Understanding Linux audit.logs for SSH - USER_AUTH

The name of the pictureThe name of the pictureThe name of the pictureClash Royale CLAN TAG#URR8PPP











up vote
0
down vote

favorite












Let's say I have this entry in my Linux audit.log:



type=USER_AUTH msg=audit(1357702397.903:2747564): user pid=15121 uid=0
auid=4294967295 ses=4294967295 msg='op=PAM:authentication acct="test"
exe="/usr/sbin/sshd" hostname=192.20.11.53 addr=192.20.11.53 terminal=ssh
es="success"


Does this mean that someone has authenticated via SSH using username and password, or with their private key? Is there a way to tell?










share|improve this question













migrated from security.stackexchange.com 8 mins ago


This question came from our site for information security professionals.














  • not from that one line - suse.com/documentation/sles11/book_security/data/…
    – schroeder
    10 mins ago










  • Take a look at the options: access.redhat.com/documentation/en-us/red_hat_enterprise_linux/…
    – schroeder
    8 mins ago














up vote
0
down vote

favorite












Let's say I have this entry in my Linux audit.log:



type=USER_AUTH msg=audit(1357702397.903:2747564): user pid=15121 uid=0
auid=4294967295 ses=4294967295 msg='op=PAM:authentication acct="test"
exe="/usr/sbin/sshd" hostname=192.20.11.53 addr=192.20.11.53 terminal=ssh
es="success"


Does this mean that someone has authenticated via SSH using username and password, or with their private key? Is there a way to tell?










share|improve this question













migrated from security.stackexchange.com 8 mins ago


This question came from our site for information security professionals.














  • not from that one line - suse.com/documentation/sles11/book_security/data/…
    – schroeder
    10 mins ago










  • Take a look at the options: access.redhat.com/documentation/en-us/red_hat_enterprise_linux/…
    – schroeder
    8 mins ago












up vote
0
down vote

favorite









up vote
0
down vote

favorite











Let's say I have this entry in my Linux audit.log:



type=USER_AUTH msg=audit(1357702397.903:2747564): user pid=15121 uid=0
auid=4294967295 ses=4294967295 msg='op=PAM:authentication acct="test"
exe="/usr/sbin/sshd" hostname=192.20.11.53 addr=192.20.11.53 terminal=ssh
es="success"


Does this mean that someone has authenticated via SSH using username and password, or with their private key? Is there a way to tell?










share|improve this question













Let's say I have this entry in my Linux audit.log:



type=USER_AUTH msg=audit(1357702397.903:2747564): user pid=15121 uid=0
auid=4294967295 ses=4294967295 msg='op=PAM:authentication acct="test"
exe="/usr/sbin/sshd" hostname=192.20.11.53 addr=192.20.11.53 terminal=ssh
es="success"


Does this mean that someone has authenticated via SSH using username and password, or with their private key? Is there a way to tell?







linux ssh logs






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked 21 mins ago







Bob Bobson The Third Esq.











migrated from security.stackexchange.com 8 mins ago


This question came from our site for information security professionals.






migrated from security.stackexchange.com 8 mins ago


This question came from our site for information security professionals.













  • not from that one line - suse.com/documentation/sles11/book_security/data/…
    – schroeder
    10 mins ago










  • Take a look at the options: access.redhat.com/documentation/en-us/red_hat_enterprise_linux/…
    – schroeder
    8 mins ago
















  • not from that one line - suse.com/documentation/sles11/book_security/data/…
    – schroeder
    10 mins ago










  • Take a look at the options: access.redhat.com/documentation/en-us/red_hat_enterprise_linux/…
    – schroeder
    8 mins ago















not from that one line - suse.com/documentation/sles11/book_security/data/…
– schroeder
10 mins ago




not from that one line - suse.com/documentation/sles11/book_security/data/…
– schroeder
10 mins ago












Take a look at the options: access.redhat.com/documentation/en-us/red_hat_enterprise_linux/…
– schroeder
8 mins ago




Take a look at the options: access.redhat.com/documentation/en-us/red_hat_enterprise_linux/…
– schroeder
8 mins ago















active

oldest

votes











Your Answer







StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "106"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);

else
createEditor();

);

function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
convertImagesToLinks: false,
noModals: false,
showLowRepImageUploadWarning: true,
reputationToPostImages: null,
bindNavPrevention: true,
postfix: "",
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);



);













 

draft saved


draft discarded


















StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f475912%2funderstanding-linux-audit-logs-for-ssh-user-auth%23new-answer', 'question_page');

);

Post as a guest


































active

oldest

votes













active

oldest

votes









active

oldest

votes






active

oldest

votes















 

draft saved


draft discarded















































 


draft saved


draft discarded














StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f475912%2funderstanding-linux-audit-logs-for-ssh-user-auth%23new-answer', 'question_page');

);

Post as a guest













































































Popular posts from this blog

How to check contact read email or not when send email to Individual?

Bahrain

Postfix configuration issue with fips on centos 7; mailgun relay