LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Other *NIX Forums > Solaris / OpenSolaris
User Name
Password
Solaris / OpenSolaris This forum is for the discussion of Solaris, OpenSolaris, OpenIndiana, and illumos.
General Sun, SunOS and Sparc related questions also go here. Any Solaris fork or distribution is welcome.

Notices


Reply
  Search this Thread
Old 01-13-2008, 10:11 PM   #1
keysorsoze
Member
 
Registered: Apr 2004
Location: Queens, NY
Distribution: Red Hat, Solaris
Posts: 295

Rep: Reputation: 30
Logwatch on Solaris?


Hi, has anyone experimented with logwatch on Solaris? If so what are your opinions. We currently have a script that basically dumps our /var/adm/message file for all our systems. Sometimes we get blank emails because nothing occurred sometimes we are bombarded with bootup messages. I am looking for a way to monitor the logs for suspicious activity such as ssh failed logins and basically system messages such as the disk suite failing or other hardware components failing. Logwatch on Linux is great but does anyone here use it for Solaris?
 
Old 01-15-2008, 01:46 AM   #2
UltraSoul
Member
 
Registered: Dec 2004
Location: Japan
Distribution: REDHAT9.0, Mandrake10.1
Posts: 404

Rep: Reputation: 31
Hi, keysorsoze

I have no experiences on logwatch. My opinion is as follows.

- For logging ssh activity to /var/adm/messages. Add one line to /etc/syslog.conf and restart syslog daemon, then
test the ssh loggin setting by ssh -l <username> <server_ip>

auth.info /var/adm/messages ==> you also can use one file to log ssh activity only.
Solaris9: /etc/init.d/syslog stop ==> Start
Solaris10: svcadm restart system/system-log

- About disk info, I always checked the following commands. You can man these commands. If disk has some errors, /var/adm/messages
should log disk errors with timestamp. And if you are using disk array, some monitor s/w shold be available for your array.

# format
# iostat -En

- /usr/platform/`uname -i`/sbin/prtdiag -v can show you system healthy.
 
Old 01-15-2008, 07:04 AM   #3
keysorsoze
Member
 
Registered: Apr 2004
Location: Queens, NY
Distribution: Red Hat, Solaris
Posts: 295

Original Poster
Rep: Reputation: 30
UltraSoul

Your idea is good but I would like a system that will email me daily logs of all my systems and highlight suspicious items such as failed attempts etc. Logwatch on Linux is great I just was wondering if anyone used it for Solaris or if it even is possible. I don't want to manually SSH into each system to look at the /var/adm/messages file for all systems.


Thanks
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Logwatch winchester169 Linux - Security 1 10-21-2004 09:18 AM
***logwatch*** LinuxRam Linux - General 1 08-25-2004 04:09 AM
logwatch I keep getting this help please lildrummerboy Linux - Newbie 1 08-01-2004 01:57 PM
logwatch lildrummerboy Linux - Newbie 1 07-29-2004 07:38 PM
Logwatch miguel Linux - General 0 11-08-2002 05:15 AM

LinuxQuestions.org > Forums > Other *NIX Forums > Solaris / OpenSolaris

All times are GMT -5. The time now is 02:51 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration