Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: LEM Agent for Linux sends logs to manager from wrong IP address

$
0
0

Here's a couple of lines from /var/log/audit/audit.log:

 

type=USER_START msg=audit(1459948449.045:128516): user pid=9482 uid=10011713 auid=10011713 ses=7110 msg='op=PAM:session_open acct="root" exe="/bin/su" hostname=? addr=? terminal=pts/1 res=success'

type=CRED_ACQ msg=audit(1459948449.045:128517): user pid=9482 uid=10011713 auid=10011713 ses=7110 msg='op=PAM:setcred acct="root" exe="/bin/su" hostname=? addr=? terminal=pts/1 res=success'

 

The other logs (/var/log/secure, /var/log/messages) are as you describe.

 

I guess I'll have to limit log collection to those two logs.

 

Thanks


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>