Différences
Ci-dessous, les différences entre deux révisions de la page.
Les deux révisions précédentesRévision précédenteProchaine révision | Révision précédente | ||
elearning:workbooks:redhat:rh124:l110 [2024/09/26 11:51] – created admin | elearning:workbooks:redhat:rh124:l110 [2024/11/28 08:58] (Version actuelle) – admin | ||
---|---|---|---|
Ligne 50: | Ligne 50: | ||
* 5.6 - Consultation des Journaux en Live | * 5.6 - Consultation des Journaux en Live | ||
* 5.7 - Consultation des Journaux avec des Mots Clefs | * 5.7 - Consultation des Journaux avec des Mots Clefs | ||
+ | * LAB #6 - Le Serveur d' | ||
+ | * 6.1 - Introduction | ||
+ | * 6.2 - Le Service chronyd | ||
+ | * 6.2 - Le Fichier / | ||
=====Présentation===== | =====Présentation===== | ||
Ligne 64: | Ligne 68: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
- | [ 0.000000] Linux version | + | [ 0.000000] Linux version |
- | CC)) #1 SMP Thu Apr 8 19:01:30 UTC 2021 | + | Sep 13 12:41:50 EDT 2024 |
- | [ 0.000000] Command line: BOOT_IMAGE=(hd0, | + | [ 0.000000] The list of certified hardware and cloud instances for Red Hat Enterprise Linux 9 can be viewed at the Red Hat Ecosystem Catalog, https:// |
- | shkernel=auto | + | [ 0.000000] Command line: BOOT_IMAGE=(hd0, |
+ | oot rd.lvm.lv=rhel/ | ||
[ 0.000000] x86/fpu: Supporting XSAVE feature 0x001: 'x87 floating point registers' | [ 0.000000] x86/fpu: Supporting XSAVE feature 0x001: 'x87 floating point registers' | ||
[ 0.000000] x86/fpu: Supporting XSAVE feature 0x002: 'SSE registers' | [ 0.000000] x86/fpu: Supporting XSAVE feature 0x002: 'SSE registers' | ||
Ligne 74: | Ligne 79: | ||
[ 0.000000] x86/fpu: xstate_offset[2]: | [ 0.000000] x86/fpu: xstate_offset[2]: | ||
[ 0.000000] x86/fpu: Enabled xstate features 0x7, context size is 832 bytes, using ' | [ 0.000000] x86/fpu: Enabled xstate features 0x7, context size is 832 bytes, using ' | ||
+ | [ 0.000000] signal: max sigframe size: 1776 | ||
[ 0.000000] BIOS-provided physical RAM map: | [ 0.000000] BIOS-provided physical RAM map: | ||
[ 0.000000] BIOS-e820: [mem 0x0000000000000000-0x000000000009fbff] usable | [ 0.000000] BIOS-e820: [mem 0x0000000000000000-0x000000000009fbff] usable | ||
[ 0.000000] BIOS-e820: [mem 0x000000000009fc00-0x000000000009ffff] reserved | [ 0.000000] BIOS-e820: [mem 0x000000000009fc00-0x000000000009ffff] reserved | ||
[ 0.000000] BIOS-e820: [mem 0x00000000000f0000-0x00000000000fffff] reserved | [ 0.000000] BIOS-e820: [mem 0x00000000000f0000-0x00000000000fffff] reserved | ||
- | [ 0.000000] BIOS-e820: [mem 0x0000000000100000-0x00000000dffeffff] usable | + | [ 0.000000] BIOS-e820: [mem 0x0000000000100000-0x00000000bffd9fff] usable |
- | [ 0.000000] BIOS-e820: [mem 0x00000000dfff0000-0x00000000dfffffff] ACPI data | + | [ 0.000000] BIOS-e820: [mem 0x00000000bffda000-0x00000000bfffffff] reserved |
- | [ 0.000000] BIOS-e820: [mem 0x00000000fec00000-0x00000000fec00fff] reserved | + | [ 0.000000] BIOS-e820: [mem 0x00000000feffc000-0x00000000feffffff] reserved |
- | [ 0.000000] BIOS-e820: [mem 0x00000000fee00000-0x00000000fee00fff] reserved | + | |
[ 0.000000] BIOS-e820: [mem 0x00000000fffc0000-0x00000000ffffffff] reserved | [ 0.000000] BIOS-e820: [mem 0x00000000fffc0000-0x00000000ffffffff] reserved | ||
- | [ 0.000000] BIOS-e820: [mem 0x0000000100000000-0x000000011fffffff] usable | + | [ 0.000000] BIOS-e820: [mem 0x0000000100000000-0x000000023fffffff] usable |
[ 0.000000] NX (Execute Disable) protection: active | [ 0.000000] NX (Execute Disable) protection: active | ||
- | [ 0.000000] SMBIOS 2.5 present. | + | [ 0.000000] SMBIOS 2.8 present. |
- | [ 0.000000] DMI: innotek GmbH VirtualBox/ | + | [ 0.000000] DMI: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.1-0-g3208b098f51a-prebuilt.qemu.org 04/01/2014 |
[ 0.000000] Hypervisor detected: KVM | [ 0.000000] Hypervisor detected: KVM | ||
+ | [ 0.000000] kvm-clock: Using msrs 4b564d01 and 4b564d00 | ||
+ | [ 0.000001] kvm-clock: using sched offset of 11342917026 cycles | ||
+ | [ 0.000003] clocksource: | ||
+ | [ 0.000010] tsc: Detected 2099.998 MHz processor | ||
+ | [ 0.001013] e820: update [mem 0x00000000-0x00000fff] usable ==> reserved | ||
+ | [ 0.001016] e820: remove [mem 0x000a0000-0x000fffff] usable | ||
+ | [ 0.001021] last_pfn = 0x240000 max_arch_pfn = 0x400000000 | ||
+ | [ 0.001058] MTRR map: 4 entries (3 fixed + 1 variable; max 19), built from 8 variable MTRRs | ||
+ | [ 0.001061] x86/PAT: Configuration [0-7]: WB WC UC- UC WB WP UC- WT | ||
+ | [ 0.001103] last_pfn = 0xbffda max_arch_pfn = 0x400000000 | ||
+ | [ 0.009594] found SMP MP-table at [mem 0x000f5bc0-0x000f5bcf] | ||
+ | [ 0.009621] Using GB pages for direct mapping | ||
+ | [ 0.009825] RAMDISK: [mem 0x3149c000-0x34a45fff] | ||
+ | [ 0.009836] ACPI: Early table checksum verification disabled | ||
+ | [ 0.009849] ACPI: RSDP 0x00000000000F5980 000014 (v00 BOCHS ) | ||
+ | [ 0.009857] ACPI: RSDT 0x00000000BFFE300C 000038 (v01 BOCHS BXPC | ||
+ | [ 0.009870] ACPI: FACP 0x00000000BFFE2DDE 000074 (v01 BOCHS BXPC | ||
+ | [ 0.009876] ACPI: DSDT 0x00000000BFFDF040 003D9E (v01 BOCHS BXPC | ||
+ | [ 0.009881] ACPI: FACS 0x00000000BFFDF000 000040 | ||
+ | [ 0.009885] ACPI: APIC 0x00000000BFFE2E52 000090 (v01 BOCHS BXPC | ||
+ | [ 0.009889] ACPI: SSDT 0x00000000BFFE2EE2 0000CA (v01 BOCHS VMGENID | ||
+ | [ 0.009893] ACPI: HPET 0x00000000BFFE2FAC 000038 (v01 BOCHS BXPC | ||
+ | [ 0.009898] ACPI: WAET 0x00000000BFFE2FE4 000028 (v01 BOCHS BXPC | ||
+ | [ 0.009901] ACPI: Reserving FACP table memory at [mem 0xbffe2dde-0xbffe2e51] | ||
+ | [ 0.009902] ACPI: Reserving DSDT table memory at [mem 0xbffdf040-0xbffe2ddd] | ||
+ | [ 0.009903] ACPI: Reserving FACS table memory at [mem 0xbffdf000-0xbffdf03f] | ||
+ | [ 0.009904] ACPI: Reserving APIC table memory at [mem 0xbffe2e52-0xbffe2ee1] | ||
+ | [ 0.009905] ACPI: Reserving SSDT table memory at [mem 0xbffe2ee2-0xbffe2fab] | ||
+ | [ 0.009906] ACPI: Reserving HPET table memory at [mem 0xbffe2fac-0xbffe2fe3] | ||
+ | [ 0.009906] ACPI: Reserving WAET table memory at [mem 0xbffe2fe4-0xbffe300b] | ||
+ | [ 0.010241] No NUMA configuration found | ||
--More-- | --More-- | ||
+ | [q] | ||
</ | </ | ||
Ligne 94: | Ligne 131: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
Usage: | Usage: | ||
Ligne 117: | Ligne 154: | ||
-p, --force-prefix | -p, --force-prefix | ||
-r, --raw print the raw message buffer | -r, --raw print the raw message buffer | ||
+ | | ||
-S, --syslog | -S, --syslog | ||
-s, --buffer-size < | -s, --buffer-size < | ||
-u, --userspace | -u, --userspace | ||
-w, --follow | -w, --follow | ||
+ | -W, --follow-new | ||
-x, --decode | -x, --decode | ||
-d, --show-delta | -d, --show-delta | ||
Ligne 129: | Ligne 168: | ||
| | ||
Suspending/ | Suspending/ | ||
+ | | ||
+ | | ||
-h, --help | -h, --help | ||
Ligne 163: | Ligne 204: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
- | trainee | + | trainee |
- | reboot | + | trainee |
- | trainee | + | trainee |
- | trainee | + | trainee |
- | reboot | + | trainee |
- | trainee | + | trainee |
- | reboot | + | reboot |
- | trainee | + | reboot |
- | reboot | + | trainee |
- | trainee | + | trainee |
- | trainee | + | reboot |
- | reboot | + | trainee |
- | trainee | + | trainee |
- | trainee | + | trainee |
- | trainee | + | reboot |
- | trainee | + | |
- | reboot | + | |
- | trainee | + | |
- | trainee | + | |
- | trainee | + | |
- | trainee | + | |
- | trainee | + | |
- | trainee | + | |
- | trainee | + | |
- | trainee | + | |
- | trainee | + | |
- | reboot | + | |
- | trainee | + | |
- | reboot | + | |
- | trainee | + | |
- | reboot | + | |
- | reboot | + | |
- | wtmp begins | + | wtmp begins |
</ | </ | ||
Ligne 203: | Ligne 227: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
Usage: | Usage: | ||
Ligne 238: | Ligne 262: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
- | Username | + | Username |
- | root pts/0 Thu Jun 3 09:01:46 -0400 2021 | + | root pts/1 Sat Sep 28 08:43:22 +0200 2024 |
- | bin **Never logged in** | + | bin |
- | daemon | + | daemon |
- | adm **Never logged in** | + | adm |
- | lp | + | lp **Never logged in** |
- | sync | + | sync **Never logged in** |
- | shutdown | + | shutdown |
- | halt | + | halt **Never logged in** |
- | mail | + | mail **Never logged in** |
- | operator | + | operator |
- | games **Never logged in** | + | games |
- | ftp **Never logged in** | + | ftp |
- | nobody | + | nobody |
- | dbus **Never logged in** | + | systemd-coredump |
- | systemd-coredump | + | dbus |
- | systemd-resolve | + | polkitd |
- | tss | + | avahi **Never logged in** |
- | polkitd | + | tss **Never logged in** |
- | unbound | + | colord |
- | libstoragemgmt | + | clevis |
- | cockpit-ws | + | rtkit **Never logged in** |
- | sssd | + | sssd **Never logged in** |
- | setroubleshoot | + | geoclue |
- | sshd **Never logged in** | + | libstoragemgmt |
- | chrony | + | systemd-oom |
- | tcpdump | + | setroubleshoot |
- | trainee | + | pipewire |
- | cockpit-wsinstance | + | flatpak |
- | rngd **Never logged in** | + | gdm tty1 Thu Sep 26 14:55:01 +0200 2024 |
- | gluster | + | cockpit-ws |
- | qemu **Never logged in** | + | cockpit-wsinstance |
- | rpc | + | gnome-initial-setup |
- | rpcuser | + | sshd |
- | saslauth | + | chrony |
- | radvd | + | dnsmasq |
- | dnsmasq | + | tcpdump |
- | fenestros2 | + | trainee |
- | fenestros1 | + | apache |
- | apache | + | fenestros2 |
+ | fenestros1 | ||
</ | </ | ||
Ligne 284: | Ligne 309: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
Usage: lastlog [options] | Usage: lastlog [options] | ||
Ligne 302: | Ligne 327: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
- | trainee | + | root |
- | trainee | + | root |
- | trqinee | + | |
- | btmp begins Thu Jun 3 09:51:07 2021 | + | btmp begins Thu Oct 19 18:29:22 2023 |
</ | </ | ||
Ligne 313: | Ligne 337: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
Usage: | Usage: | ||
Ligne 345: | Ligne 369: | ||
====1.4 - Le Fichier / | ====1.4 - Le Fichier / | ||
- | Sous RHEL/ | + | Sous RHEL 9 ce fichier contient la journalisation des opérations de gestion des authentifications : |
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
- | Jun 3 09:01:20 centos8 sshd[905]: Server listening on :: port 22. | + | Sep 27 14:08:31 redhat9 passwd[10515]: gkr-pam: couldn' |
- | Jun 3 09:01:39 centos8 sshd[1585]: Accepted | + | Sep 27 14:21:40 redhat9 su[10537]: pam_unix(su:session): session opened for user fenestros2(uid=1001) |
- | Jun 3 09:01:39 centos8 systemd[1590]: pam_unix(systemd-user:session): session opened for user trainee | + | Sep 27 14:21:50 redhat9 su[10537]: pam_unix(su:session): session |
- | Jun 3 09:01:39 centos8 sshd[1585]: pam_unix(sshd:session): session | + | Sep 27 14:22:01 redhat9 |
- | Jun 3 09:01:46 centos8 | + | Sep 27 14:23:49 redhat9 |
- | Jun 3 09:01:46 centos8 | + | Sep 27 17:23:32 redhat9 sshd[9392]: Received disconnect from 10.0.2.1 port 37560:11: disconnected |
- | Jun 3 09:51:05 centos8 login[1158]: pam_unix(login:auth): check pass; user unknown | + | Sep 27 17:23:32 redhat9 sshd[9392]: Disconnected from user trainee |
- | Jun 3 09:51:05 centos8 login[1158]: pam_unix(login:auth): authentication failure; logname=LOGIN uid=0 euid=0 tty=tty1 ruser= rhost= | + | Sep 27 17:23:32 redhat9 sshd[9357]: pam_unix(sshd:session): session closed for user trainee |
- | Jun 3 09:51:07 centos8 login[1158]: FAILED LOGIN 1 FROM tty1 FOR trqinee, Authentication failure | + | Sep 27 17:23:32 redhat9 su[10062]: pam_unix(su-l:session): session closed for user root |
- | Jun 3 09:51:18 centos8 unix_chkpwd[2400]: password check failed | + | Sep 28 08:09:13 redhat9 sshd[11965]: Accepted password for trainee from 10.0.2.1 port 42238 ssh2 |
- | Jun 3 09:51:18 centos8 login[1158]: pam_unix(login:auth): authentication failure; logname=LOGIN uid=0 euid=0 tty=tty1 ruser= rhost= | + | Sep 28 08:09:13 redhat9 systemd[11972]: pam_unix(systemd-user: |
- | Jun 3 09:51:20 centos8 login[1158]: FAILED LOGIN 2 FROM tty1 FOR trainee, Authentication failure | + | Sep 28 08:09:13 redhat9 sshd[11965]: pam_unix(sshd:session): session opened for user trainee(uid=1000) by trainee(uid=0) |
- | Jun 3 09:51:45 centos8 login[1158]: pam_unix(login:auth): check pass; user unknown | + | Sep 28 08:43:17 redhat9 sshd[12053]: Accepted password for trainee |
- | Jun 3 09:51:45 centos8 login[1158]: pam_unix(login:auth): authentication failure; logname=LOGIN | + | Sep 28 08:43:17 redhat9 sshd[12053]: pam_unix(sshd:session): session opened for user trainee(uid=1000) by trainee(uid=0) |
- | Jun 3 09:51:47 centos8 login[1158]: | + | Sep 28 08:43:22 redhat9 su[12102]: pam_unix(su-l:session): session opened for user root(uid=0) by trainee(uid=1000) |
</ | </ | ||
Ligne 370: | Ligne 394: | ||
===Le fichier / | ===Le fichier / | ||
- | Ce fichier contient les messages du système d' | + | Ce fichier contient les messages du système d' |
* des appels système, | * des appels système, | ||
Ligne 379: | Ligne 403: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
- | type=PROCTITLE | + | type=CRYPTO_KEY_USER |
- | type=USER_START msg=audit(1622728321.901: | + | type=CRED_ACQ |
- | type=CRED_REFR | + | type=USER_LOGIN |
- | type=CRED_DISP | + | type=USER_START |
- | type=USER_END | + | type=CRYPTO_KEY_USER |
- | type=SERVICE_STOP | + | type=BPF msg=audit(1727528068.011:1051): prog-id=189 op=LOAD |
- | type=USER_ACCT | + | type=BPF msg=audit(1727528068.011: |
- | type=CRED_ACQ | + | type=SERVICE_START msg=audit(1727528068.076: |
- | type=LOGIN msg=audit(1622728381.954: | + | type=USER_AUTH |
- | type=SYSCALL msg=audit(1622728381.954: | + | type=USER_ACCT |
- | type=PROCTITLE msg=audit(1622728381.954: | + | type=CRED_ACQ |
- | type=USER_START | + | type=USER_START |
- | type=CRED_REFR | + | type=SERVICE_STOP |
- | type=CRED_DISP | + | type=BPF msg=audit(1727528105.369: |
- | type=USER_END | + | type=BPF msg=audit(1727528105.369: |
</ | </ | ||
Ligne 404: | Ligne 428: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
# | # | ||
# This file controls the configuration of the audit daemon | # This file controls the configuration of the audit daemon | ||
Ligne 440: | Ligne 464: | ||
## | ## | ||
distribute_network = no | distribute_network = no | ||
- | q_depth = 400 | + | q_depth = 2000 |
overflow_action = SYSLOG | overflow_action = SYSLOG | ||
max_restarts = 10 | max_restarts = 10 | ||
plugin_dir = / | plugin_dir = / | ||
+ | end_of_event_timeout = 2 | ||
</ | </ | ||
Ligne 449: | Ligne 474: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
auditd: unrecognized option ' | auditd: unrecognized option ' | ||
Usage: auditd [-f] [-l] [-n] [-s disable|enable|nochange] [-c < | Usage: auditd [-f] [-l] [-n] [-s disable|enable|nochange] [-c < | ||
Ligne 459: | Ligne 484: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
## This file is automatically generated from / | ## This file is automatically generated from / | ||
-D | -D | ||
Ligne 465: | Ligne 490: | ||
-f 1 | -f 1 | ||
--backlog_wait_time 60000 | --backlog_wait_time 60000 | ||
+ | |||
+ | [root@redhat9 ~]# ls -l / | ||
+ | total 4 | ||
+ | -rw-------. 1 root root 244 Oct 19 2023 audit.rules | ||
+ | |||
+ | [root@redhat9 ~]# cat / | ||
+ | ## First rule - delete all | ||
+ | -D | ||
+ | |||
+ | ## Increase the buffers to survive stress events. | ||
+ | ## Make this bigger for busy systems | ||
+ | -b 8192 | ||
+ | |||
+ | ## This determine how long to wait in burst of events | ||
+ | --backlog_wait_time 60000 | ||
+ | |||
+ | ## Set failure mode to syslog | ||
+ | -f 1 | ||
</ | </ | ||
Ligne 471: | Ligne 514: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
usage: auditctl [options] | usage: auditctl [options] | ||
- | -a < | + | -a < |
- | -A < | + | -A < |
- | -b < | + | -b < |
- | allowed Default=64 | + | allowed Default=64 |
- | -c Continue through errors in rules | + | -c Continue through errors in rules |
- | -C f=f Compare collected fields if available: | + | -C f=f Compare collected fields if available: |
- | Field name, operator(=, | + | Field name, operator(=, |
- | -d < | + | -d < |
- | l=task, | + | l=task, |
- | a=never, | + | a=never, |
- | -D Delete all rules and watches | + | -D Delete all rules and watches |
- | -e [0..2] | + | -e [0..2] |
- | -f [0..2] | + | -f [0..2] |
- | 0=silent 1=printk 2=panic | + | 0=silent 1=printk 2=panic |
- | -F f=v Build rule: field name, operator(=, | + | -F f=v Build rule: field name, operator(=, |
- | > | + | > |
- | -h Help | + | -h Help |
- | -i Ignore errors when reading rules from file | + | -i Ignore errors when reading rules from file |
- | -k < | + | -k < |
- | -l List rules | + | -l List rules |
- | -m text | + | -m text |
- | -p [r|w|x|a] | + | -p [r|w|x|a] |
- | r=read, w=write, x=execute, a=attribute | + | r=read, w=write, x=execute, a=attribute |
- | -q < | + | -q < |
- | -r < | + | -r < |
- | -R < | + | -R < |
- | -s Report status | + | -s Report status |
- | -S syscall | + | -S syscall |
- | -t Trim directory watches | + | --signal < |
- | -v Version | + | -t Trim directory watches |
- | -w < | + | -v Version |
- | -W < | + | -w < |
- | --loginuid-immutable | + | -W < |
- | --backlog_wait_time | + | --loginuid-immutable |
- | --reset-lost | + | --backlog_wait_time |
+ | --reset-lost | ||
+ | --reset_backlog_wait_time_actual | ||
+ | There was an error while processing parameters | ||
</ | </ | ||
Ligne 519: | Ligne 565: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
Summary Report | Summary Report | ||
====================== | ====================== | ||
- | Range of time in logs: 05/08/2020 08:13:52.320 - 06/03/2021 10:20:02.028 | + | Range of time in logs: 10/19/2023 18:27:19.140 - 09/28/2024 14:57:20.231 |
- | Selected time for report: | + | Selected time for report: |
- | Number of changes in configuration: | + | Number of changes in configuration: |
- | Number of changes to accounts, groups, or roles: | + | Number of changes to accounts, groups, or roles: |
- | Number of logins: | + | Number of logins: |
- | Number of failed logins: | + | Number of failed logins: |
- | Number of authentications: | + | Number of authentications: |
- | Number of failed authentications: | + | Number of failed authentications: |
- | Number of users: | + | Number of users: |
- | Number of terminals: | + | Number of terminals: |
Number of host names: 4 | Number of host names: 4 | ||
- | Number of executables: | + | Number of executables: |
Number of commands: 11 | Number of commands: 11 | ||
Number of files: 0 | Number of files: 0 | ||
Number of AVC's: 0 | Number of AVC's: 0 | ||
- | Number of MAC events: | + | Number of MAC events: |
Number of failed syscalls: 0 | Number of failed syscalls: 0 | ||
- | Number of anomaly events: | + | Number of anomaly events: |
Number of responses to anomaly events: 0 | Number of responses to anomaly events: 0 | ||
- | Number of crypto events: | + | Number of crypto events: |
Number of integrity events: 0 | Number of integrity events: 0 | ||
Number of virt events: 0 | Number of virt events: 0 | ||
Number of keys: 0 | Number of keys: 0 | ||
- | Number of process IDs: 616 | + | Number of process IDs: 158 |
- | Number of events: | + | Number of events: |
</ | </ | ||
Ligne 553: | Ligne 599: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
usage: aureport [options] | usage: aureport [options] | ||
- | -a,--avc Avc report | + | |
- | -au, | + | -au, |
- | --comm Commands run report | + | --comm |
- | -c, | + | -c, |
- | -cr, | + | -cr, |
- | -e, | + | |
- | -f,--file File name report | + | --eoe-timeout secs End of Event Timeout |
- | --failed only failed events in report | + | |
- | -h,--host Remote Host name report | + | |
- | --help help | + | |
- | -i, | + | --failed |
- | -if, | + | -h, |
- | --input-logs Use the logs even if stdin is a pipe | + | --help |
- | --integrity Integrity event report | + | -i, |
- | -l,--login Login | + | -if,--input <Input File name> |
- | -k,--key Key | + | --input-logs |
- | -m,--mods Modification to accounts report | + | --integrity |
- | -ma,--mac Mandatory Access Control (MAC) report | + | -k,--key Key report |
- | -n, | + | -l,--login Login report |
- | -nc, | + | -m, |
- | --node <node name> Only events from a specific node | + | -ma, |
- | -p,--pid Pid report | + | -n, |
- | -r, | + | -nc, |
- | -s, | + | --node <node name> |
- | --success only success events in report | + | -p, |
- | --summary sorted totals for main object in report | + | -r, |
- | -t,--log Log time range report | + | -s, |
- | -te,--end [end date] [end time] ending date & time for reports | + | --success |
- | -tm, | + | --summary |
- | -ts, | + | -t, |
- | --tty Report about tty keystrokes | + | -te,--end [end date] [end time] ending date & time for reports |
- | -u,--user User name report | + | -tm, |
- | -v, | + | -ts,--start [start date] [start time] |
- | --virt Virtualization report | + | --tty |
- | -x, | + | -u, |
- | If no report is given, the summary report will be displayed | + | -v, |
+ | --virt | ||
+ | -x, | ||
+ | If no report is given, the summary report will be displayed | ||
</ | </ | ||
Ligne 598: | Ligne 647: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
- | ---- | + | |
- | time-> | + | |
- | type=USER_AUTH msg=audit(1598972728.209: | + | |
- | omain addr=? terminal=pts/ | + | |
---- | ---- | ||
- | time->Tue Sep 1 11:05:28 2020 | + | time->Thu Oct 19 18:29:20 2023 |
- | type=USER_ACCT | + | type=USER_AUTH |
- | ost.localdomain | + | tname=? |
---- | ---- | ||
- | time->Tue Sep 1 11:05:28 2020 | + | time->Thu Oct 19 18:29:31 2023 |
- | type=CRED_ACQ | + | type=USER_AUTH |
- | dr=? terminal=pts/ | + | su" hostname=? addr=? terminal=/dev/pts/0 res=success' |
---- | ---- | ||
- | time->Tue Sep 1 11:05:28 2020 | + | time->Thu Oct 19 18:29:31 2023 |
- | type=USER_START | + | type=USER_ACCT |
- | , | + | "/ |
---- | ---- | ||
- | time->Tue Sep 1 11:10:13 2020 | + | time->Thu Oct 19 18:29:31 2023 |
- | type=USER_END | + | type=CRED_ACQ |
- | pam_xauth | + | name=? addr=? terminal=/dev/pts/0 res=success' |
---- | ---- | ||
- | time->Tue Sep 1 11:10:13 2020 | + | time->Thu Oct 19 18:29:31 2023 |
- | type=CRED_DISP | + | type=USER_START |
- | ddr=? terminal=pts/ | + | am_systemd,pam_unix, |
---- | ---- | ||
- | time->Mon Apr 19 11:48:01 2021 | + | time->Thu Oct 19 18:35:21 2023 |
- | type=USER_AUTH msg=audit(1618847281.847:77): pid=1768 uid=1000 auid=1000 ses=1 subj=unconfined_u: | + | type=USER_AUTH msg=audit(1697733321.865:218): pid=6500 uid=1000 auid=1000 ses=6 subj=unconfined_u: |
- | ng.loc | + | su" hostname=? addr=? terminal=/dev/pts/1 res=success' |
---- | ---- | ||
- | time->Mon Apr 19 11:48:01 2021 | + | time->Thu Oct 19 18:35:21 2023 |
- | type=USER_ACCT msg=audit(1618847281.847:78): pid=1768 uid=1000 auid=1000 ses=1 subj=unconfined_u: | + | type=USER_ACCT msg=audit(1697733321.905:219): pid=6500 uid=1000 auid=1000 ses=6 subj=unconfined_u: |
- | 8.ittraining.loc | + | "/ |
---- | ---- | ||
- | time->Mon Apr 19 11:48:01 2021 | + | time->Thu Oct 19 18:35:21 2023 |
- | type=CRED_ACQ msg=audit(1618847281.847:79): pid=1768 uid=1000 auid=1000 ses=1 subj=unconfined_u: | + | type=CRED_ACQ msg=audit(1697733321.905:220): pid=6500 uid=1000 auid=1000 ses=6 subj=unconfined_u: |
- | ddr=? terminal=pts/ | + | name=? addr=? terminal=/dev/pts/1 res=success' |
---- | ---- | ||
- | time->Mon Apr 19 11:48:01 2021 | + | time->Thu Oct 19 18:35:21 2023 |
- | type=USER_START msg=audit(1618847281.883:80): pid=1768 uid=1000 auid=1000 ses=1 subj=unconfined_u: | + | type=USER_START msg=audit(1697733321.909:221): pid=6500 uid=1000 auid=1000 ses=6 subj=unconfined_u: |
- | ,pam_xauth acct=" | + | am_systemd, |
---- | ---- | ||
- | time->Mon Apr 19 12:04:39 2021 | + | time->Thu Oct 19 18:35:40 2023 |
- | type=USER_END msg=audit(1618848279.544:541): pid=1768 uid=1000 auid=1000 ses=1 subj=unconfined_u: | + | type=USER_END msg=audit(1697733340.703:222): pid=6500 uid=1000 auid=1000 ses=6 subj=unconfined_u: |
- | ,pam_xauth acct=" | + | m_systemd, |
---- | ---- | ||
- | time->Mon Apr 19 12:04:39 2021 | + | time->Thu Oct 19 18:35:40 2023 |
- | type=CRED_DISP msg=audit(1618848279.544:542): pid=1768 uid=1000 auid=1000 ses=1 subj=unconfined_u: | + | type=CRED_DISP msg=audit(1697733340.704:223): pid=6500 uid=1000 auid=1000 ses=6 subj=unconfined_u: |
- | addr=? terminal=pts/ | + | tname=? addr=? terminal=/dev/pts/1 res=success' |
---- | ---- | ||
- | time->Mon Apr 19 12:05:57 2021 | + | time->Wed Sep 25 10:15:06 2024 |
- | type=USER_AUTH msg=audit(1618848357.204:69): pid=4892 uid=1000 auid=1000 ses=1 subj=unconfined_u: | + | type=USER_AUTH msg=audit(1727252106.538:115): pid=1963 uid=1000 auid=1000 ses=2 subj=unconfined_u: |
- | addr=? terminal=pts/ | + | su" hostname=? addr=? terminal=/dev/pts/0 res=success' |
---- | ---- | ||
- | time->Mon Apr 19 12:06:03 2021 | + | time->Wed Sep 25 10:15:06 2024 |
- | type=USER_AUTH | + | type=USER_ACCT |
- | ng.loc | + | "/ |
---- | ---- | ||
+ | time-> | ||
+ | type=CRED_ACQ msg=audit(1727252106.579: | ||
--More-- | --More-- | ||
+ | [q] | ||
</ | </ | ||
Ligne 662: | Ligne 710: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
usage: ausearch [options] | usage: ausearch [options] | ||
- | -a,--event <Audit event id> | + | |
- | --arch < | + | --arch < |
- | -c, | + | -c, |
- | --checkpoint < | + | --checkpoint < |
- | --debug Write malformed events that are skipped to stderr | + | --debug |
- | -e, | + | -e, |
- | -f, | + | |
- | --format [raw|default|interpret|csv|text] results format options | + | --eoe-timeout secs End of Event timeout |
- | -ga, | + | --extra-keys |
- | -ge, | + | --extra-labels |
- | group id | + | --extra-obj2 |
- | -gi,--gid <Group Id> search based on group id | + | --extra-time |
- | -h,--help help | + | |
- | -hn,--host <Host Name> search based on remote host name | + | --format [raw|default|interpret|csv|text] results format options |
- | -i, | + | -ga, |
- | -if, | + | -ge, |
- | --input-logs Use the logs even if stdin is a pipe | + | group id |
- | --just-one Emit just one event | + | -gi,--gid <Group Id> |
- | -k, | + | -h, |
- | -l, --line-buffered Flush output on every line | + | -hn,--host <Host Name> |
- | -m, | + | -i, |
- | -n, | + | -if,--input <Input File name> |
- | -o, | + | --input-logs |
- | -p, | + | --just-one |
- | -pp,--ppid <Parent Process id> | + | -k, |
- | -r,--raw output is completely unformatted | + | -l, --line-buffered |
- | -sc, | + | -m, |
- | -se, | + | -n, |
- | object | + | -o, |
- | --session <login session id> | + | -p, |
- | -su, | + | -pp,--ppid <Parent Process id> |
- | -sv, | + | -r, |
- | success value | + | -sc, |
- | -te,--end [end date] [end time] ending date & time for search | + | -se, |
- | -ts, | + | |
- | -tm, | + | --session <login session id> |
- | -ua, | + | -su, |
- | -ue, | + | -sv, |
- | user id | + | success value |
- | -ui,--uid <User Id> search based on user id | + | -te,--end [end date] [end time] ending date & time for search |
- | -ul, | + | -ts,--start [start date] [start time] |
- | -uu,--uuid <guest UUID> search for events related to the virtual | + | -tm, |
- | machine with the given UUID. | + | -ua, |
- | -v, | + | -ue, |
- | -vm, | + | user id |
- | machine with the name. | + | -ui,--uid <User Id> |
- | -w,--word string matches are whole word | + | -ul, |
- | -x, | + | -uu,--uuid <guest UUID> |
+ | machine with the given UUID. | ||
+ | -v, | ||
+ | -vm, | ||
+ | machine with the name. | ||
+ | -w, | ||
+ | -x, | ||
</ | </ | ||
Ligne 723: | Ligne 777: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
- | Jun 3 10:15:01 centos8 | + | Sep 28 13:33:57 redhat9 |
- | Jun 3 10:16:01 centos8 systemd[1]: Started Session 77 of user trainee. | + | Sep 28 13:35:04 redhat9 cupsd[5736]: REQUEST localhost - - "POST / HTTP/1.1" 200 182 Renew-Subscription successful-ok |
- | Jun 3 10:16:01 centos8 systemd[1]: session-77.scope: Succeeded. | + | Sep 28 14:33:24 redhat9 cupsd[5736]: REQUEST localhost |
- | Jun 3 10:17:01 centos8 | + | Sep 28 14:54:27 redhat9 |
- | Jun 3 10:17:01 centos8 | + | Sep 28 14:54:27 redhat9 |
- | Jun 3 10:18:01 centos8 | + | Sep 28 14:54:28 redhat9 |
- | Jun 3 10:18:01 centos8 | + | Sep 28 14:54:28 redhat9 |
- | Jun 3 10:19:01 centos8 systemd[1]: Started Session 80 of user trainee. | + | Sep 28 14:54:35 redhat9 su[12662]: (to root) trainee |
- | Jun 3 10:19:01 centos8 | + | Sep 28 14:55:05 redhat9 |
- | Jun 3 10:20:02 centos8 | + | Sep 28 14:57:20 redhat9 |
- | Jun 3 10:20:02 centos8 | + | Sep 28 14:57:20 redhat9 |
- | Jun 3 10:21:01 centos8 | + | Sep 28 14:57:20 redhat9 |
- | Jun 3 10:21:01 centos8 | + | Sep 28 14:57:20 redhat9 |
- | Jun 3 10:22:01 centos8 | + | Sep 28 15:02:37 redhat9 |
- | Jun 3 10:22:01 centos8 | + | Sep 28 15:02:37 redhat9 |
</ | </ | ||
Ligne 751: | Ligne 805: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
- | total 2448 | + | total 1952 |
- | drwxr-xr-x. 2 root | + | drwxr-xr-x. 2 root |
- | drwx------. 2 root | + | drwx------. 2 root |
- | -rw-------. 1 root | + | -rw-------. 1 root |
- | -rw-------. 1 root | + | -rw-------. 1 root |
- | -rw-------. 1 root | + | -rw-rw----. 1 root |
- | -rw-------. 1 root | + | drwxr-x---. 2 chrony chrony |
- | -rw-------. 1 root | + | -rw-------. 1 root |
- | -rw-rw----. 1 root | + | drwxr-xr-x. 2 lp |
- | -rw-rw----. 1 root | + | -rw-r--r--. 1 root |
- | drwxr-xr-x. 2 chrony chrony | + | -rw-r--r--. 1 root |
- | -rw-------. 1 root | + | -rw-r--r--. 1 root |
- | -rw-------. 1 root | + | -rw-r-----. 1 root |
- | -rw-------. 1 root | + | drwx--x--x. 2 root gdm 6 Jan 18 2024 gdm |
- | -rw-------. 1 root | + | -rw-r--r--. 1 root |
- | -rw-------. 1 root | + | drwx------. |
- | -rw-r--r--. 1 root | + | drwx------. |
- | -rw-------. 1 root | + | -rw-------. 1 root |
- | -rw-------. 1 root | + | -rw-rw-r--. 1 root |
- | -rw-r--r--. 1 root | + | -rw-------. 1 root |
- | -rw-r--r--. 1 root | + | -rw-------. 1 root |
- | -rw-r-----. 1 root | + | drwx------. |
- | drwxr-xr-x. 2 root root | + | drwxr-xr-x. 2 root |
- | -rw-------. 1 root | + | lrwxrwxrwx. 1 root |
- | -rw-r--r--. 1 root | + | drwxr-xr-x. 2 root |
- | -rw-------. | + | drwx------. 3 root |
- | -rw-------. 1 root | + | -rw-------. 1 root |
- | -rw-rw-r--. 1 root | + | drwx------. |
- | drwx------. 3 root | + | -rw-------. 1 root |
- | -rw-------. 1 root | + | drwxr-x---. 2 sssd |
- | -rw-------. 1 root | + | -rw-------. 1 root |
- | -rw-------. | + | drwxr-xr-x. 2 root |
- | -rw-------. 1 root | + | -rw-rw-r--. 1 root |
- | -rw-------. 1 root | + | |
- | -rw-------. 1 root | + | |
- | -rw-------. 1 root | + | |
- | -rw-------. 1 root | + | |
- | drwx------. 2 root | + | |
- | drwx------. 3 root | + | |
- | -rw-------. | + | |
- | -rw-------. 1 root | + | |
- | -rw-------. | + | |
- | -rw-------. 1 root | + | |
- | -rw-------. 1 root | + | |
- | -rw-------. 1 root | + | |
- | -rw-------. 1 root | + | |
- | -rw-------. 1 root | + | |
- | drwxr-x---. 2 sssd | + | |
- | drwxr-xr-x. 3 root | + | |
- | drwxr-xr-x. 2 root | + | |
- | -rw-rw-r--. 1 root | + | |
</ | </ | ||
Ligne 826: | Ligne 862: | ||
* transmettre les informations à une application liée à rsyslog via un tube (par exemple, **|logrotate**). | * transmettre les informations à une application liée à rsyslog via un tube (par exemple, **|logrotate**). | ||
- | Sous RHEL/CentOS, le daemon rsyslog est configuré par l' | + | Sous RHEL 9, le daemon rsyslog est configuré par l' |
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
# Options for rsyslogd | # Options for rsyslogd | ||
# Syslogd options are deprecated since rsyslog v3. | # Syslogd options are deprecated since rsyslog v3. | ||
Ligne 881: | Ligne 917: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
# rsyslog configuration file | # rsyslog configuration file | ||
Ligne 887: | Ligne 923: | ||
# or latest version online at http:// | # or latest version online at http:// | ||
# If you experience problems, see http:// | # If you experience problems, see http:// | ||
+ | |||
+ | #### GLOBAL DIRECTIVES #### | ||
+ | |||
+ | # Where to place auxiliary files | ||
+ | global(workDirectory="/ | ||
+ | |||
+ | # Use default timestamp format | ||
+ | module(load=" | ||
#### MODULES #### | #### MODULES #### | ||
- | module(load=" | + | module(load=" |
| | ||
- | | + | |
- | module(load=" | + | module(load=" |
+ | | ||
+ | | ||
| | ||
# | # | ||
# | # | ||
+ | |||
+ | # Include all config files in / | ||
+ | include(file="/ | ||
# Provides UDP syslog reception | # Provides UDP syslog reception | ||
Ligne 907: | Ligne 956: | ||
# | # | ||
# | # | ||
- | |||
- | #### GLOBAL DIRECTIVES #### | ||
- | |||
- | # Where to place auxiliary files | ||
- | global(workDirectory="/ | ||
- | |||
- | # Use default timestamp format | ||
- | module(load=" | ||
- | |||
- | # Include all config files in / | ||
- | include(file="/ | ||
#### RULES #### | #### RULES #### | ||
Ligne 951: | Ligne 989: | ||
# ### sample forwarding rule ### | # ### sample forwarding rule ### | ||
# | # | ||
- | # An on-disk queue is created for this action. If the remote host is | + | # # An on-disk queue is created for this action. If the remote host is |
- | # down, messages are spooled to disk and sent when it is up again. | + | # # down, messages are spooled to disk and sent when it is up again. |
# | # | ||
# | # | ||
Ligne 958: | Ligne 996: | ||
# | # | ||
# | # | ||
- | # Remote Logging (we use TCP for reliable delivery) | + | # # Remote Logging (we use TCP for reliable delivery) |
- | # remote_host is: name/ip, e.g. 192.168.0.1, | + | # # remote_host is: name/ip, e.g. 192.168.0.1, |
# | # | ||
</ | </ | ||
Ligne 984: | Ligne 1022: | ||
| module(load=" | | module(load=" | ||
- | Dans le fichier **/ | + | Dans le fichier **/ |
< | < | ||
Ligne 990: | Ligne 1028: | ||
#### MODULES #### | #### MODULES #### | ||
- | module(load=" | + | module(load=" |
| | ||
- | | + | |
- | module(load=" | + | module(load=" |
+ | | ||
+ | | ||
| | ||
# | # | ||
# | # | ||
- | |||
- | # Provides UDP syslog reception | ||
- | # for parameters see http:// | ||
- | # | ||
- | # | ||
- | |||
- | # Provides TCP syslog reception | ||
- | # for parameters see http:// | ||
- | # | ||
- | # | ||
... | ... | ||
</ | </ | ||
Ligne 1016: | Ligne 1046: | ||
# Provides UDP syslog reception | # Provides UDP syslog reception | ||
# for parameters see http:// | # for parameters see http:// | ||
- | module(load=" | + | #module(load=" |
- | input(type=" | + | #input(type=" |
# Provides TCP syslog reception | # Provides TCP syslog reception | ||
# for parameters see http:// | # for parameters see http:// | ||
- | module(load=" | + | #module(load=" |
- | input(type=" | + | #input(type=" |
... | ... | ||
</ | </ | ||
Ligne 1030: | Ligne 1060: | ||
</ | </ | ||
- | Pour envoyer l' | + | Pour envoyer l' |
< | < | ||
Ligne 1036: | Ligne 1066: | ||
# ### sample forwarding rule ### | # ### sample forwarding rule ### | ||
# | # | ||
- | # An on-disk queue is created for this action. If the remote host is | + | # # An on-disk queue is created for this action. If the remote host is |
- | # down, messages are spooled to disk and sent when it is up again. | + | # # down, messages are spooled to disk and sent when it is up again. |
# | # | ||
# | # | ||
Ligne 1043: | Ligne 1073: | ||
# | # | ||
# | # | ||
- | # Remote Logging (we use TCP for reliable delivery) | + | # # Remote Logging (we use TCP for reliable delivery) |
- | # remote_host is: name/ip, e.g. 192.168.0.1, | + | # # remote_host is: name/ip, e.g. 192.168.0.1, |
- | Target=" | + | #Target=" |
... | ... | ||
</ | </ | ||
Ligne 1115: | Ligne 1145: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
</ | </ | ||
Ligne 1121: | Ligne 1151: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
- | Jun 3 12:55:01 centos8 systemd[1]: session-237.scope: Succeeded. | + | Sep 28 15:05:26 redhat9 dnf[12735]: Extra Packages for Enterprise Linux 9 openh264 |
- | Jun 3 12:56:01 centos8 systemd[1]: Started Session 238 of user trainee. | + | Sep 28 15:05:26 redhat9 dnf[12735]: Extra Packages for Enterprise Linux 9 - Next - 199 kB/s | 26 kB 00:00 |
- | Jun 3 12:56:01 centos8 systemd[1]: session-238.scope: Succeeded. | + | Sep 28 15:05:27 redhat9 dnf[12735]: Red Hat Enterprise Linux 9 for x86_64 |
- | Jun 3 12:57:01 centos8 systemd[1]: Started Session 239 of user trainee. | + | Sep 28 15:05:27 redhat9 dnf[12735]: Red Hat Enterprise Linux 9 for x86_64 - BaseOS |
- | Jun 3 12:57:01 centos8 systemd[1]: session-239.scope: Succeeded. | + | Sep 28 15:05:28 redhat9 dnf[12735]: Red Hat CodeReady Linux Builder for RHEL 9 x86_ 34 kB/s | 4.5 kB 00:00 |
- | Jun 3 12:58:01 centos8 systemd[1]: Started Session 240 of user trainee. | + | Sep 28 15:05:28 redhat9 dnf[12735]: Metadata cache created. |
- | Jun 3 12:58:01 centos8 | + | Sep 28 15:05:28 redhat9 |
- | Jun 3 12:58:55 centos8 trainee[5139]: Linux est super | + | Sep 28 15:05:28 redhat9 systemd[1]: Finished dnf makecache. |
- | Jun 3 12:59:01 centos8 | + | Sep 28 15:05:28 redhat9 |
- | Jun 3 12:59:01 centos8 systemd[1]: session-241.scope: | + | Sep 28 15:15:29 redhat9 root[12751]: Linux est super |
</ | </ | ||
Ligne 1137: | Ligne 1167: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
Usage: | Usage: | ||
Ligne 1184: | Ligne 1214: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
# see "man logrotate" | # see "man logrotate" | ||
+ | |||
+ | # global options do not affect preceding include directives | ||
+ | |||
# rotate log files weekly | # rotate log files weekly | ||
weekly | weekly | ||
Ligne 1201: | Ligne 1234: | ||
#compress | #compress | ||
- | # RPM packages drop log rotation information into this directory | + | # packages drop log rotation information into this directory |
include / | include / | ||
Ligne 1225: | Ligne 1258: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
Usage: logrotate [OPTION...] < | Usage: logrotate [OPTION...] < | ||
- | -d, --debug | + | -d, --debug |
- | | + | |
-f, --force | -f, --force | ||
-m, --mail=command | -m, --mail=command | ||
-s, --state=statefile | -s, --state=statefile | ||
+ | --skip-state-lock | ||
-v, --verbose | -v, --verbose | ||
-l, --log=logfile | -l, --log=logfile | ||
Ligne 1243: | Ligne 1276: | ||
=====LAB #5 - La Journalisation avec journald===== | =====LAB #5 - La Journalisation avec journald===== | ||
- | Sous RHEL/CentOS 8, les fichiers de Syslog sont gardés pour une question de compatibilité. Cependant, tous les journaux sont d' | + | Sous RHEL 9, les fichiers de Syslog sont gardés pour une question de compatibilité. Cependant, tous les journaux sont d' |
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
total 0 | total 0 | ||
- | drwxr-s---+ 2 root systemd-journal 60 Jun 3 09:01 de79af4f226d480fa7d3fec4cabbf97a | + | drwxr-s---+ 2 root systemd-journal 60 Sep 25 12:44 5a35a3eb625c45cea1d33535723e791f |
</ | </ | ||
A l' | A l' | ||
- | Pour rendre les journaux permenants, il faut créer | + | La configuration de ce comportement se trouve dans le fichier |
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
- | [root@centos8 ~]# ls -l / | + | # This file is part of systemd. |
- | total 0 | + | # |
- | [root@centos8 ~]# systemctl restart | + | # systemd |
- | [root@centos8 ~]# ls -l / | + | # terms of the GNU Lesser General Public License as published by the Free |
- | ls: cannot access | + | # Software Foundation; either version 2.1 of the License, or (at your option) |
- | [root@centos8 ~]# ls -l /var/log/journal/ | + | # any later version. |
- | total 0 | + | # |
- | drwxr-xr-x. 2 root root 28 Jun 3 13:03 de79af4f226d480fa7d3fec4cabbf97a | + | # Entries in this file show the compile time defaults. Local configuration |
+ | # should be created by either modifying this file, or by creating "drop-ins" in | ||
+ | # the journald.conf.d/ subdirectory. The latter is generally recommended. | ||
+ | # Defaults can be restored by simply deleting this file and all drop-ins. | ||
+ | # | ||
+ | # Use 'systemd-analyze cat-config systemd/journald.conf' | ||
+ | # | ||
+ | # See journald.conf(5) for details. | ||
+ | |||
+ | [Journal] | ||
+ | #Storage=auto | ||
+ | # | ||
+ | #Seal=yes | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | #TTYPath=/dev/console | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | # | ||
+ | Audit= | ||
</ | </ | ||
- | Journald ne peut pas envoyer les traces à un autre ordinateur. Pour utiliser un serveur | + | La valeur |
+ | |||
+ | | ||
+ | * **persistent** - le journal est persistant et est stocké | ||
+ | * **volatile** - le journal est stocké dans un fichier | ||
+ | |||
+ | Pour rendre le journal permenant, modifiez le fichier | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 ~]# vi / |
+ | [root@redhat9 | ||
# This file is part of systemd. | # This file is part of systemd. | ||
# | # | ||
- | # systemd is free software; you can redistribute it and/or modify it | + | # systemd is free software; you can redistribute it and/or modify it under the |
- | # | + | # terms of the GNU Lesser General Public License as published by the Free |
- | # | + | # Software Foundation; either version 2.1 of the License, or (at your option) |
- | # | + | # |
# | # | ||
- | # Entries in this file show the compile time defaults. | + | # Entries in this file show the compile time defaults. |
- | # You can change settings | + | # should be created |
- | # Defaults can be restored by simply deleting this file. | + | # the journald.conf.d/ |
+ | # Defaults can be restored by simply deleting this file and all drop-ins. | ||
+ | # | ||
+ | # Use ' | ||
# | # | ||
# See journald.conf(5) for details. | # See journald.conf(5) for details. | ||
[Journal] | [Journal] | ||
- | #Storage=auto | + | Storage=auto |
# | # | ||
#Seal=yes | #Seal=yes | ||
Ligne 1303: | Ligne 1385: | ||
# | # | ||
# | # | ||
- | ForwardToSyslog=yes | ||
# | # | ||
# | # | ||
Ligne 1314: | Ligne 1395: | ||
# | # | ||
# | # | ||
+ | # | ||
+ | Audit= | ||
</ | </ | ||
+ | |||
+ | Créez le répertoire **/ | ||
+ | |||
+ | < | ||
+ | [root@redhat9 ~]# mkdir / | ||
+ | [root@redhat9 ~]# ls -l / | ||
+ | total 0 | ||
+ | </ | ||
+ | |||
+ | Redémarrez votre VM : | ||
+ | |||
+ | < | ||
+ | [root@redhat9 ~]# reboot | ||
+ | [root@redhat9 ~]# Connection to 10.0.2.101 closed by remote host. | ||
+ | Connection to 10.0.2.101 closed. | ||
+ | </ | ||
+ | |||
+ | Reconnectez-vous à votre VM : | ||
+ | |||
+ | < | ||
+ | [trainee@redhat9 ~]$ su - | ||
+ | Password: fenestros | ||
+ | |||
+ | [root@redhat9 ~]# ls -l / | ||
+ | total 0 | ||
+ | |||
+ | [root@redhat9 ~]# ls -l / | ||
+ | total 0 | ||
+ | drwxr-sr-x+ 2 root systemd-journal 53 Sep 28 15:39 5a35a3eb625c45cea1d33535723e791f | ||
+ | </ | ||
+ | |||
+ | Journald ne peut pas envoyer de traces à un autre ordinateur. Pour utiliser un serveur de journalisation distant il faut donc ajouter la directive **ForwardToSyslog=yes** au fichier de configuration de journald, **/ | ||
====5.1 - Consultation des Journaux==== | ====5.1 - Consultation des Journaux==== | ||
Ligne 1321: | Ligne 1436: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
- | -- Logs begin at Thu 2021-06-03 09:01:10 EDT, end at Thu 2021-06-03 13:08:01 EDT. -- | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: Linux version |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: Linux version | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: The list of certified hardware and cloud instances for Red Hat Enterprise Linux 9 can be viewed at the Red Hat Ecosystem Catalog, https:// |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: Command line: BOOT_IMAGE=(hd0, | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: Command line: BOOT_IMAGE=(hd0, |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: x86/fpu: Supporting XSAVE feature 0x001: 'x87 floating point registers' | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: x86/fpu: Supporting XSAVE feature 0x001: 'x87 floating point registers' |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: x86/fpu: Supporting XSAVE feature 0x002: 'SSE registers' | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: x86/fpu: Supporting XSAVE feature 0x002: 'SSE registers' |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: x86/fpu: Supporting XSAVE feature 0x004: 'AVX registers' | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: x86/fpu: Supporting XSAVE feature 0x004: 'AVX registers' |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: x86/fpu: xstate_offset[2]: | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: x86/fpu: xstate_offset[2]: |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: x86/fpu: Enabled xstate features 0x7, context size is 832 bytes, using ' | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: x86/fpu: Enabled xstate features 0x7, context size is 832 bytes, using ' |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-provided physical RAM map: | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: signal: max sigframe size: 1776 |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x0000000000000000-0x000000000009fbff] usable | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: BIOS-provided physical RAM map: |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x000000000009fc00-0x000000000009ffff] reserved | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: BIOS-e820: [mem 0x0000000000000000-0x000000000009fbff] usable |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x00000000000f0000-0x00000000000fffff] reserved | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: BIOS-e820: [mem 0x000000000009fc00-0x000000000009ffff] reserved |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x0000000000100000-0x00000000dffeffff] usable | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: BIOS-e820: [mem 0x00000000000f0000-0x00000000000fffff] reserved |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x00000000dfff0000-0x00000000dfffffff] ACPI data | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: BIOS-e820: [mem 0x0000000000100000-0x00000000bffd9fff] usable |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x00000000fec00000-0x00000000fec00fff] reserved | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: BIOS-e820: [mem 0x00000000bffda000-0x00000000bfffffff] reserved |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x00000000fee00000-0x00000000fee00fff] reserved | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: BIOS-e820: [mem 0x00000000feffc000-0x00000000feffffff] reserved |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x00000000fffc0000-0x00000000ffffffff] reserved | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: BIOS-e820: [mem 0x00000000fffc0000-0x00000000ffffffff] reserved |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x0000000100000000-0x000000011fffffff] usable | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: BIOS-e820: [mem 0x0000000100000000-0x000000023fffffff] usable |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: NX (Execute Disable) protection: active | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: NX (Execute Disable) protection: active |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: SMBIOS 2.5 present. | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: SMBIOS 2.8 present. |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: DMI: innotek GmbH VirtualBox/ | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: DMI: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.1-0-g3208b098f51a-prebuilt.qemu.org 04/01/2014 |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: Hypervisor detected: KVM | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: Hypervisor detected: KVM |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: kvm-clock: Using msrs 4b564d01 and 4b564d00 | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: kvm-clock: Using msrs 4b564d01 and 4b564d00 |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: kvm-clock: cpu 0, msr 114801001, primary cpu clock | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: kvm-clock: using sched offset of 269552729537899 |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: kvm-clock: using sched offset of 5675771878 | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: clocksource: |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: clocksource: | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: tsc: Detected |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: tsc: Detected | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: e820: update [mem 0x00000000-0x00000fff] usable ==> reserved |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: e820: update [mem 0x00000000-0x00000fff] usable ==> reserved | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: e820: remove [mem 0x000a0000-0x000fffff] usable |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: e820: remove [mem 0x000a0000-0x000fffff] usable | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: last_pfn = 0x240000 |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: last_pfn = 0x120000 | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: MTRR map: 4 entries (3 fixed + 1 variable; max 19), built from 8 variable |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: MTRR default type: uncachable | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: x86/PAT: Configuration [0-7]: WB |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: MTRR variable | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: last_pfn = 0xbffda |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: Disabled | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: found SMP MP-table at [mem 0x000f5bc0-0x000f5bcf] |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: x86/PAT: MTRRs disabled, skipping PAT initialization too. | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: CPU MTRRs all blank - virtualized system. | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: x86/PAT: Configuration [0-7]: WB | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: last_pfn = 0xdfff0 | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: found SMP MP-table at [mem 0x0009fff0-0x0009ffff] | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: WAET 0x00000000BFFE2FE4 000028 (v01 BOCHS BXPC |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: Reserving FACP table memory at [mem 0xbffe2dde-0xbffe2e51] |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: Reserving DSDT table memory at [mem 0xbffdf040-0xbffe2ddd] |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: Reserving FACS table memory at [mem 0xbffdf000-0xbffdf03f] |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: Reserving APIC table memory at [mem 0xbffe2e52-0xbffe2ee1] |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: ACPI: Early table checksum verification disabled | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: Reserving SSDT table memory at [mem 0xbffe2ee2-0xbffe2fab] |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: ACPI: RSDP 0x00000000000E0000 000024 (v02 VBOX ) | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: Reserving HPET table memory at [mem 0xbffe2fac-0xbffe2fe3] |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: ACPI: XSDT 0x00000000DFFF0030 00003C (v01 VBOX | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: Reserving WAET table memory at [mem 0xbffe2fe4-0xbffe300b] |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: ACPI: FACP 0x00000000DFFF00F0 0000F4 (v04 VBOX | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: ACPI: DSDT 0x00000000DFFF0480 002325 (v02 VBOX | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: ACPI: FACS 0x00000000DFFF0200 000040 | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: NODE_DATA(0) allocated [mem 0x23ffd5000-0x23fffffff] |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: | + | lines 1-55 |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: | + | |
- | lines 1-57 | + | |
</ | </ | ||
Ligne 1391: | Ligne 1504: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
- | -- Logs begin at Thu 2021-06-03 09:01:10 EDT, end at Thu 2021-06-03 13:10:01 EDT. -- | + | Sep 28 15:37:18 redhat9.ittraining.loc |
- | Jun 03 10:01:01 centos8.ittraining.loc | + | Sep 28 15:37:18 redhat9.ittraining.loc |
- | Jun 03 10:01:01 centos8.ittraining.loc anacron[2575]: | + | Sep 28 15:37:18 redhat9.ittraining.loc |
- | Jun 03 10:01:01 centos8.ittraining.loc | + | Sep 28 15:37:18 redhat9.ittraining.loc |
- | Jun 03 10:16:01 centos8.ittraining.loc anacron[2575]: | + | |
- | Jun 03 10:16:01 centos8.ittraining.loc | + | |
- | Jun 03 10:16:01 centos8.ittraining.loc | + | |
</ | </ | ||
<WRAP center round important 60%> | <WRAP center round important 60%> | ||
- | **Important** : Rappelez-vous que sous RHEL/CentOS 8 le répertoire **/sbin** est un lien symbolique vers **/ | + | **Important** : Rappelez-vous que sous RHEL9 le répertoire **/sbin** est un lien symbolique vers **/ |
</ | </ | ||
Ligne 1410: | Ligne 1520: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
- | -- Logs begin at Thu 2021-06-03 09:01:10 EDT, end at Thu 2021-06-03 13:11:01 EDT. -- | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: Linux version |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: Linux version | + | el9) #1 SMP PREEMPT_DYNAMIC Fri Sep 13 12:41:50 EDT 2024 |
- | 8.3.1 20191121 | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: The list of certified hardware and cloud instances for Red Hat Enterprise Linux 9 can be viewed at the Red Hat Ecosystem Catalog, https:// |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: Command line: BOOT_IMAGE=(hd0, | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: Command line: BOOT_IMAGE=(hd0, |
- | c-0d59-45be-bd73-d292b80be33c | + | apper/rhel-swap rd.lvm.lv=rhel/ |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: x86/fpu: Supporting XSAVE feature 0x001: 'x87 floating point registers' | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: x86/fpu: Supporting XSAVE feature 0x001: 'x87 floating point registers' |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: x86/fpu: Supporting XSAVE feature 0x002: 'SSE registers' | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: x86/fpu: Supporting XSAVE feature 0x002: 'SSE registers' |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: x86/fpu: Supporting XSAVE feature 0x004: 'AVX registers' | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: x86/fpu: Supporting XSAVE feature 0x004: 'AVX registers' |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: x86/fpu: xstate_offset[2]: | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: x86/fpu: xstate_offset[2]: |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: x86/fpu: Enabled xstate features 0x7, context size is 832 bytes, using ' | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: x86/fpu: Enabled xstate features 0x7, context size is 832 bytes, using ' |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-provided physical RAM map: | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: signal: max sigframe size: 1776 |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x0000000000000000-0x000000000009fbff] usable | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: BIOS-provided physical RAM map: |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x000000000009fc00-0x000000000009ffff] reserved | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: BIOS-e820: [mem 0x0000000000000000-0x000000000009fbff] usable |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x00000000000f0000-0x00000000000fffff] reserved | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: BIOS-e820: [mem 0x000000000009fc00-0x000000000009ffff] reserved |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x0000000000100000-0x00000000dffeffff] usable | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: BIOS-e820: [mem 0x00000000000f0000-0x00000000000fffff] reserved |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x00000000dfff0000-0x00000000dfffffff] ACPI data | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: BIOS-e820: [mem 0x0000000000100000-0x00000000bffd9fff] usable |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x00000000fec00000-0x00000000fec00fff] reserved | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: BIOS-e820: [mem 0x00000000bffda000-0x00000000bfffffff] reserved |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x00000000fee00000-0x00000000fee00fff] reserved | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: BIOS-e820: [mem 0x00000000feffc000-0x00000000feffffff] reserved |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x00000000fffc0000-0x00000000ffffffff] reserved | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: BIOS-e820: [mem 0x00000000fffc0000-0x00000000ffffffff] reserved |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: BIOS-e820: [mem 0x0000000100000000-0x000000011fffffff] usable | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: BIOS-e820: [mem 0x0000000100000000-0x000000023fffffff] usable |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: NX (Execute Disable) protection: active | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: NX (Execute Disable) protection: active |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: SMBIOS 2.5 present. | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: SMBIOS 2.8 present. |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: DMI: innotek GmbH VirtualBox/ | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: DMI: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.1-0-g3208b098f51a-prebuilt.qemu.org 04/01/2014 |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: Hypervisor detected: KVM | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: Hypervisor detected: KVM |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: kvm-clock: Using msrs 4b564d01 and 4b564d00 | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: kvm-clock: Using msrs 4b564d01 and 4b564d00 |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: kvm-clock: cpu 0, msr 114801001, primary cpu clock | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: kvm-clock: using sched offset of 269552729537899 |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: kvm-clock: using sched offset of 5675771878 | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: clocksource: |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: clocksource: | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: tsc: Detected |
- | 590591483 | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: e820: update [mem 0x00000000-0x00000fff] usable ==> reserved |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: tsc: Detected | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: e820: remove [mem 0x000a0000-0x000fffff] usable |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: e820: update [mem 0x00000000-0x00000fff] usable ==> reserved | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: last_pfn = 0x240000 max_arch_pfn = 0x400000000 |
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: MTRR map: 4 entries (3 fixed + 1 variable; max 19), built from 8 variable MTRRs | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: x86/PAT: Configuration [0-7]: WB WC UC- UC WB WP UC- WT | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: last_pfn = 0xbffda max_arch_pfn = 0x400000000 | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: found SMP MP-table at [mem 0x000f5bc0-0x000f5bcf] | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: Using GB pages for direct mapping | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: RAMDISK: [mem 0x3149c000-0x34a45fff] | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: Early table checksum verification disabled | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: RSDP 0x00000000000F5980 000014 (v00 BOCHS ) | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: RSDT 0x00000000BFFE300C 000038 (v01 BOCHS BXPC | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: FACP 0x00000000BFFE2DDE 000074 (v01 BOCHS BXPC | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: DSDT 0x00000000BFFDF040 003D9E (v01 BOCHS BXPC | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: FACS 0x00000000BFFDF000 000040 | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: APIC 0x00000000BFFE2E52 000090 (v01 BOCHS BXPC | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: SSDT 0x00000000BFFE2EE2 0000CA (v01 BOCHS VMGENID | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: HPET 0x00000000BFFE2FAC 000038 (v01 BOCHS BXPC | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: WAET 0x00000000BFFE2FE4 000028 (v01 BOCHS BXPC | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: Reserving FACP table memory at [mem 0xbffe2dde-0xbffe2e51] | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: Reserving DSDT table memory at [mem 0xbffdf040-0xbffe2ddd] | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: Reserving FACS table memory at [mem 0xbffdf000-0xbffdf03f] | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: Reserving APIC table memory at [mem 0xbffe2e52-0xbffe2ee1] | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: Reserving SSDT table memory at [mem 0xbffe2ee2-0xbffe2fab] | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: Reserving HPET table memory at [mem 0xbffe2fac-0xbffe2fe3] | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: Reserving WAET table memory at [mem 0xbffe2fe4-0xbffe300b] | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: No NUMA configuration found | ||
--More-- | --More-- | ||
+ | [q] | ||
</ | </ | ||
Ligne 1454: | Ligne 1589: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
- | -- Logs begin at Thu 2021-06-03 09:01:10 EDT, end at Thu 2021-06-03 13:12:01 EDT. -- | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: acpi PNP0A03:00: fail to add MMCONFIG information, |
- | Jun 03 09:01:10 centos8.ittraining.loc kernel: | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: device-mapper: core: CONFIG_IMA_DISABLE_HTABLE is disabled. Duplicate IMA measurements will not be recorded in the IMA log. |
- | Jun 03 09:01:10 centos8.ittraining.loc | + | Sep 28 15:37:00 redhat9.ittraining.loc systemd[1]: sys-module-fuse.device: |
- | Jun 03 09:01:12 centos8.ittraining.loc | + | Sep 28 15:37:00 redhat9.ittraining.loc kernel: sd 0:0:0:0: Power-on or device reset occurred |
- | Jun 03 09:01:12 centos8.ittraining.loc | + | Sep 28 15:37:10 redhat9.ittraining.loc lvm[696]: PV /dev/sda2 online, VG rhel is complete. |
- | Jun 03 09:01:12 centos8.ittraining.loc | + | Sep 28 15:37:12 redhat9.ittraining.loc avahi-daemon[752]: |
- | Jun 03 09:01:18 centos8.ittraining.loc | + | Sep 28 15:37:16 redhat9.ittraining.loc kernel: |
- | Jun 03 09:01:20 centos8.ittraining.loc | + | Sep 28 15:37:20 redhat9.ittraining.loc kernel: |
- | Jun 03 09:01:21 centos8.ittraining.loc | + | Sep 28 15:37:23 redhat9.ittraining.loc |
- | Jun 03 09:01:24 centos8.ittraining.loc | + | Sep 28 15:37:23 redhat9.ittraining.loc / |
- | Jun 03 09:01:24 centos8.ittraining.loc | + | Sep 28 15:37:23 redhat9.ittraining.loc / |
- | Jun 03 09:01:26 centos8.ittraining.loc | + | Sep 28 15:37:23 redhat9.ittraining.loc / |
- | Jun 03 09:01:28 centos8.ittraining.loc | + | Sep 28 15:37:23 redhat9.ittraining.loc / |
- | Jun 03 12:46:31 centos8.ittraining.loc | + | Sep 28 15:37:23 redhat9.ittraining.loc / |
- | lines 1-15/ | + | Sep 28 15:37:23 redhat9.ittraining.loc / |
+ | Sep 28 15:37:23 redhat9.ittraining.loc / | ||
+ | Sep 28 15:37:23 redhat9.ittraining.loc org.gnome.Shell.desktop[1802]: | ||
+ | Sep 28 15:37:23 redhat9.ittraining.loc org.gnome.Shell.desktop[1802]: | ||
+ | Sep 28 15:37:25 redhat9.ittraining.loc / | ||
+ | Sep 28 15:37:25 redhat9.ittraining.loc | ||
+ | Sep 28 15:37:27 redhat9.ittraining.loc | ||
+ | Sep 28 15:37:27 redhat9.ittraining.loc / | ||
+ | Sep 28 15:37:27 redhat9.ittraining.loc | ||
+ | Sep 28 15:37:27 redhat9.ittraining.loc / | ||
+ | Sep 28 15:37:28 redhat9.ittraining.loc wireplumber[1859]: | ||
+ | Sep 28 15:37:28 redhat9.ittraining.loc | ||
+ | Sep 28 15:37:28 redhat9.ittraining.loc | ||
+ | Sep 28 15:37:28 redhat9.ittraining.loc | ||
+ | Sep 28 15:37:28 redhat9.ittraining.loc wireplumber[1859]: | ||
+ | Sep 28 15:37:28 redhat9.ittraining.loc gnome-shell[1802]: | ||
+ | Sep 28 15:37:28 redhat9.ittraining.loc / | ||
+ | Sep 28 15:37:28 redhat9.ittraining.loc / | ||
+ | Sep 28 15:37:28 redhat9.ittraining.loc / | ||
+ | Sep 28 15:37:28 redhat9.ittraining.loc | ||
+ | Sep 28 15:37:28 redhat9.ittraining.loc gsd-sharing[1908]: Failed to StopUnit service: GDBus.Error: | ||
+ | Sep 28 15:37:28 redhat9.ittraining.loc gsd-sharing[1908]: | ||
+ | Sep 28 15:37:28 redhat9.ittraining.loc | ||
+ | Sep 28 15:37:28 redhat9.ittraining.loc gnome-shell[1802]: | ||
+ | Sep 28 15:37:29 redhat9.ittraining.loc dbus-broker[751]: | ||
+ | Sep 28 15:37:29 redhat9.ittraining.loc dbus-broker[751]: A security policy denied :1.25 to send method call / | ||
+ | Sep 28 15:37:29 redhat9.ittraining.loc / | ||
+ | Sep 28 15:37:30 redhat9.ittraining.loc gnome-shell[1802]: | ||
+ | Sep 28 15:37:30 redhat9.ittraining.loc | ||
+ | Sep 28 15:37:30 redhat9.ittraining.loc / | ||
+ | Sep 28 15:37:30 redhat9.ittraining.loc | ||
+ | Sep 28 15:37:30 redhat9.ittraining.loc | ||
+ | Sep 28 15:37:30 redhat9.ittraining.loc gsd-media-keys[1923]: | ||
+ | Sep 28 15:37:30 redhat9.ittraining.loc org.gnome.Shell.desktop[2153]: | ||
+ | Sep 28 15:37:30 redhat9.ittraining.loc org.gnome.Shell.desktop[2153]: | ||
+ | Sep 28 15:37:30 redhat9.ittraining.loc org.gnome.Shell.desktop[2153]: | ||
+ | Sep 28 15:37:30 redhat9.ittraining.loc org.gnome.Shell.desktop[2153]: | ||
+ | Sep 28 15:37:30 redhat9.ittraining.loc / | ||
+ | Sep 28 15:37:30 redhat9.ittraining.loc | ||
+ | Sep 28 15:39:43 redhat9.ittraining.loc / | ||
+ | lines 1-55 | ||
</ | </ | ||
Ligne 1490: | Ligne 1665: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
- | -- Logs begin at Thu 2021-06-03 09:01:10 EDT, end at Thu 2021-06-03 13:14:01 EDT. -- | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: Linux version 5.14.0-427.37.1.el9_4.x86_64 (mockbuild@x86-64-02.build.eng.rdu2.redhat.com) (gcc (GCC) 11.4.1 20231218 (Red Hat 11.4.1-3), GNU ld version 2.35.2-43> |
- | Jun 03 12:00:01 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc |
- | Jun 03 12:00:01 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc |
- | Jun 03 12:00:01 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc |
- | Jun 03 12:01:01 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: x86/fpu: Supporting XSAVE feature 0x002: 'SSE registers' |
- | Jun 03 12:01:01 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc |
- | Jun 03 12:01:01 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc |
- | Jun 03 12:01:01 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc |
- | Jun 03 12:01:01 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc |
- | Jun 03 12:01:01 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: BIOS-provided physical RAM map: |
- | Jun 03 12:02:01 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc |
- | Jun 03 12:02:01 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc |
- | Jun 03 12:02:01 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: BIOS-e820: [mem 0x00000000000f0000-0x00000000000fffff] reserved |
- | Jun 03 12:03:01 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc |
- | Jun 03 12:03:01 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: BIOS-e820: [mem 0x00000000bffda000-0x00000000bfffffff] reserved |
- | Jun 03 12:03:01 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc |
- | Jun 03 12:04:01 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: BIOS-e820: [mem 0x00000000fffc0000-0x00000000ffffffff] reserved |
- | Jun 03 12:04:01 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc |
- | Jun 03 12:04:01 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: NX (Execute Disable) protection: active |
- | Jun 03 12:05:01 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc |
- | Jun 03 12:05:01 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc |
- | Jun 03 12:05:01 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: Hypervisor detected: KVM |
- | Jun 03 12:06:02 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc |
- | Jun 03 12:06:02 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc |
- | Jun 03 12:06:02 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc |
- | Jun 03 12:07:01 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc |
- | Jun 03 12:07:01 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: e820: update [mem 0x00000000-0x00000fff] usable ==> reserved |
- | Jun 03 12:07:01 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc |
- | Jun 03 12:08:01 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: last_pfn = 0x240000 max_arch_pfn = 0x400000000 |
- | Jun 03 12:08:01 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc |
- | Jun 03 12:08:01 centos8.ittraining.loc | + | Sep 28 15:36:59 redhat9.ittraining.loc |
- | lines 1-31 | + | Sep 28 15:36:59 redhat9.ittraining.loc kernel: last_pfn = 0xbffda max_arch_pfn = 0x400000000 |
+ | Sep 28 15:36:59 redhat9.ittraining.loc | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: Using GB pages for direct mapping | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: Early table checksum verification disabled | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: RSDP 0x00000000000F5980 000014 | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: RSDT 0x00000000BFFE300C 000038 (v01 BOCHS BXPC | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: DSDT 0x00000000BFFDF040 003D9E (v01 BOCHS BXPC | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: APIC 0x00000000BFFE2E52 000090 (v01 BOCHS BXPC | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: HPET 0x00000000BFFE2FAC 000038 | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: WAET 0x00000000BFFE2FE4 000028 (v01 BOCHS BXPC | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: Reserving DSDT table memory at [mem 0xbffdf040-0xbffe2ddd] | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: Reserving FACS table memory at [mem 0xbffdf000-0xbffdf03f] | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: Reserving APIC table memory at [mem 0xbffe2e52-0xbffe2ee1] | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: ACPI: Reserving HPET table memory at [mem 0xbffe2fac-0xbffe2fe3] | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: No NUMA configuration found | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc | ||
+ | Sep 28 15:36:59 redhat9.ittraining.loc kernel: NODE_DATA(0) allocated [mem 0x23ffd5000-0x23fffffff] | ||
+ | lines 1-55 | ||
</ | </ | ||
Ligne 1534: | Ligne 1733: | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
- | -- Logs begin at Thu 2021-06-03 09:01:10 EDT. -- | + | Sep 28 15:41:02 redhat9.ittraining.loc systemd[2200]: Starting Mark boot as successful... |
- | Jun 03 13:13:08 centos8.ittraining.loc systemd[1]: Started dnf makecache. | + | Sep 28 15:41:03 redhat9.ittraining.loc systemd[2200]: Finished Mark boot as successful. |
- | Jun 03 13:14:01 centos8.ittraining.loc systemd[1]: Started Session 256 of user trainee. | + | Sep 28 15:42:29 redhat9.ittraining.loc |
- | Jun 03 13:14:01 centos8.ittraining.loc | + | Sep 28 15:42:29 redhat9.ittraining.loc systemd[1]: |
- | Jun 03 13:14:01 centos8.ittraining.loc systemd[1]: | + | Sep 28 15:43:02 redhat9.ittraining.loc systemd[1340]: Created slice User Background Tasks Slice. |
- | Jun 03 13:15:01 centos8.ittraining.loc systemd[1]: Started Session 257 of user trainee. | + | Sep 28 15:43:02 redhat9.ittraining.loc |
- | Jun 03 13:15:01 centos8.ittraining.loc | + | Sep 28 15:43:02 redhat9.ittraining.loc systemd[1340]: Finished Cleanup of User's Temporary Files and Directories. |
- | Jun 03 13:15:01 centos8.ittraining.loc systemd[1]: session-257.scope: | + | Sep 28 15:44:02 redhat9.ittraining.loc systemd[2200]: Created slice User Background Tasks Slice. |
- | Jun 03 13:16:02 centos8.ittraining.loc systemd[1]: Started Session 258 of user trainee. | + | Sep 28 15:44:02 redhat9.ittraining.loc |
- | Jun 03 13:16:02 centos8.ittraining.loc | + | Sep 28 15:44:02 redhat9.ittraining.loc systemd[2200]: Finished Cleanup of User's Temporary Files and Directories. |
- | Jun 03 13:16:02 centos8.ittraining.loc systemd[1]: session-258.scope: | + | |
^C | ^C | ||
</ | </ | ||
- | Ouvrez un deuxième terminal et saisissez | + | ====5.7 - Consultation des Journaux avec des Mots Clefs=== |
+ | |||
+ | Pour consulter les mots clefs compris par Journald, tapez la commande | ||
< | < | ||
- | [trainee@centos8 | + | [root@redhat9 |
+ | _AUDIT_LOGINUID= | ||
+ | _AUDIT_SESSION= | ||
+ | AVAILABLE= | ||
+ | AVAILABLE_PRETTY= | ||
+ | _BOOT_ID= | ||
+ | _CAP_EFFECTIVE= | ||
+ | _CMDLINE= | ||
+ | CODE_FILE= | ||
+ | CODE_FUNC= | ||
+ | CODE_LINE= | ||
+ | _COMM= | ||
+ | CURRENT_USE= | ||
+ | CURRENT_USE_PRETTY= | ||
+ | DBUS_BROKER_LOG_DROPPED= | ||
+ | DBUS_BROKER_MESSAGE_DESTINATION= | ||
+ | DBUS_BROKER_MESSAGE_INTERFACE= | ||
+ | DBUS_BROKER_MESSAGE_MEMBER= | ||
+ | DBUS_BROKER_MESSAGE_PATH= | ||
+ | DBUS_BROKER_MESSAGE_SERIAL= | ||
+ | DBUS_BROKER_MESSAGE_SIGNATURE= | ||
</ | </ | ||
- | Retournez consulter | + | Pour voir la liste des processus dont les traces sont inclus dans les journaux du mots clefs, tapez la commande journalctl suivi par le nom d'un mot clef puis appuyer deux fois sur la touche < |
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
- | -- Logs begin at Thu 2021-06-03 09:01:10 EDT. -- | + | 0 |
- | Jun 03 13:13:08 centos8.ittraining.loc systemd[1]: Started dnf makecache. | + | |
- | Jun 03 13:14:01 centos8.ittraining.loc systemd[1]: Started Session 256 of user trainee. | + | [root@redhat9 ~]# journalctl _COMM= |
- | Jun 03 13:14:01 centos8.ittraining.loc CROND[5391]: | + | accounts-daemon |
- | Jun 03 13:14:01 centos8.ittraining.loc systemd[1]: | + | at-spi2-registr |
- | Jun 03 13:15:01 centos8.ittraining.loc | + | auditctl |
- | Jun 03 13:15:01 centos8.ittraining.loc CROND[5407]: | + | auditd |
- | Jun 03 13:15:01 centos8.ittraining.loc | + | augenrules |
- | Jun 03 13:16:02 centos8.ittraining.loc systemd[1]: Started Session 258 of user trainee. | + | |
- | Jun 03 13:16:02 centos8.ittraining.loc CROND[5420]: | + | |
- | Jun 03 13:16:02 centos8.ittraining.loc systemd[1]: session-258.scope: Succeeded. | + | |
- | Jun 03 13:17:01 centos8.ittraining.loc | + | |
- | Jun 03 13:17:01 centos8.ittraining.loc CROND[5436]: | + | |
- | Jun 03 13:17:01 centos8.ittraining.loc | + | |
- | Jun 03 13:17:19 centos8.ittraining.loc sshd[5439]: Accepted password for trainee from 10.0.2.2 port 39906 ssh2 | + | |
- | Jun 03 13:17:19 centos8.ittraining.loc systemd-logind[880]: | + | |
- | Jun 03 13:17:19 centos8.ittraining.loc systemd[1]: Started Session 260 of user trainee. | + | |
- | Jun 03 13:17:19 centos8.ittraining.loc sshd[5439]: pam_unix(sshd: | + | |
- | Jun 03 13:17:34 centos8.ittraining.loc trainee[5470]: | + | |
- | Jun 03 13:17:34 centos8.ittraining.loc rsyslogd[1113]: | + | |
- | Jun 03 13:18:01 centos8.ittraining.loc | + | |
- | Jun 03 13:18:01 centos8.ittraining.loc CROND[5481]: | + | |
- | Jun 03 13:18:01 centos8.ittraining.loc systemd[1]: session-261.scope: Succeeded. | + | |
- | ^C | + | |
</ | </ | ||
- | <WRAP center round important | + | =====LAB #6 - Le Serveur d' |
- | **Important** | + | |
+ | ====6.1 - Introduction==== | ||
+ | |||
+ | Dans le cas d'un serveur de réseau, il est souvent important de maintenir l' | ||
+ | |||
+ | Le protocole utilisé s' | ||
+ | |||
+ | <WRAP center round important> | ||
+ | **Important** | ||
</ | </ | ||
- | ====5.7 - Consultation des Journaux avec des Mots Clefs=== | + | Linux utilise le fuseau d' |
- | Pour consulter les mots clefs compris par Journald, tapez la commande **journalctl** puis appuyer **deux** fois sur la touche | + | <code> |
+ | [root@redhat9 ~]# ls -l / | ||
+ | lrwxrwxrwx. 1 root root 34 Oct 19 2023 / | ||
+ | </code> | ||
+ | |||
+ | Ce fichier peut être un fichier ordinaire ou bien un lien symbolique pointant vers un de sfichiers dans le répertoire **/ | ||
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
- | _AUDIT_LOGINUID= | + | Africa |
- | _AUDIT_SESSION= | + | America |
- | AVAILABLE= | + | Antarctica |
- | AVAILABLE_PRETTY= | + | Arctic |
- | _BOOT_ID= | + | |
- | _CAP_EFFECTIVE= | + | |
- | _CMDLINE= | + | |
- | CODE_FILE= | + | |
- | CODE_FUNC= | + | |
- | CODE_LINE= | + | |
- | _COMM= | + | |
- | CURRENT_USE= | + | |
- | CURRENT_USE_PRETTY= | + | |
- | DISK_AVAILABLE= | + | |
- | DISK_AVAILABLE_PRETTY= | + | |
- | DISK_KEEP_FREE= | + | |
- | DISK_KEEP_FREE_PRETTY= | + | |
- | _EXE= | + | |
- | _GID= | + | |
</ | </ | ||
- | Pour voir la liste des processus dont les traces sont inclus dans les journaux du mots clefs, tapez la commande journalctl suivi par le nom d'un mot clef puis appuyer deux fois sur la touche < | + | Pour connaître |
< | < | ||
- | [root@centos8 | + | [root@redhat9 |
- | 0 | + | Sat Sep 28 03:55:32 PM CEST 2024 |
- | [root@centos8 ~]# journalctl _COMM= | + | |
- | anacron | + | |
- | auditd | + | |
- | augenrules | + | |
- | chronyd | + | |
- | crond firewalld | + | |
</ | </ | ||
+ | |||
+ | <WRAP center round important> | ||
+ | **Important** - Vous pouvez consulter la liste des codes des zones à l' | ||
+ | </ | ||
+ | |||
+ | Le fuseau d' | ||
+ | |||
+ | < | ||
+ | [root@redhat9 ~]# timedatectl | ||
+ | Local time: Sat 2024-09-28 15:57:01 CEST | ||
+ | | ||
+ | RTC time: Sat 2024-09-28 13:57:01 | ||
+ | Time zone: Europe/ | ||
+ | System clock synchronized: | ||
+ | NTP service: inactive | ||
+ | RTC in local TZ: no | ||
+ | </ | ||
+ | |||
+ | La commande **timedatectl** peut être utilisée pour modifier le fuseau d' | ||
+ | |||
+ | < | ||
+ | [root@redhat9 ~]# timedatectl set-timezone America/ | ||
+ | |||
+ | [root@redhat9 ~]# timedatectl | ||
+ | Local time: Sat 2024-09-28 07:05:43 MST | ||
+ | | ||
+ | RTC time: Sat 2024-09-28 14:05:43 | ||
+ | Time zone: America/ | ||
+ | System clock synchronized: | ||
+ | NTP service: inactive | ||
+ | RTC in local TZ: no | ||
+ | |||
+ | [root@redhat9 ~]# timedatectl set-timezone Europe/ | ||
+ | [root@redhat9 ~]# timedatectl | ||
+ | Local time: Sat 2024-09-28 16:06:35 CEST | ||
+ | | ||
+ | RTC time: Sat 2024-09-28 14:06:35 | ||
+ | Time zone: Europe/ | ||
+ | System clock synchronized: | ||
+ | NTP service: inactive | ||
+ | RTC in local TZ: no | ||
+ | </ | ||
+ | |||
+ | L' | ||
+ | |||
+ | Vous pouvez aussi modifier le fuseau d' | ||
+ | |||
+ | < | ||
+ | [root@redhat9 ~]# tzselect | ||
+ | Please identify a location so that time zone rules can be set correctly. | ||
+ | Please select a continent, ocean, " | ||
+ | 1) Africa | ||
+ | 2) Americas | ||
+ | 3) Antarctica | ||
+ | 4) Asia 8) Indian Ocean | ||
+ | #? ^C | ||
+ | </ | ||
+ | |||
+ | Il est est possible de modifier le fuseau d' | ||
+ | |||
+ | < | ||
+ | [root@redhat9 ~]# date | ||
+ | Sat Sep 28 03:59:46 PM CEST 2024 | ||
+ | [root@redhat9 ~]# export TZ=:/ | ||
+ | [root@redhat9 ~]# date | ||
+ | Sat Sep 28 02:59:54 PM BST 2024 | ||
+ | [root@redhat9 ~]# export TZ=:/ | ||
+ | [root@redhat9 ~]# date | ||
+ | Sat Sep 28 04:00:06 PM CEST 2024 | ||
+ | </ | ||
+ | |||
+ | ====6.2 - Le Service chronyd==== | ||
+ | |||
+ | Sous RHEL 9, le serveur d' | ||
+ | |||
+ | < | ||
+ | [root@redhat9 ~]# systemctl status chronyd | ||
+ | ○ chronyd.service - NTP client/ | ||
+ | | ||
+ | | ||
+ | Docs: man: | ||
+ | | ||
+ | </ | ||
+ | |||
+ | Pour activer ce serveur, utilisez l' | ||
+ | |||
+ | < | ||
+ | [root@redhat9 ~]# timedatectl set-ntp yes | ||
+ | |||
+ | [root@redhat9 ~]# timedatectl | ||
+ | Local time: Sat 2024-09-28 16:53:46 CEST | ||
+ | | ||
+ | RTC time: Sat 2024-09-28 14:53:46 | ||
+ | Time zone: Europe/ | ||
+ | System clock synchronized: | ||
+ | NTP service: active | ||
+ | RTC in local TZ: no | ||
+ | </ | ||
+ | |||
+ | Vérifiez ensuite que le service **chronyd** est démarré : | ||
+ | |||
+ | < | ||
+ | [root@redhat9 ~]# systemctl status chronyd | ||
+ | ● chronyd.service - NTP client/ | ||
+ | | ||
+ | | ||
+ | Docs: man: | ||
+ | | ||
+ | Process: 2673 ExecStart=/ | ||
+ | Main PID: 2675 (chronyd) | ||
+ | Tasks: 1 (limit: 48800) | ||
+ | | ||
+ | CPU: 45ms | ||
+ | | ||
+ | | ||
+ | |||
+ | Sep 28 16:53:41 redhat9.ittraining.loc systemd[1]: Starting NTP client/ | ||
+ | Sep 28 16:53:41 redhat9.ittraining.loc chronyd[2675]: | ||
+ | Sep 28 16:53:41 redhat9.ittraining.loc chronyd[2675]: | ||
+ | Sep 28 16:53:41 redhat9.ittraining.loc chronyd[2675]: | ||
+ | Sep 28 16:53:41 redhat9.ittraining.loc chronyd[2675]: | ||
+ | Sep 28 16:53:41 redhat9.ittraining.loc systemd[1]: Started NTP client/ | ||
+ | Sep 28 16:53:46 redhat9.ittraining.loc chronyd[2675]: | ||
+ | Sep 28 16:53:46 redhat9.ittraining.loc chronyd[2675]: | ||
+ | </ | ||
+ | |||
+ | La commande **chronyc** permet de voir le statut de la synchronisation : | ||
+ | |||
+ | < | ||
+ | [root@redhat9 ~]# chronyc sources -v | ||
+ | |||
+ | .-- Source mode ' | ||
+ | / .- Source state ' | ||
+ | | / ' | ||
+ | || .- xxxx [ yyyy ] +/- zzzz | ||
+ | || Reachability register (octal) -. | ||
+ | || Log2(Polling interval) --. | | yyyy = measured offset, | ||
+ | || \ | ||
+ | || | ||
+ | MS Name/IP address | ||
+ | =============================================================================== | ||
+ | ^* 64.ip-54-39-23.net | ||
+ | ^- rikku.vrillusions.com | ||
+ | ^- rwhois.dargalsolutions.c> | ||
+ | ^- ntp.pawdesigns.ca | ||
+ | </ | ||
+ | |||
+ | ====6.3 - Le Fichier / | ||
+ | |||
+ | Le service **chronyd** maintient l' | ||
+ | calcule la dérive de l' | ||
+ | |||
+ | Les serveurs NTP configurés sont : **pool 2.rhel.pool.ntp.org iburst**. L' | ||
+ | |||
+ | Le protocole NTP utilise le port 123. Les serveurs de temps de racine s' | ||
+ | |||
+ | < | ||
+ | [root@redhat9 ~]# cat / | ||
+ | # Use public servers from the pool.ntp.org project. | ||
+ | # Please consider joining the pool (https:// | ||
+ | pool 2.rhel.pool.ntp.org iburst | ||
+ | |||
+ | # Use NTP servers from DHCP. | ||
+ | sourcedir / | ||
+ | |||
+ | # Record the rate at which the system clock gains/ | ||
+ | driftfile / | ||
+ | |||
+ | # Allow the system clock to be stepped in the first three updates | ||
+ | # if its offset is larger than 1 second. | ||
+ | makestep 1.0 3 | ||
+ | |||
+ | # Enable kernel synchronization of the real-time clock (RTC). | ||
+ | rtcsync | ||
+ | |||
+ | # Enable hardware timestamping on all interfaces that support it. | ||
+ | # | ||
+ | |||
+ | # Increase the minimum number of selectable sources required to adjust | ||
+ | # the system clock. | ||
+ | #minsources 2 | ||
+ | |||
+ | # Allow NTP client access from local network. | ||
+ | #allow 192.168.0.0/ | ||
+ | |||
+ | # Serve time even if not synchronized to a time source. | ||
+ | #local stratum 10 | ||
+ | |||
+ | # Require authentication (nts or key option) for all NTP sources. | ||
+ | # | ||
+ | |||
+ | # Specify file containing keys for NTP authentication. | ||
+ | keyfile / | ||
+ | |||
+ | # Save NTS keys and cookies. | ||
+ | ntsdumpdir / | ||
+ | |||
+ | # Insert/ | ||
+ | # | ||
+ | |||
+ | # Get TAI-UTC offset and leap seconds from the system tz database. | ||
+ | leapsectz right/UTC | ||
+ | |||
+ | # Specify directory for log files. | ||
+ | logdir / | ||
+ | |||
+ | # Select which information is logged. | ||
+ | #log measurements statistics tracking | ||
+ | </ | ||
+ | |||
+ | |||
----- | ----- | ||
Copyright © 2024 Hugh Norris. | Copyright © 2024 Hugh Norris. |