Understanding Linux audit.logs for SSH - USER_AUTH

Multi tool use
Multi tool use

The name of the pictureThe name of the pictureThe name of the pictureClash Royale CLAN TAG#URR8PPP











up vote
0
down vote

favorite












Let's say I have this entry in my Linux audit.log:



type=USER_AUTH msg=audit(1357702397.903:2747564): user pid=15121 uid=0
auid=4294967295 ses=4294967295 msg='op=PAM:authentication acct="test"
exe="/usr/sbin/sshd" hostname=192.20.11.53 addr=192.20.11.53 terminal=ssh
es="success"


Does this mean that someone has authenticated via SSH using username and password, or with their private key? Is there a way to tell?










share|improve this question













migrated from security.stackexchange.com 8 mins ago


This question came from our site for information security professionals.














  • not from that one line - suse.com/documentation/sles11/book_security/data/…
    – schroeder
    10 mins ago










  • Take a look at the options: access.redhat.com/documentation/en-us/red_hat_enterprise_linux/…
    – schroeder
    8 mins ago














up vote
0
down vote

favorite












Let's say I have this entry in my Linux audit.log:



type=USER_AUTH msg=audit(1357702397.903:2747564): user pid=15121 uid=0
auid=4294967295 ses=4294967295 msg='op=PAM:authentication acct="test"
exe="/usr/sbin/sshd" hostname=192.20.11.53 addr=192.20.11.53 terminal=ssh
es="success"


Does this mean that someone has authenticated via SSH using username and password, or with their private key? Is there a way to tell?










share|improve this question













migrated from security.stackexchange.com 8 mins ago


This question came from our site for information security professionals.














  • not from that one line - suse.com/documentation/sles11/book_security/data/…
    – schroeder
    10 mins ago










  • Take a look at the options: access.redhat.com/documentation/en-us/red_hat_enterprise_linux/…
    – schroeder
    8 mins ago












up vote
0
down vote

favorite









up vote
0
down vote

favorite











Let's say I have this entry in my Linux audit.log:



type=USER_AUTH msg=audit(1357702397.903:2747564): user pid=15121 uid=0
auid=4294967295 ses=4294967295 msg='op=PAM:authentication acct="test"
exe="/usr/sbin/sshd" hostname=192.20.11.53 addr=192.20.11.53 terminal=ssh
es="success"


Does this mean that someone has authenticated via SSH using username and password, or with their private key? Is there a way to tell?










share|improve this question













Let's say I have this entry in my Linux audit.log:



type=USER_AUTH msg=audit(1357702397.903:2747564): user pid=15121 uid=0
auid=4294967295 ses=4294967295 msg='op=PAM:authentication acct="test"
exe="/usr/sbin/sshd" hostname=192.20.11.53 addr=192.20.11.53 terminal=ssh
es="success"


Does this mean that someone has authenticated via SSH using username and password, or with their private key? Is there a way to tell?







linux ssh logs






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked 21 mins ago







Bob Bobson The Third Esq.











migrated from security.stackexchange.com 8 mins ago


This question came from our site for information security professionals.






migrated from security.stackexchange.com 8 mins ago


This question came from our site for information security professionals.













  • not from that one line - suse.com/documentation/sles11/book_security/data/…
    – schroeder
    10 mins ago










  • Take a look at the options: access.redhat.com/documentation/en-us/red_hat_enterprise_linux/…
    – schroeder
    8 mins ago
















  • not from that one line - suse.com/documentation/sles11/book_security/data/…
    – schroeder
    10 mins ago










  • Take a look at the options: access.redhat.com/documentation/en-us/red_hat_enterprise_linux/…
    – schroeder
    8 mins ago















not from that one line - suse.com/documentation/sles11/book_security/data/…
– schroeder
10 mins ago




not from that one line - suse.com/documentation/sles11/book_security/data/…
– schroeder
10 mins ago












Take a look at the options: access.redhat.com/documentation/en-us/red_hat_enterprise_linux/…
– schroeder
8 mins ago




Take a look at the options: access.redhat.com/documentation/en-us/red_hat_enterprise_linux/…
– schroeder
8 mins ago















active

oldest

votes











Your Answer







StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "106"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);

else
createEditor();

);

function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
convertImagesToLinks: false,
noModals: false,
showLowRepImageUploadWarning: true,
reputationToPostImages: null,
bindNavPrevention: true,
postfix: "",
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);



);













 

draft saved


draft discarded


















StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f475912%2funderstanding-linux-audit-logs-for-ssh-user-auth%23new-answer', 'question_page');

);

Post as a guest


































active

oldest

votes













active

oldest

votes









active

oldest

votes






active

oldest

votes















 

draft saved


draft discarded















































 


draft saved


draft discarded














StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f475912%2funderstanding-linux-audit-logs-for-ssh-user-auth%23new-answer', 'question_page');

);

Post as a guest













































































lKmh8sbKKA1hsI ixyQh89 8g7JIS pD WmzW6ziJhGmrl0cYDII8djZps2Jcj,kYLZBigTEgSe
FdKAE4,H5cdR,a12gtl,5ivM043,2pN giTyQ,tcNrg8pO8nBmnlqf32NvqccCQzN,7roTrbO0,V0cA

Popular posts from this blog

How to check contact read email or not when send email to Individual?

How many registers does an x86_64 CPU actually have?

Displaying single band from multi-band raster using QGIS