Understanding Linux audit.logs for SSH - USER_AUTH
Clash Royale CLAN TAG#URR8PPP
up vote
0
down vote
favorite
Let's say I have this entry in my Linux audit.log:
type=USER_AUTH msg=audit(1357702397.903:2747564): user pid=15121 uid=0
auid=4294967295 ses=4294967295 msg='op=PAM:authentication acct="test"
exe="/usr/sbin/sshd" hostname=192.20.11.53 addr=192.20.11.53 terminal=ssh
es="success"
Does this mean that someone has authenticated via SSH using username and password, or with their private key? Is there a way to tell?
linux ssh logs
migrated from security.stackexchange.com 8 mins ago
This question came from our site for information security professionals.
add a comment |Â
up vote
0
down vote
favorite
Let's say I have this entry in my Linux audit.log:
type=USER_AUTH msg=audit(1357702397.903:2747564): user pid=15121 uid=0
auid=4294967295 ses=4294967295 msg='op=PAM:authentication acct="test"
exe="/usr/sbin/sshd" hostname=192.20.11.53 addr=192.20.11.53 terminal=ssh
es="success"
Does this mean that someone has authenticated via SSH using username and password, or with their private key? Is there a way to tell?
linux ssh logs
migrated from security.stackexchange.com 8 mins ago
This question came from our site for information security professionals.
not from that one line - suse.com/documentation/sles11/book_security/data/â¦
â schroeder
10 mins ago
Take a look at the options: access.redhat.com/documentation/en-us/red_hat_enterprise_linux/â¦
â schroeder
8 mins ago
add a comment |Â
up vote
0
down vote
favorite
up vote
0
down vote
favorite
Let's say I have this entry in my Linux audit.log:
type=USER_AUTH msg=audit(1357702397.903:2747564): user pid=15121 uid=0
auid=4294967295 ses=4294967295 msg='op=PAM:authentication acct="test"
exe="/usr/sbin/sshd" hostname=192.20.11.53 addr=192.20.11.53 terminal=ssh
es="success"
Does this mean that someone has authenticated via SSH using username and password, or with their private key? Is there a way to tell?
linux ssh logs
Let's say I have this entry in my Linux audit.log:
type=USER_AUTH msg=audit(1357702397.903:2747564): user pid=15121 uid=0
auid=4294967295 ses=4294967295 msg='op=PAM:authentication acct="test"
exe="/usr/sbin/sshd" hostname=192.20.11.53 addr=192.20.11.53 terminal=ssh
es="success"
Does this mean that someone has authenticated via SSH using username and password, or with their private key? Is there a way to tell?
linux ssh logs
linux ssh logs
asked 21 mins ago
Bob Bobson The Third Esq.
migrated from security.stackexchange.com 8 mins ago
This question came from our site for information security professionals.
migrated from security.stackexchange.com 8 mins ago
This question came from our site for information security professionals.
not from that one line - suse.com/documentation/sles11/book_security/data/â¦
â schroeder
10 mins ago
Take a look at the options: access.redhat.com/documentation/en-us/red_hat_enterprise_linux/â¦
â schroeder
8 mins ago
add a comment |Â
not from that one line - suse.com/documentation/sles11/book_security/data/â¦
â schroeder
10 mins ago
Take a look at the options: access.redhat.com/documentation/en-us/red_hat_enterprise_linux/â¦
â schroeder
8 mins ago
not from that one line - suse.com/documentation/sles11/book_security/data/â¦
â schroeder
10 mins ago
not from that one line - suse.com/documentation/sles11/book_security/data/â¦
â schroeder
10 mins ago
Take a look at the options: access.redhat.com/documentation/en-us/red_hat_enterprise_linux/â¦
â schroeder
8 mins ago
Take a look at the options: access.redhat.com/documentation/en-us/red_hat_enterprise_linux/â¦
â schroeder
8 mins ago
add a comment |Â
active
oldest
votes
active
oldest
votes
active
oldest
votes
active
oldest
votes
active
oldest
votes
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f475912%2funderstanding-linux-audit-logs-for-ssh-user-auth%23new-answer', 'question_page');
);
Post as a guest
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
not from that one line - suse.com/documentation/sles11/book_security/data/â¦
â schroeder
10 mins ago
Take a look at the options: access.redhat.com/documentation/en-us/red_hat_enterprise_linux/â¦
â schroeder
8 mins ago