SYSLOG and security ? on RH9

Angelo tenaciousone at gmail.com
Mon Jun 6 00:41:54 UTC 2005


Naturally by these questions, I'm not as an Seasoned Veteran of Linux
as I am with Winblow$ machines so I'm stumbling a little but I have 5
questions: Syslogs and security;

1. Where are the SYSTEM logs stored?
2. I saw this in my logs today "Jun  5 04:02:29 MYSERVERNAME syslogd
1.4.1: restart." - I didn't restart my computer and if I'm correct,
does this mean my system was started?
3. I know what it is on a WinBlow$ machine but I'm not sure on Linux,
if a new account is on the system, where is that security event
shown/tracked?
4. My Security logs only showed two entries :Jun  5 17:23:14
MYSERVERNAME xinetd[3358]: START: sgi_fam pid=13765 from=<no address>
Jun  5 20:19:32 MYSERVERNAME xinetd[3358]: START: sgi_fam pid=14119
from=<no address>", this can't be possible - it appears to have been
cleared? Is that possible?
5. How can I prevent my logs from being cleared and/or track when they
have been?

Thanks in advance.

-- 
/==========The One===========\
"..I don't care your a PhD...put you're hands up, and step away from
my keyboard..."




More information about the redhat-list mailing list