL DIRECTIVES #### | ||
# Where to place auxiliary files | # Where to place auxiliary files | ||
- | $WorkDirectory | + | global(workDirectory=" |
# Use default timestamp format | # Use default timestamp format | ||
- | $ActionFileDefaultTemplate | + | module(load=" |
- | + | ||
- | # File syncing capability is disabled by default. This feature is usually not required, | + | |
- | # not useful and an extreme performance hit | + | |
- | # | + | |
# Include all config files in / | # Include all config files in / | ||
- | $IncludeConfig | + | include(file=" |
- | + | ||
- | # Turn off message reception via local log socket; | + | |
- | # local messages are retrieved through imjournal now. | + | |
- | $OmitLocalLogging on | + | |
- | + | ||
- | # File to store the position in the journal | + | |
- | $IMJournalStateFile imjournal.state | + | |
#### RULES #### | #### RULES #### | ||
Ligne 945: | Ligne 949: | ||
- | # ### begin forwarding rule ### | + | # ### sample |
- | # The statement between the begin ... end define a SINGLE forwarding | + | #action(type=" |
- | # rule. They belong together, do NOT split them. If you create multiple | + | |
- | # forwarding rules, duplicate the whole block! | + | |
- | # Remote Logging | + | |
- | # | + | |
# An on-disk queue is created for this action. If the remote host is | # An on-disk queue is created for this action. If the remote host is | ||
# down, messages are spooled to disk and sent when it is up again. | # down, messages are spooled to disk and sent when it is up again. | ||
- | #$ActionQueueFileName | + | #queue.filename=" |
- | #$ActionQueueMaxDiskSpace | + | #queue.maxdiskspace=" |
- | #$ActionQueueSaveOnShutdown | + | #queue.saveonshutdown=" |
- | #$ActionQueueType | + | #queue.type=" |
- | #$ActionResumeRetryCount | + | #action.resumeRetryCount=" |
- | # remote host is: name/ip:port, e.g. 192.168.0.1:514, port optional | + | # Remote Logging (we use TCP for reliable delivery) |
- | #*.* @@remote-host: | + | # remote_host |
- | # ### end of the forwarding rule ### | + | #Target=" |
</ | </ | ||
Ligne 970: | Ligne 970: | ||
* Section traitant les options de comportement global du service rsyslog, | * Section traitant les options de comportement global du service rsyslog, | ||
* **Règles** (// | * **Règles** (// | ||
- | * Section traitant les règles de configuration des journaux. Les règles au format syslogd gardent le même format. Les nouvelles règles, compatibles seulement avec rsyslog commencent par **$**. | + | * Section traitant les règles de configuration des journaux. Les règles au format syslogd gardent le même format. Les nouvelles règles, compatibles seulement avec rsyslog commencent par **module**. |
===Modules=== | ===Modules=== | ||
Ligne 977: | Ligne 977: | ||
^ Module ^ Fonction ^ | ^ Module ^ Fonction ^ | ||
- | | $ModLoad | + | | module(load=" |
- | | $ModLoad imklog.so | Active la trace de messages du **noyau** | | + | | module(load=" |
- | | $ModLoad | + | | module(load=" |
- | | $ModLoad | + | | module(load=" |
- | | $ModLoad | + | | module(load=" |
+ | | module(load=" | ||
- | Dans le fichier **/ | + | Dans le fichier **/ |
< | < | ||
... | ... | ||
- | * **#### MODULES #### | + | #### MODULES #### |
- | $ModLoad | + | module(load=" |
- | $ModLoad imklog.so # provides kernel | + | SysSock.Use=" |
- | #$ModLoad | + | # local messages are retrieved through imjournal now. |
+ | module(load=" | ||
+ | | ||
+ | # | ||
+ | #module(load=" | ||
# Provides UDP syslog reception | # Provides UDP syslog reception | ||
- | #$ModLoad | + | # for parameters see http:// |
- | #$UDPServerRun | + | #module(load=" |
+ | # | ||
# Provides TCP syslog reception | # Provides TCP syslog reception | ||
- | #$ModLoad | + | # for parameters see http:// |
- | #$InputTCPServerRun | + | #module(load=" |
+ | # | ||
... | ... | ||
</ | </ | ||
Ligne 1007: | Ligne 1014: | ||
< | < | ||
... | ... | ||
- | * **#### MODULES #### | ||
- | |||
- | $ModLoad imuxsock.so # | ||
- | $ModLoad imklog.so # provides kernel logging support (previously done by rklogd) | ||
- | #$ModLoad immark.so # provides --MARK-- message capability | ||
- | |||
# Provides UDP syslog reception | # Provides UDP syslog reception | ||
- | $ModLoad | + | # for parameters see http:// |
- | $UDPServerRun | + | module(load=" |
+ | input(type=" | ||
# Provides TCP syslog reception | # Provides TCP syslog reception | ||
- | $ModLoad | + | # for parameters see http:// |
- | $InputTCPServerRun | + | module(load=" |
+ | input(type=" | ||
... | ... | ||
</ | </ | ||
- | <WRAP center round important> | + | <WRAP center round important |
- | **Important** : Les deux directives **$ModLoad | + | **Important** : Les deux directives **module(load=" |
</ | </ | ||
- | Pour envoyer l' | + | Pour envoyer l' |
< | < | ||
... | ... | ||
- | # ### begin forwarding rule ### | + | # ### sample |
- | # The statement between the begin ... end define a SINGLE forwarding | + | #action(type=" |
- | # rule. They belong together, do NOT split them. If you create multiple | + | |
- | # forwarding rules, duplicate the whole block! | + | |
- | # Remote Logging | + | |
- | # | + | |
# An on-disk queue is created for this action. If the remote host is | # An on-disk queue is created for this action. If the remote host is | ||
# down, messages are spooled to disk and sent when it is up again. | # down, messages are spooled to disk and sent when it is up again. | ||
- | $WorkDirectory / | + | #queue.filename=" |
- | $ActionQueueFileName | + | # |
- | $ActionQueueMaxDiskSpace | + | # |
- | $ActionQueueSaveOnShutdown | + | # |
- | $ActionQueueType | + | # |
- | $ActionResumeRetryCount | + | # Remote Logging (we use TCP for reliable delivery) |
- | # remote host is: name/ip:port, e.g. 192.168.0.1:514, port optional | + | # remote_host |
- | *.* @@remote-host: | + | Target=" |
- | # ### end of the forwarding rule ### | + | |
... | ... | ||
</ | </ | ||
- | <WRAP center round important> | + | <WRAP center round important |
- | **Important** : Ces directives utilisent le protocole TCP. Le serveur distant doit donc être configuré pour ce mode de communication.La directive ***.* @@remote-host: | + | **Important** : Ces directives utilisent le protocole TCP. Le serveur distant doit donc être configuré pour ce mode de communication. La directive **Target=" |
</ | </ | ||
- | |||
===Directives Globales=== | ===Directives Globales=== | ||
Ligne 1061: | Ligne 1058: | ||
< | < | ||
- | $ActionFileDefaultTemplate | + | module(load=" |
</ | </ | ||
Ligne 1101: | Ligne 1098: | ||
- | <WRAP center round important> | + | <WRAP center round important |
**Important** : Une Action précédée par le signe **-** est entreprise d'une manière **asynchrone**. Dans le cas ou l' | **Important** : Une Action précédée par le signe **-** est entreprise d'une manière **asynchrone**. Dans le cas ou l' | ||
</ | </ | ||
- | + | =====LAB #3 - La Commande logger===== | |
- | =====La Commande logger===== | + | |
La commande **/ | La commande **/ | ||
Ligne 1119: | Ligne 1115: | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
</ | </ | ||
Ligne 1125: | Ligne 1121: | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
- | Sep 29 11:42:17 centos7 fprintd: ** Message: entering main loop | + | Jun 3 12:55:01 centos8 systemd[1]: session-237.scope: Succeeded. |
- | Sep 29 11:42:20 centos7 su: (to root) trainee | + | Jun 3 12:56:01 centos8 systemd[1]: Started Session 238 of user trainee. |
- | Sep 29 11:42:47 centos7 fprintd: ** Message: No devices in use, exit | + | Jun 3 12:56:01 centos8 systemd[1]: session-238.scope: Succeeded. |
- | Sep 29 11:49:39 centos7 pulseaudio[2833]: [alsa-sink] alsa-sink.c: ALSA woke us up to write new data to the device, but there was actually nothing to write! | + | Jun 3 12:57:01 centos8 systemd[1]: Started Session 239 of user trainee. |
- | Sep 29 11:49:39 centos7 pulseaudio[2833]: [alsa-sink] alsa-sink.c: Most likely this is a bug in the ALSA driver ' | + | Jun 3 12:57:01 centos8 systemd[1]: session-239.scope: Succeeded. |
- | Sep 29 11:49:39 centos7 pulseaudio[2833]: [alsa-sink] alsa-sink.c: | + | Jun 3 12:58:01 centos8 systemd[1]: Started Session 240 of user trainee. |
- | Sep 29 11:50:01 centos7 | + | Jun 3 12:58:01 centos8 |
- | Sep 29 11:50:01 centos7 systemd: Starting Session 4 of user root. | + | Jun 3 12:58:55 centos8 trainee[5139]: Linux est super |
- | Sep 29 11:50:01 centos7 | + | Jun 3 12:59:01 centos8 |
- | Sep 29 11:55:57 centos7 trainee: Linux est super | + | Jun 3 12:59:01 centos8 systemd[1]: session-241.scope: |
</ | </ | ||
- | |||
- | ====Options de la commande==== | ||
Les options de la commande logger sont : | Les options de la commande logger sont : | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
Usage: | Usage: | ||
- | | + | |
+ | |||
+ | Enter messages into the system log. | ||
Options: | Options: | ||
- | -T, --tcp use TCP only | + | -i log the logger command' |
- | -d, --udp use UDP only | + | |
- | | + | -f, --file < |
- | -f, --file < | + | -e, --skip-empty |
- | -h, --help display this help text and exit | + | |
- | -n, --server < | + | -p, --priority < |
- | -P, --port < | + | |
- | -p, --priority < | + | |
- | -s, --stderr | + | -s, --stderr |
- | -t, --tag < | + | -S, --size < |
- | -u, --socket < | + | -t, --tag < |
- | -V, --version | + | -n, --server < |
+ | -P, --port < | ||
+ | -T, --tcp use TCP only | ||
+ | -d, --udp use UDP only | ||
+ | | ||
+ | | ||
+ | < | ||
+ | | ||
+ | | ||
+ | | ||
+ | -u, --socket < | ||
+ | | ||
+ | print connection errors when using Unix sockets | ||
+ | | ||
+ | |||
+ | -h, --help | ||
+ | -V, --version | ||
+ | |||
+ | For more details see logger(1). | ||
</ | </ | ||
- | =====La Commande logrotate===== | + | =====LAB #4 - La Commande logrotate===== |
Les fichiers journaux grossissent régulièrement. Le programme **/ | Les fichiers journaux grossissent régulièrement. Le programme **/ | ||
Ligne 1170: | Ligne 1184: | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
# see "man logrotate" | # see "man logrotate" | ||
# rotate log files weekly | # rotate log files weekly | ||
Ligne 1189: | Ligne 1203: | ||
# RPM packages drop log rotation information into this directory | # RPM packages drop log rotation information into this directory | ||
include / | include / | ||
- | |||
- | # no packages own wtmp and btmp -- we'll rotate them here | ||
- | / | ||
- | monthly | ||
- | create 0664 root utmp | ||
- | minsize 1M | ||
- | rotate 1 | ||
- | } | ||
- | |||
- | / | ||
- | missingok | ||
- | monthly | ||
- | create 0600 root utmp | ||
- | rotate 1 | ||
- | } | ||
# system-specific logs may be also be configured here. | # system-specific logs may be also be configured here. | ||
Ligne 1219: | Ligne 1218: | ||
La deuxième partie du fichier concerne des configurations spécifiques pour certains fichiers journaux. | La deuxième partie du fichier concerne des configurations spécifiques pour certains fichiers journaux. | ||
- | <WRAP center round important> | + | <WRAP center round important |
**Important** : Notez que la compression des fichiers de journalisation n'est pas activée par défaut. | **Important** : Notez que la compression des fichiers de journalisation n'est pas activée par défaut. | ||
</ | </ | ||
- | |||
- | ====Options de la commande==== | ||
Les options de la commande logrotate sont : | Les options de la commande logrotate sont : | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
Usage: logrotate [OPTION...] < | Usage: logrotate [OPTION...] < | ||
- | -d, --debug | + | -d, --debug |
+ | messages | ||
-f, --force | -f, --force | ||
-m, --mail=command | -m, --mail=command | ||
-s, --state=statefile | -s, --state=statefile | ||
-v, --verbose | -v, --verbose | ||
- | --version | + | |
+ | | ||
Help options: | Help options: | ||
-?, --help | -?, --help | ||
- | | + | |
</ | </ | ||
- | =====La Journalisation avec journald===== | + | =====LAB #5 - La Journalisation avec journald===== |
- | Sous RHEL/ | + | Sous RHEL/ |
< | < | ||
- | [root@centos7 | + | [root@centos8 |
total 0 | total 0 | ||
- | drwxr-sr-x. 2 root systemd-journal 60 Sep 29 14:41 a2feb9eb09b1488da0f23b99a66350f8 | + | drwxr-s---+ 2 root systemd-journal 60 Jun 3 09:01 de79af4f226d480fa7d3fec4cabbf97a |
</ | </ | ||
Ligne 1257: | Ligne 1256: | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
- | [root@centos7 | + | [root@centos8 |
total 0 | total 0 | ||
- | [root@centos7 | + | [root@centos8 |
- | [root@centos7 | + | [root@centos8 |
- | ls: cannot access / | + | ls: cannot access |
- | [root@centos7 | + | [root@centos8 |
total 0 | total 0 | ||
- | drwxr-sr-x. 2 root systemd-journal 73 Sep 29 15:30 a2feb9eb09b1488da0f23b99a66350f8 | + | drwxr-xr-x. 2 root root 28 Jun 3 13:03 de79af4f226d480fa7d3fec4cabbf97a |
- | [root@centos7 ~]# | + | |
</ | </ | ||
- | <WRAP center round important> | + | Journald ne peut pas envoyer les traces à un autre ordinateur. Pour utiliser un serveur de journalisation distant il faut donc inclure la directive **ForwardToSyslog=yes** dans le fichier de configuration de journald, **/ |
- | **Important** : Journald ne peut pas envoyer les traces à un autre ordinateur. Pour utiliser un serveur de journalisation distant il faut donc inclure la directive **ForwardToSyslog=yes** dans le fichier de configuration de journald, **/ | + | |
- | </WRAP> | + | < |
+ | [root@centos8 ~]# cat / | ||
+ | # This file is part of systemd. | ||
+ | # | ||
+ | # systemd is free software; you can redistribute it and/or modify it | ||
+ | # under the terms of the GNU Lesser General Public License as published by | ||
+ | # the Free Software Foundation; either version 2.1 of the License, or | ||
+ | # (at your option) any later version. | ||
+ | # | ||
+ | # Entries in this file show the compile time defaults. | ||
+ | # You can change settings by editing this file. | ||
+ | # Defaults can be restored by simply deleting this file. | ||
+ | # | ||
+ | # See journald.conf(5) for details. | ||
+ | |||
+ | [Journal] | ||
+ | # | ||
+ | # | ||
+ | #Seal=yes | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | ForwardToSyslog=yes | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | </code> | ||
- | ====Consultation des Journaux==== | + | ====5.1 - Consultation des Journaux==== |
L' | L' | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
- | -- Logs begin at Tue 2015-09-29 11:25:10 CEST, end at Tue 2015-09-29 18:10:01 CEST. -- | + | -- Logs begin at Thu 2021-06-03 09:01:10 EDT, end at Thu 2021-06-03 13:08:01 EDT. -- |
- | Sep 29 11:25:10 centos7.fenestros.loc systemd-journal[82]: Runtime journal is using 8.0M (max 74.8M, leaving 112.3M of free 740.8M, current limit 74.8 | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: Linux version 4.18.0-240.22.1.el8_3.x86_64 |
- | Sep 29 11:25:10 centos7.fenestros.loc systemd-journal[82]: Runtime journal is using 8.0M (max 74.8M, leaving 112.3M of free 740.8M, current limit 74.8 | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: Command line: BOOT_IMAGE=(hd0,msdos1)/ |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: e820: BIOS-provided physical RAM map: | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-provided physical RAM map: |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: BIOS-e820: [mem 0x0000000000000000-0x000000000009fbff] usable | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x0000000000000000-0x000000000009fbff] usable |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: BIOS-e820: [mem 0x000000000009fc00-0x000000000009ffff] reserved | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x000000000009fc00-0x000000000009ffff] reserved |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: BIOS-e820: [mem 0x00000000000f0000-0x00000000000fffff] reserved | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x00000000000f0000-0x00000000000fffff] reserved |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: BIOS-e820: [mem 0x0000000000100000-0x000000005ffeffff] usable | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x0000000000100000-0x00000000dffeffff] usable |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: BIOS-e820: [mem 0x000000005fff0000-0x000000005fffffff] ACPI data | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x00000000dfff0000-0x00000000dfffffff] ACPI data |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: BIOS-e820: [mem 0x00000000fffc0000-0x00000000ffffffff] reserved | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x00000000fec00000-0x00000000fec00fff] reserved |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: NX (Execute Disable) protection: active | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x00000000fee00000-0x00000000fee00fff] reserved |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: SMBIOS 2.5 present. | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x00000000fffc0000-0x00000000ffffffff] reserved |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: DMI: innotek GmbH VirtualBox/ | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x0000000100000000-0x000000011fffffff] usable |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: e820: update [mem 0x00000000-0x00000fff] usable ==> reserved | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: NX (Execute Disable) protection: active |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: e820: remove [mem 0x000a0000-0x000fffff] usable | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: SMBIOS 2.5 present. |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: No AGP bridge found | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: DMI: innotek GmbH VirtualBox/ |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: e820: last_pfn = 0x5fff0 | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: Hypervisor detected: KVM |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: MTRR default type: uncachable | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: kvm-clock: Using msrs 4b564d01 and 4b564d00 |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: MTRR variable ranges disabled: | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: kvm-clock: cpu 0, msr 114801001, primary cpu clock |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: x86 PAT enabled: cpu 0, old 0x7040600070406, | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: kvm-clock: using sched offset of 5675771878 cycles |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: CPU MTRRs all blank - virtualized system. | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: clocksource: |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: found SMP MP-table at [mem 0x0009fff0-0x0009ffff] | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: tsc: Detected 1190.400 MHz processor |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: e820: update [mem 0x00000000-0x00000fff] usable ==> reserved |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: e820: remove [mem 0x000a0000-0x000fffff] usable |
- | lines 1-29 | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: last_pfn = 0x120000 |
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: MTRR default type: uncachable | ||
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: MTRR variable ranges disabled: | ||
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: Disabled | ||
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: x86/PAT: MTRRs disabled, skipping PAT initialization too. | ||
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: CPU MTRRs all blank - virtualized system. | ||
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: x86/PAT: Configuration [0-7]: WB WT UC- UC WB WT UC- UC | ||
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: last_pfn = 0xdfff0 max_arch_pfn = 0x400000000 | ||
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: found SMP MP-table at [mem 0x0009fff0-0x0009ffff] | ||
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: kexec: Reserving the low 1M of memory for crashkernel | ||
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: BRK [0x114a01000, | ||
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: | ||
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: | ||
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: BRK [0x114a04000, | ||
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: BRK [0x114a05000, | ||
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: BRK [0x114a06000, | ||
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: BRK [0x114a07000, | ||
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: BRK [0x114a08000, | ||
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: BRK [0x114a09000, | ||
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: RAMDISK: [mem 0x34e00000-0x366f7fff] | ||
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: ACPI: Early table checksum verification disabled | ||
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: ACPI: RSDP 0x00000000000E0000 000024 (v02 VBOX ) | ||
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: ACPI: XSDT 0x00000000DFFF0030 00003C (v01 VBOX | ||
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: ACPI: FACP 0x00000000DFFF00F0 0000F4 (v04 VBOX | ||
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: ACPI: DSDT 0x00000000DFFF0480 002325 (v02 VBOX | ||
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: ACPI: FACS 0x00000000DFFF0200 000040 | ||
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: ACPI: FACS 0x00000000DFFF0200 000040 | ||
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: ACPI: APIC 0x00000000DFFF0240 00006C (v02 VBOX | ||
+ | lines 1-57 | ||
</ | </ | ||
- | <WRAP center round important> | + | <WRAP center round important |
**Important** : Notez que les messages importants sont en gras, par exemple les messages de niveaux **notice** ou **warning** et que les messages graves sont en rouge. | **Important** : Notez que les messages importants sont en gras, par exemple les messages de niveaux **notice** ou **warning** et que les messages graves sont en rouge. | ||
</ | </ | ||
- | ===Consultation des Journaux d'une Application Spécifique=== | + | ====5.2 - Consultation des Journaux d'une Application Spécifique==== |
Pour consulter les entrées concernant une application spécifique, | Pour consulter les entrées concernant une application spécifique, | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
- | -- Logs begin at Tue 2015-09-29 11:25:10 CEST, end at Tue 2015-09-29 18:20:01 CEST. -- | + | -- Logs begin at Thu 2021-06-03 09:01:10 EDT, end at Thu 2021-06-03 13:10:01 EDT. -- |
- | Sep 29 12: | + | Jun 03 10: |
- | Sep 29 12: | + | Jun 03 10: |
- | Sep 29 12: | + | Jun 03 10: |
- | Sep 29 13:45:00 centos7.fenestros.loc anacron[4100]: Job `cron.daily' | + | Jun 03 10:16:01 centos8.ittraining.loc anacron[2575]: Job `cron.daily' |
+ | Jun 03 10:16:01 centos8.ittraining.loc anacron[2575]: | ||
+ | Jun 03 10:16:01 centos8.ittraining.loc anacron[2575]: | ||
</ | </ | ||
- | <WRAP center round important> | + | <WRAP center round important |
- | **Important** : Rappelez-vous que sous RHEL/ | + | **Important** : Rappelez-vous que sous RHEL/ |
</ | </ | ||
- | ===Consultation des Journaux depuis le Dernier Démarrage=== | + | ====5.3 - Consultation des Journaux depuis le Dernier Démarrage==== |
Pour consulter les entrées depuis le dernier démarrage, il suffit d' | Pour consulter les entrées depuis le dernier démarrage, il suffit d' | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
- | -- Logs begin at Tue 2015-09-29 11:25:10 CEST, end at Tue 2015-09-29 18:28:56 CEST. -- | + | -- Logs begin at Thu 2021-06-03 09:01:10 EDT, end at Thu 2021-06-03 13:11:01 EDT. -- |
- | Sep 29 11:25:10 centos7.fenestros.loc systemd-journal[82]: | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: Linux version |
- | M). | + | 8.3.1 20191121 |
- | Sep 29 11:25:10 centos7.fenestros.loc systemd-journal[82]: | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: Command line: BOOT_IMAGE=(hd0, |
- | M). | + | c-0d59-45be-bd73-d292b80be33c |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: Initializing cgroup subsys cpuset | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: Initializing cgroup subsys cpu | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: x86/fpu: Supporting XSAVE feature 0x002: 'SSE registers' |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: Initializing cgroup subsys cpuacct | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: x86/fpu: Supporting XSAVE feature 0x004: 'AVX registers' |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: Linux version | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: x86/fpu: xstate_offset[2]: |
- | ed Hat 4.8.2-16) (GCC) ) #1 SMP Wed May 13 10:06:09 UTC 2015 | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: x86/fpu: Enabled xstate features 0x7, context size is 832 bytes, using ' |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: Command line: BOOT_IMAGE=/ | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-provided physical RAM map: |
- | 91 ro vconsole.keymap=fr | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x0000000000000000-0x000000000009fbff] usable |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x000000000009fc00-0x000000000009ffff] reserved |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: BIOS-e820: [mem 0x0000000000000000-0x000000000009fbff] usable | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x00000000000f0000-0x00000000000fffff] reserved |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: BIOS-e820: [mem 0x000000000009fc00-0x000000000009ffff] reserved | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x0000000000100000-0x00000000dffeffff] usable |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: BIOS-e820: [mem 0x00000000000f0000-0x00000000000fffff] reserved | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x00000000dfff0000-0x00000000dfffffff] ACPI data |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: BIOS-e820: [mem 0x0000000000100000-0x000000005ffeffff] usable | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x00000000fec00000-0x00000000fec00fff] reserved |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: BIOS-e820: [mem 0x000000005fff0000-0x000000005fffffff] ACPI data | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x00000000fee00000-0x00000000fee00fff] reserved |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: BIOS-e820: [mem 0x00000000fffc0000-0x00000000ffffffff] reserved | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x00000000fffc0000-0x00000000ffffffff] reserved |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: NX (Execute Disable) protection: active | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x0000000100000000-0x000000011fffffff] usable |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: SMBIOS 2.5 present. | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: NX (Execute Disable) protection: active |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: DMI: innotek GmbH VirtualBox/ | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: SMBIOS 2.5 present. |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: DMI: innotek GmbH VirtualBox/ |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: | + | 590591483 ns |
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: | ||
+ | Jun 03 09:01:10 centos8.ittraining.loc kernel: | ||
--More-- | --More-- | ||
</ | </ | ||
- | <WRAP center round important> | + | <WRAP center round important |
**Important** : Notez que vous pouvez consulter les messages des démarrages précédents, | **Important** : Notez que vous pouvez consulter les messages des démarrages précédents, | ||
</ | </ | ||
- | ===Consultation des Journaux d'une Priorité Spécifique=== | + | ====5.4 - Consultation des Journaux d'une Priorité Spécifique==== |
Pour consulter les entrées à partir d'une priorité spécifique et supérieur, il suffit d' | Pour consulter les entrées à partir d'une priorité spécifique et supérieur, il suffit d' | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
- | -- Logs begin at Tue 2015-09-29 11:25:10 CEST, end at Tue 2015-09-29 18:30:02 CEST. -- | + | -- Logs begin at Thu 2021-06-03 09:01:10 EDT, end at Thu 2021-06-03 13:12:01 EDT. -- |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: | + | Jun 03 09:01:10 centos8.ittraining.loc kernel: |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: ACPI: DSDT 000000005fff0470 01BF1 (v01 VBOX | + | Jun 03 09:01:12 centos8.ittraining.loc kernel: |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: | + | Jun 03 09:01:12 centos8.ittraining.loc kernel: |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: | + | Jun 03 09:01:12 centos8.ittraining.loc kernel: |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: ACPI: SSDT 000000005fff02a0 001CC (v01 VBOX | + | Jun 03 09:01:18 centos8.ittraining.loc kernel: |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: | + | Jun 03 09:01:20 centos8.ittraining.loc firewalld[874]: WARNING: AllowZoneDrifting is enabled. This is considered an insecure configuration> |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: | + | Jun 03 09:01:21 centos8.ittraining.loc systemd[1]: iscsi.service: Unit cannot be reloaded because it is inactive. |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: | + | Jun 03 09:01:24 centos8.ittraining.loc systemd[1]: iscsi.service: Unit cannot be reloaded because it is inactive. |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: | + | Jun 03 09:01:24 centos8.ittraining.loc systemd[1]: iscsi.service: Unit cannot be reloaded because it is inactive. |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: | + | Jun 03 09:01:26 centos8.ittraining.loc chronyd[850]: System clock wrong by 1.753498 seconds, adjustment started |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: Movable zone start for each node | + | Jun 03 09:01:28 centos8.ittraining.loc chronyd[850]: System clock was stepped by 1.753498 seconds |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: Early memory node ranges | + | Jun 03 12:46:31 centos8.ittraining.loc chronyd[850]: System clock wrong by 47255.336542 seconds, adjustment started |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: | + | lines 1-15/15 (END) |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: | + | |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: Built 1 zonelists in Node order, mobility grouping on. Total pages: 386937 | + | |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: Policy zone: DMA32 | + | |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: tsc: Fast TSC calibration failed | + | |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: tsc: Unable to calibrate against PIT | + | |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: ACPI: All ACPI Tables successfully acquired | + | |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: NMI watchdog: disabled (cpu0): hardware events not enabled | + | |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: ACPI: Executed | + | |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: ACPI Exception: AE_NOT_FOUND, While evaluating Sleep State [\_S1_] (20130517/ | + | |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: ACPI Exception: AE_NOT_FOUND, | + | |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: ACPI Exception: AE_NOT_FOUND, | + | |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: ACPI Exception: AE_NOT_FOUND, | + | |
- | Sep 29 11:25:10 centos7.fenestros.loc kernel: acpi PNP0A03:00: fail to add MMCONFIG information, can't access extended PCI configuration space under t | + | |
- | lines 1-29 | + | |
</ | </ | ||
- | ===Consultation des Journaux d'une Plage de Dates ou d' | + | Les priorités reconnues par Journald sont : |
+ | |||
+ | ^ Niveau ^ Priorité ^ Description ^ | ||
+ | | 0 | emerg | Système inutilisable | | ||
+ | | 1 | alert | Action immédiate requise | | ||
+ | | 2 | crit | Condition critique atteinte | | ||
+ | | 3 | err | Erreurs rencontrées | | ||
+ | | 4 | warning | Avertissements présentés | | ||
+ | | 5 | notice | Condition normale - message important | | ||
+ | | 6 | info | Condition normale - message simple | | ||
+ | | 7 | debug | Condition normale - message de débogage | | ||
+ | |||
+ | ====5.5 - Consultation des Journaux d'une Plage de Dates ou d' | ||
Pour consulter les entrées d'une plage de dates ou d' | Pour consulter les entrées d'une plage de dates ou d' | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
- | -- Logs begin at Tue 2015-09-29 11:25:10 CEST, end at Tue 2015-09-29 18:30:02 CEST. -- | + | -- Logs begin at Thu 2021-06-03 09:01:10 EDT, end at Thu 2021-06-03 13:14:01 EDT. -- |
- | Sep 29 18:05:50 centos7.fenestros.loc systemd[1]: | + | Jun 03 12:00:01 centos8.ittraining.loc systemd[1]: |
- | Sep 29 18:06:23 centos7.fenestros.loc dbus-daemon[526]: dbus[526]: [system] Activating via systemd: service name=' | + | Jun 03 12:00:01 centos8.ittraining.loc CROND[4238]: (trainee) CMD (/bin/pwd > pwd.txt) |
- | Sep 29 18:06:23 centos7.fenestros.loc dbus[526]: [system] Activating via systemd: service name=' | + | Jun 03 12:00:01 centos8.ittraining.loc systemd[1]: session-181.scope: Succeeded. |
- | Sep 29 18:06:23 centos7.fenestros.loc systemd[1]: | + | Jun 03 12:01:01 centos8.ittraining.loc CROND[4251]: (root) CMD (run-parts /etc/cron.hourly) |
- | Sep 29 18:06:23 centos7.fenestros.loc dbus-daemon[526]: dbus[526]: [system] Successfully activated service 'net.reactivated.Fprint' | + | Jun 03 12:01:01 centos8.ittraining.loc systemd[1]: |
- | Sep 29 18:06:23 centos7.fenestros.loc dbus[526]: [system] Successfully activated service 'net.reactivated.Fprint' | + | Jun 03 12:01:01 centos8.ittraining.loc run-parts[4255]: (/ |
- | Sep 29 18:06:23 centos7.fenestros.loc systemd[1]: | + | Jun 03 12:01:01 centos8.ittraining.loc CROND[4260]: (trainee) CMD (/bin/pwd > pwd.txt) |
- | Sep 29 18:06:23 centos7.fenestros.loc fprintd[7642]: Launching FprintObject | + | Jun 03 12:01:01 centos8.ittraining.loc run-parts[4262]: (/etc/cron.hourly) finished 0anacron |
- | Sep 29 18:06:23 centos7.fenestros.loc fprintd[7642]: ** Message: D-Bus service launched with name: net.reactivated.Fprint | + | Jun 03 12:01:01 centos8.ittraining.loc systemd[1]: |
- | Sep 29 18:06:23 centos7.fenestros.loc fprintd[7642]: ** Message: entering main loop | + | Jun 03 12:02:01 centos8.ittraining.loc systemd[1]: Started Session 183 of user trainee. |
- | Sep 29 18:06:27 centos7.fenestros.loc gdm-password][7646]: gkr-pam: unlocked login keyring | + | Jun 03 12:02:01 centos8.ittraining.loc CROND[4275]: (trainee) CMD (/bin/pwd > pwd.txt) |
- | Sep 29 18:06:27 centos7.fenestros.loc dbus-daemon[526]: dbus[526]: [system] Activating via systemd: service name=' | + | Jun 03 12:02:01 centos8.ittraining.loc systemd[1]: session-183.scope: Succeeded. |
- | Sep 29 18:06:27 centos7.fenestros.loc dbus[526]: [system] Activating via systemd: service name=' | + | Jun 03 12:03:01 centos8.ittraining.loc systemd[1]: Started Session 184 of user trainee. |
- | Sep 29 18:06:27 centos7.fenestros.loc systemd[1]: | + | Jun 03 12:03:01 centos8.ittraining.loc CROND[4289]: (trainee) CMD (/bin/pwd > pwd.txt) |
- | Sep 29 18:06:27 centos7.fenestros.loc dbus-daemon[526]: dbus[526]: [system] Successfully activated service 'org.freedesktop.hostname1' | + | Jun 03 12:03:01 centos8.ittraining.loc systemd[1]: session-184.scope: Succeeded. |
- | Sep 29 18:06:27 centos7.fenestros.loc dbus[526]: [system] Successfully activated service 'org.freedesktop.hostname1' | + | Jun 03 12:04:01 centos8.ittraining.loc systemd[1]: |
- | Sep 29 18:06:27 centos7.fenestros.loc systemd[1]: Started | + | Jun 03 12:04:01 centos8.ittraining.loc CROND[4303]: (trainee) CMD (/bin/pwd > pwd.txt) |
- | Sep 29 18:06:53 centos7.fenestros.loc fprintd[7642]: ** Message: No devices in use, exit | + | Jun 03 12:04:01 centos8.ittraining.loc systemd[1]: session-185.scope: Succeeded. |
- | Sep 29 18:09:27 centos7.fenestros.loc systemd[1]: | + | Jun 03 12:05:01 centos8.ittraining.loc systemd[1]: Started |
- | Sep 29 18:09:27 centos7.fenestros.loc systemd-journal[362]: Journal stopped | + | Jun 03 12:05:01 centos8.ittraining.loc CROND[4319]: (trainee) CMD (/bin/pwd > pwd.txt) |
- | Sep 29 18:09:27 centos7.fenestros.loc systemd-journal[7694]: Permanent journal is using 8.0M (max 699.0M, leaving 1.0G of free 2.5G, current limit 699 | + | Jun 03 12:05:01 centos8.ittraining.loc systemd[1]: |
- | Sep 29 18:09:27 centos7.fenestros.loc systemd-journal[7694]: Permanent journal is using 8.0M (max 699.0M, leaving 1.0G of free 2.5G, current limit 699 | + | Jun 03 12:06:02 centos8.ittraining.loc systemd[1]: Started Session 187 of user trainee. |
- | Sep 29 18:09:27 centos7.fenestros.loc systemd-journal[7694]: Time spent on flushing to /var is 52.802ms for 1492 entries. | + | Jun 03 12:06:02 centos8.ittraining.loc CROND[4332]: (trainee) CMD (/bin/pwd > pwd.txt) |
- | Sep 29 18:09:27 centos7.fenestros.loc systemd-journald[362]: Received SIGTERM | + | Jun 03 12:06:02 centos8.ittraining.loc systemd[1]: session-187.scope: Succeeded. |
- | Sep 29 18:09:27 centos7.fenestros.loc systemd-journal[7694]: Journal started | + | Jun 03 12:07:01 centos8.ittraining.loc systemd[1]: Started Session 188 of user trainee. |
- | Sep 29 18:09:27 centos7.fenestros.loc systemd[1]: | + | Jun 03 12:07:01 centos8.ittraining.loc CROND[4346]: (trainee) CMD (/bin/pwd > pwd.txt) |
- | Sep 29 18:09:27 centos7.fenestros.loc systemd[1]: Started Trigger Flushing of Journal to Persistent Storage. | + | Jun 03 12:07:01 centos8.ittraining.loc systemd[1]: session-188.scope: |
- | Sep 29 18:10:01 centos7.fenestros.loc systemd[1]: | + | Jun 03 12:08:01 centos8.ittraining.loc systemd[1]: |
- | lines 1-29 | + | Jun 03 12:08:01 centos8.ittraining.loc CROND[4360]: (trainee) CMD (/bin/pwd > pwd.txt) |
+ | Jun 03 12:08:01 centos8.ittraining.loc systemd[1]: | ||
+ | lines 1-31 | ||
</ | </ | ||
- | <WRAP center round important> | + | <WRAP center round important |
- | **Important** : Le format de la date est **2015-09-29 18: | + | **Important** : Il est possible d' |
</ | </ | ||
- | ===Consultation des Journaux en Live=== | + | ====5.6 - Consultation des Journaux en Live==== |
Pour consulter les journaux en live, il suffit d' | Pour consulter les journaux en live, il suffit d' | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
- | -- Logs begin at Tue 2015-09-29 11:25:10 CEST. -- | + | -- Logs begin at Thu 2021-06-03 09:01:10 EDT. -- |
- | Sep 29 18:28:56 centos7.fenestros.loc gdm-password][8599]: gkr-pam: unlocked login keyring | + | Jun 03 13:13:08 centos8.ittraining.loc systemd[1]: Started dnf makecache. |
- | Sep 29 18:29:24 centos7.fenestros.loc fprintd[8595]: ** Message: No devices in use, exit | + | Jun 03 13:14:01 centos8.ittraining.loc systemd[1]: Started Session 256 of user trainee. |
- | Sep 29 18:30:01 centos7.fenestros.loc systemd[1]: Created slice user-0.slice. | + | Jun 03 13:14:01 centos8.ittraining.loc CROND[5391]: (trainee) CMD (/bin/pwd > pwd.txt) |
- | Sep 29 18:30:02 centos7.fenestros.loc systemd[1]: | + | Jun 03 13:14:01 centos8.ittraining.loc systemd[1]: |
- | Sep 29 18:30:02 centos7.fenestros.loc systemd[1]: Started Session | + | Jun 03 13:15:01 centos8.ittraining.loc systemd[1]: Started Session |
- | Sep 29 18:30:02 centos7.fenestros.loc CROND[8670]: (root) CMD (/usr/lib64/ | + | Jun 03 13:15:01 centos8.ittraining.loc CROND[5407]: (trainee) CMD (/bin/pwd > pwd.txt) |
- | Sep 29 18:40:01 centos7.fenestros.loc systemd[1]: | + | Jun 03 13:15:01 centos8.ittraining.loc systemd[1]: |
- | Sep 29 18:40:01 centos7.fenestros.loc systemd[1]: Starting Session 34 of user root. | + | Jun 03 13:16:02 centos8.ittraining.loc systemd[1]: Started Session |
- | Sep 29 18:40:01 centos7.fenestros.loc systemd[1]: Started Session | + | Jun 03 13:16:02 centos8.ittraining.loc CROND[5420]: (trainee) CMD (/bin/pwd > pwd.txt) |
- | Sep 29 18:40:01 centos7.fenestros.loc CROND[8809]: (root) CMD (/usr/lib64/ | + | Jun 03 13:16:02 centos8.ittraining.loc systemd[1]: session-258.scope: |
+ | ^C | ||
</ | </ | ||
Ligne 1477: | Ligne 1552: | ||
< | < | ||
- | [trainee@centos7 | + | [trainee@centos8 |
</ | </ | ||
Ligne 1483: | Ligne 1558: | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
- | -- Logs begin at Tue 2015-09-29 11:25:10 CEST. -- | + | -- Logs begin at Thu 2021-06-03 09:01:10 EDT. -- |
- | Sep 29 18:28:56 centos7.fenestros.loc gdm-password][8599]: gkr-pam: unlocked login keyring | + | Jun 03 13:13:08 centos8.ittraining.loc systemd[1]: Started dnf makecache. |
- | Sep 29 18:29:24 centos7.fenestros.loc fprintd[8595]: ** Message: No devices in use, exit | + | Jun 03 13:14:01 centos8.ittraining.loc systemd[1]: Started Session 256 of user trainee. |
- | Sep 29 18:30:01 centos7.fenestros.loc systemd[1]: | + | Jun 03 13:14:01 centos8.ittraining.loc CROND[5391]: |
- | Sep 29 18:30:02 centos7.fenestros.loc systemd[1]: | + | Jun 03 13:14:01 centos8.ittraining.loc systemd[1]: session-256.scope: Succeeded. |
- | Sep 29 18:30:02 centos7.fenestros.loc systemd[1]: Started Session | + | Jun 03 13:15:01 centos8.ittraining.loc systemd[1]: |
- | Sep 29 18:30:02 centos7.fenestros.loc CROND[8670]: (root) CMD (/usr/lib64/ | + | Jun 03 13:15:01 centos8.ittraining.loc CROND[5407]: |
- | Sep 29 18:40:01 centos7.fenestros.loc systemd[1]: | + | Jun 03 13:15:01 centos8.ittraining.loc systemd[1]: session-257.scope: Succeeded. |
- | Sep 29 18:40:01 centos7.fenestros.loc systemd[1]: | + | Jun 03 13:16:02 centos8.ittraining.loc systemd[1]: |
- | Sep 29 18:40:01 centos7.fenestros.loc systemd[1]: Started Session | + | Jun 03 13:16:02 centos8.ittraining.loc CROND[5420]: |
- | Sep 29 18:40:01 centos7.fenestros.loc CROND[8809]: (root) CMD (/usr/lib64/ | + | Jun 03 13:16:02 centos8.ittraining.loc systemd[1]: session-258.scope: |
- | Sep 29 18:43:00 centos7.fenestros.loc trainee[8930]: Linux est super | + | Jun 03 13:17:01 centos8.ittraining.loc systemd[1]: Started Session |
- | + | Jun 03 13:17:01 centos8.ittraining.loc CROND[5436]: (trainee) CMD (/bin/pwd > pwd.txt) | |
+ | Jun 03 13:17:01 centos8.ittraining.loc systemd[1]: | ||
+ | Jun 03 13:17:19 centos8.ittraining.loc sshd[5439]: Accepted password for trainee from 10.0.2.2 port 39906 ssh2 | ||
+ | Jun 03 13:17:19 centos8.ittraining.loc systemd-logind[880]: | ||
+ | Jun 03 13:17:19 centos8.ittraining.loc systemd[1]: | ||
+ | Jun 03 13:17:19 centos8.ittraining.loc sshd[5439]: pam_unix(sshd: | ||
+ | Jun 03 13:17:34 centos8.ittraining.loc trainee[5470]: | ||
+ | Jun 03 13:17:34 centos8.ittraining.loc rsyslogd[1113]: | ||
+ | Jun 03 13:18:01 centos8.ittraining.loc systemd[1]: Started Session | ||
+ | Jun 03 13:18:01 centos8.ittraining.loc CROND[5481]: (trainee) CMD (/bin/pwd > pwd.txt) | ||
+ | Jun 03 13:18:01 centos8.ittraining.loc systemd[1]: session-261.scope: | ||
+ | ^C | ||
</ | </ | ||
- | <WRAP center round important> | + | <WRAP center round important |
- | **Important** : Notez la présence de la dernière | + | **Important** : Notez la présence de la ligne **Jun 03 13:17:34 centos8.ittraining.loc trainee[5470]: |
</ | </ | ||
- | ===Consultation des Journaux avec des Mots Clefs=== | + | ====5.7 - Consultation des Journaux avec des Mots Clefs=== |
- | Pour consulter les mots clefs compris par Journald, tapez la commande journalctl puis appuyer | + | Pour consulter les mots clefs compris par Journald, tapez la commande |
< | < | ||
- | [root@centos7 | + | [root@centos8 |
- | _AUDIT_LOGINUID= | + | _AUDIT_LOGINUID= |
- | _AUDIT_SESSION= | + | _AUDIT_SESSION= |
- | _BOOT_ID= | + | AVAILABLE= |
- | _CMDLINE= | + | AVAILABLE_PRETTY= JOB_ID= |
- | CODE_FILE= | + | _BOOT_ID= |
- | CODE_FUNC= | + | _CAP_EFFECTIVE= |
- | CODE_LINE= _KERNEL_DEVICE= | + | _CMDLINE= |
- | _COMM= _KERNEL_SUBSYSTEM= _SELINUX_CONTEXT= | + | CODE_FILE= |
+ | CODE_FUNC= | ||
+ | CODE_LINE= | ||
+ | _COMM= | ||
+ | CURRENT_USE= | ||
+ | CURRENT_USE_PRETTY= | ||
+ | DISK_AVAILABLE= | ||
+ | DISK_AVAILABLE_PRETTY= | ||
+ | DISK_KEEP_FREE= MAX_USE= | ||
+ | DISK_KEEP_FREE_PRETTY= | ||
+ | _EXE= | ||
+ | _GID= | ||
</ | </ | ||
Ligne 1523: | Ligne 1619: | ||
< | < | ||
- | [root@centos7 | + | [root@centos8 |
- | 0 | + | 0 |
- | [root@centos7 | + | [root@centos8 |
- | abrtd avahi-daemon | + | anacron |
- | accounts-daemon | + | auditd |
- | alsactl | + | augenrules |
- | anacron | + | chronyd |
- | audispd | + | crond firewalld |
- | auditd | + | |
- | augenrules | + | |
- | [root@centos7 ~]# journalctl _COMM= | + | |
</ | </ | ||
----- | ----- | ||
- | < | + | Copyright © 2024 Hugh Norris. |
- | <div align=" | + | |
- | Copyright © 2020 Hugh Norris. | + | |
- | </ | + |