Generally you'll need a filter facility (auth) but you should check that first by sending the logs. On Apr 28, 2015 7:06 PM, <wiskbroom@hotmail.com> wrote:
Greetings;
This is question is slightly OT, but I can't imagine a better place to ask; so please, no flames.
I would like to begin logging all attempts (succesful, failed, no password given, etc) to login to Sparc/Solaris machines, as well as RedHat 6 Linux boxes. My clients are using stock syslog, but my server is running syslog-NG; my second goal is to redirect all login type logs to just one file for ALL of my Solaris & Linux servers.
Does anyone have a known good syslog config file for both Solaris, and Linux?
Also, a good syslog-NG entry to force just the console and ssh data into a separate file?
Thank you!
.vp
______________________________________________________________________________ Member info: https://lists.balabit.hu/mailman/listinfo/syslog-ng Documentation: http://www.balabit.com/support/documentation/?product=syslog-ng FAQ: http://www.balabit.com/wiki/syslog-ng-faq