RE: Logging all commands executed by user root to LogLogic device
"Bahto, Richard" <[email protected]> Wed, 27 Jun 2012 15:54:40 -0400
| Newsgroups | gmane.os.solaris.managers |
|---|---|
| Message-ID | <E7F19C9CF8C9D8498A2184FB3EA3FF462C90270B@msg21usa.usa.glb.tru.com> |
Please forgive my incompleteness I am running this on a SunFire T2000 running Solaris 10 SunOS 5.10 Generic_147440-19 sun4v sparc SUNW,Sun-Fire-T200 From: Bahto, Richard Sent: Wednesday, June 27, 2012 3:52 PM To: '[email protected]' Subject: Logging all commands executed by user root to LogLogic device I am now being asked to send every command that root executes to a LogLogic device. One of my collages have successfully done this on his Linux servers using the following I have add following entry on /etc/bashrc & /etc/syslog.conf files and restart the syslog deamon. cat /etc/bashrc export PROMPT_COMMAND='history -a >(logger -p local1.debug -t "$USER[$PWD] $SSH_CONNECTION")' cat /etc/syslog.conf # Loglogic Redirection authpriv.*;local1.* @xx.xx.xx.xx I have tried this as is ( adding the export command to /etc/profile since we don't have an /etc/bashrc ) and using auth.debug and local1.debug as the facility.level . I have been unsuccessful in my attempts and would appreciate any suggestions you would offer. Thanks in advance Richard Bahto ... ================================================================= This email message is for the sole use of the intended recipient(s) and may contain confidential and privileged information. Any unauthorized review, use, disclosure or distribution is prohibited. If you are not the intended recipient, please contact the sender by reply email and destroy all copies of the original message. To reply to our email administrator directly, send an email to [email protected]. Toys "R" Us, Inc.