Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations wOOdy-Soft on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Capture Failed Login Attempts 1

Status
Not open for further replies.
Nov 18, 2008
5
I need to audit failed login attempts on a new Solaris 10 server. Most logins are via SSH (putty). I have uncommented the line below in /etc/default/login and changed its value to =0.

SYSLOG_FAILED_LOGINS=0

Additionally I've created a loginlog file with the following permissions:

-rw------- 1 root sys 0 Dec 12 08:52 loginlog

Anything else I need to do? Restart syslog service?
I can't get anything to be recorded?

Thanks for the help
 
Have you added any references to this new log file to /etc/syslog.conf? If not, syslog doesn't know that it exists... and doesn't know what kind of stuff you want to log in it.

You may wish to just use the preconfigured (but commented out) entry for /var/log/authlog. After any changes to /etc/syslog.conf you will need to pkill -HUP syslogd to make it re-read the configuration file.

Annihilannic.
 
Worked like a charm. It's logging to the /var/log/authlog file.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top