LinuxÒÁµéÔ°Ê×Ò³

¿ØÖÆÃæ°å ×ÔÓÉÐÂÎÅ ×ÔÓÉÈí¼þ ×ÔÓÉÎĵµ ×ÔÓÉÂÛ̳ ×ÔÓÉÉÌ³Ç ÁªÏµÎÒÃÇ
ÎÒµÄÊÕ²Ø ÍÆ¼öÎÄÕ »áÔ±µÇ½ ×îºó¸üР¸ß¼¶ËÑË÷ Í˳öµÇ½
ÐÂÎŶ¯Ì¬
ÐÂÊÖÈëÃÅ
¼¼ÊõÇ°ÑØ
ϵͳ¹ÜÀí
ÍøÂç¹ÜÀí
ʹÓþ­Ñé
±à³Ì¿ª·¢
ϵͳ°²È«
½â¾ö·½°¸
Ó²¼þÏà¹Ø
Unix¼Ò×å
Êý¾Ý¿âÀà
¹ÛµãÆÀÂÛ
ÈËÎï½éÉÜ



Linuxeden.com-- Linuxeden ÐÂÎÅ Îĵµ ×ÊÁÏ ½Ì³Ì LinuxÒÁµéÔ° / ÍøÂç¹ÜÀí / Àí½âLinuxϵͳµÄÈÕÖ¾
Àí½âLinuxϵͳµÄÈÕÖ¾¡¡¡¡ÕÒlinux¹¤×÷,ÕÐlinuxÈ˲Å,µ½LinuxedenÈË²ÅÆµµÀ
2004-03-26    liuqing9906       µã»÷: 6196

ÒÔÏÂÄÚÈÝÓÉÒÁµéÔ°ÍøÓÑliuqing9906Ìṩ


Àí½âLinuxϵͳµÄÈÕÖ¾

ÕªÒª

¡¡¡¡ÈÕÖ¾¶ÔÓÚ°²È«À´Ëµ£¬·Ç³£ÖØÒª£¬Ëû¼Ç¼ÁËϵͳÿÌì·¢ÉúµÄ¸÷ÖÖ¸÷ÑùµÄÊÂÇ飬Äã¿ÉÒÔͨ¹ýËûÀ´¼ì²é´íÎó·¢Éú

µÄÔ­Òò£¬»òÕßÊܵ½¹¥»÷ʱ¹¥»÷ÕßÁôϵĺۼ£¡£ÈÕÖ¾Ö÷ÒªµÄ¹¦ÄÜÓУºÉó¼ÆºÍ¼à²â¡£Ëû»¹¿ÉÒÔʵʱµÄ¼à²âϵͳ״̬£¬

¼à²âºÍ×·×ÙÇÖÈëÕߵȵȡ£



¡¡¡¡1. ÈÕÖ¾¼ò½é

¡¡¡¡ÈÕÖ¾¶ÔÓÚ°²È«À´Ëµ£¬·Ç³£ÖØÒª£¬Ëû¼Ç¼ÁËϵͳÿÌì·¢ÉúµÄ¸÷ÖÖ¸÷ÑùµÄÊÂÇ飬Äã¿ÉÒÔͨ¹ýËûÀ´¼ì²é´íÎó·¢Éú

µÄÔ­Òò£¬»òÕßÊܵ½¹¥»÷ʱ¹¥»÷ÕßÁôϵĺۼ£¡£ÈÕÖ¾Ö÷ÒªµÄ¹¦ÄÜÓУºÉó¼ÆºÍ¼à²â¡£Ëû»¹¿ÉÒÔʵʱµÄ¼à²âϵͳ״̬£¬

¼à²âºÍ×·×ÙÇÖÈëÕߵȵȡ£

¡¡¡¡ÔÚLinuxϵͳÖУ¬ÓÐÈý¸öÖ÷ÒªµÄÈÕÖ¾×Óϵͳ£º

¡¡¡¡Á¬½Óʱ¼äÈÕÖ¾--Óɶà¸ö³ÌÐòÖ´ÐУ¬°Ñ¼Í¼дÈëµ½/var/log/wtmpºÍ/var/run/utmp£¬loginµÈ³ÌÐò¸ü

ÐÂwtmpºÍutmpÎļþ£¬Ê¹ÏµÍ³¹ÜÀíÔ±Äܹ»¸ú×ÙË­ÔÚºÎʱµÇ¼µ½ÏµÍ³¡£

¡¡¡¡½ø³Ìͳ¼Æ--ÓÉϵͳÄÚºËÖ´ÐС£µ±Ò»¸ö½ø³ÌÖÕֹʱ£¬ÎªÃ¿¸ö½ø³ÌÍù½ø³Ìͳ¼ÆÎļþ£¨pacct»òacct£©ÖÐдһ¸ö

¼Í¼¡£½ø³Ìͳ¼ÆµÄÄ¿µÄÊÇΪϵͳÖеĻù±¾·þÎñÌṩÃüÁîʹÓÃͳ¼Æ¡£

¡¡¡¡´íÎóÈÕÖ¾--ÓÉsyslogd£¨8£©Ö´ÐС£¸÷ÖÖÏµÍ³ÊØ»¤½ø³Ì¡¢Óû§³ÌÐòºÍÄÚºËͨ¹ýsyslog£¨3£©ÏòÎļþ

/var/log/messages±¨¸æÖµµÃ×¢ÒâµÄʼþ¡£ÁíÍâÓÐÐí¶àUNIX³ÌÐò´´½¨ÈÕÖ¾¡£ÏñHTTPºÍFTPÕâÑùÌá¹©ÍøÂç·þ

ÎñµÄ·þÎñÆ÷Ò²±£³ÖÏêϸµÄÈÕÖ¾¡£

¡¡¡¡³£ÓõÄÈÕÖ¾ÎļþÈçÏ£º

¡¡¡¡access-log ¼Í¼HTTP/webµÄ´«Êä

¡¡¡¡acct/pacct ¼Í¼Óû§ÃüÁî

¡¡¡¡aculog ¼Í¼MODEMµÄ»î¶¯

¡¡¡¡btmp ¼Í¼ʧ°ÜµÄ¼Í¼

¡¡¡¡lastlog ¼Í¼×î½ü¼¸´Î³É¹¦µÇ¼µÄʼþºÍ×îºóÒ»´Î²»³É¹¦µÄµÇ¼

¡¡¡¡messages ´ÓsyslogÖмǼÐÅÏ¢£¨ÓеÄÁ´½Óµ½syslogÎļþ£©

¡¡¡¡sudolog ¼Í¼ʹÓÃsudo·¢³öµÄÃüÁî

¡¡¡¡sulog ¼Í¼ʹÓÃsuÃüÁîµÄʹÓÃ

¡¡¡¡syslog ´ÓsyslogÖмǼÐÅÏ¢£¨Í¨³£Á´½Óµ½messagesÎļþ£©

¡¡¡¡utmp ¼Í¼µ±Ç°µÇ¼µÄÿ¸öÓû§

¡¡¡¡wtmp Ò»¸öÓû§Ã¿´ÎµÇ¼½øÈëºÍÍ˳öʱ¼äµÄÓÀ¾Ã¼Í¼

¡¡¡¡xferlog ¼Í¼FTP»á»°

¡¡¡¡utmp¡¢wtmpºÍlastlogÈÕÖ¾ÎļþÊǶàÊýÖØÓÃUNIXÈÕÖ¾×ÓϵͳµÄ¹Ø¼ü--±£³ÖÓû§µÇ¼½øÈëºÍÍ˳öµÄ¼Í¼¡£

Óйص±Ç°µÇ¼Óû§µÄÐÅÏ¢¼Ç¼ÔÚÎļþutmpÖУ»µÇ¼½øÈëºÍÍ˳ö¼Í¼ÔÚÎļþwtmpÖУ»×îºóÒ»´ÎµÇ¼Îļþ¿ÉÒÔ

ÓÃlastlogÃüÁî²ì¿´¡£Êý¾Ý½»»»¡¢¹Ø»úºÍÖØÆðÒ²¼Ç¼ÔÚwtmpÎļþÖС£ËùÓеļͼ¶¼°üº¬Ê±¼ä´Á¡£ÕâЩÎļþ

£¨lastlogͨ³£²»´ó£©ÔÚ¾ßÓдóÁ¿Óû§µÄϵͳÖÐÔö³¤Ê®·ÖѸËÙ¡£ÀýÈçwtmpÎļþ¿ÉÒÔÎÞÏÞÔö³¤£¬³ý·Ç¶¨ÆÚ½ØÈ¡¡£

Ðí¶àϵͳÒÔÒ»Ìì»òÕßÒ»ÖÜΪµ¥Î»°ÑwtmpÅäÖóÉÑ­»·Ê¹Óá£Ëüͨ³£ÓÉcronÔËÐеĽű¾À´Ð޸ġ£ÕâЩ½Å±¾ÖØÐÂÃü

Ãû²¢Ñ­»·Ê¹ÓÃwtmpÎļþ¡£Í¨³££¬wtmpÔÚµÚÒ»Ìì½áÊøºóÃüÃûΪwtmp.1£»µÚ¶þÌìºówtmp.1±äΪwtmp.2µÈµÈ£¬Ö±

µ½wtmp.7¡£

¡¡¡¡Ã¿´ÎÓÐÒ»¸öÓû§µÇ¼ʱ£¬login³ÌÐòÔÚÎļþlastlogÖв쿴Óû§µÄUID¡£Èç¹ûÕÒµ½ÁË£¬Ôò°ÑÓû§ÉϴεǼ¡¢

Í˳öʱ¼äºÍÖ÷»úÃûдµ½±ê×¼Êä³öÖУ¬È»ºólogin³ÌÐòÔÚlastlogÖмͼеĵǼʱ¼ä¡£ÔÚеÄlastlog¼Í¼д

Èëºó£¬utmpÎļþ´ò¿ª²¢²åÈëÓû§µÄutmp¼Í¼¡£¸Ã¼Í¼һֱÓõ½Óû§µÇ¼Í˳öʱɾ³ý¡£utmpÎļþ±»¸÷ÖÖÃüÁî

ÎļþʹÓ㬰üÀ¨who¡¢w¡¢usersºÍfinger¡£

¡¡¡¡ÏÂÒ»²½£¬login³ÌÐò´ò¿ªÎļþwtmp¸½¼ÓÓû§µÄutmp¼Í¼¡£µ±Óû§µÇ¼Í˳öʱ£¬¾ßÓиüÐÂʱ¼ä´ÁµÄͬ

Ò»utmp¼Í¼¸½¼Óµ½ÎļþÖС£wtmpÎļþ±»³ÌÐòlastºÍacʹÓá£

¡¡¡¡2. ¾ßÌåÃüÁî

¡¡¡¡wtmpºÍutmpÎļþ¶¼ÊǶþ½øÖÆÎļþ£¬ËûÃDz»Äܱ»ÖîÈçtailÃüÁî¼ôÌù»òºÏ²¢£¨Ê¹ÓÃcatÃüÁ¡£Óû§

ÐèҪʹÓÃwho¡¢w¡¢users¡¢lastºÍacÀ´Ê¹ÓÃÕâÁ½¸öÎļþ°üº¬µÄÐÅÏ¢¡£

¡¡¡¡who£ºwhoÃüÁî²éѯutmpÎļþ²¢±¨¸æµ±Ç°µÇ¼µÄÿ¸öÓû§¡£WhoµÄȱʡÊä³ö°üÀ¨Óû§Ãû¡¢ÖÕ¶ËÀàÐÍ¡¢µÇ¼

ÈÕÆÚ¼°Ô¶³ÌÖ÷»ú¡£ÀýÈ磺who£¨»Ø³µ£©ÏÔʾ


chyang pts/0 Aug 18 15:06
ynguo pts/2 Aug 18 15:32
ynguo pts/3 Aug 18 13:55
lewis pts/4 Aug 18 13:35
ynguo pts/7 Aug 18 14:12
ylou pts/8 Aug 18 14:15


¡¡¡¡Èç¹ûÖ¸Ã÷ÁËwtmpÎļþâZ?Ô¡??? ??¤ð?!Ãû£¬ÔòwhoÃüÁî²éѯËùÓÐÒÔǰµÄ¼Í¼¡£ÃüÁîwho /var/log/wtmp½«±¨¸æ×Ô´ÓwtmpÎļþ

´´½¨»òɾ¸ÄÒÔÀ´µÄÿһ´ÎµÇ¼¡£

¡¡¡¡w£ºwÃüÁî²éѯutmpÎļþ²¢ÏÔʾµ±Ç°ÏµÍ³ÖÐÿ¸öÓû§ºÍËüËùÔËÐеĽø³ÌÐÅÏ¢¡£ÀýÈ磺w£¨»Ø³µ£©ÏÔ

ʾ£º3:36pm up 1 day, 22:34, 6 users, load average: 0.23, 0.29, 0.27


USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT
chyang pts/0 202.38.68.242 3:06pm 2:04 0.08s 0.04s -bash
ynguo pts/2 202.38.79.47 3:32pm 0.00s 0.14s 0.05s w
lewis pts/3 202.38.64.233 1:55pm 30:39 0.27s 0.22s -bash
lewis pts/4 202.38.64.233 1:35pm 6.00s 4.03s 0.01s sh /home/users/
ynguo pts/7 simba.nic.ustc.e 2:12pm 0.00s 0.47s 0.24s telnet mail
ylou pts/8 202.38.64.235 2:15pm 1:09m 0.10s 0.04s -bash


¡¡¡¡users£ºusersÓõ¥¶ÀµÄÒ»ÐдòÓ¡³öµ±Ç°µÇ¼µÄÓû§£¬Ã¿¸öÏÔʾµÄÓû§Ãû¶ÔÓ¦Ò»¸öµÇ¼»á»°¡£Èç¹ûÒ»¸ö

Óû§Óв»Ö¹Ò»¸öµÇ¼»á»°£¬ÄÇËûµÄÓû§Ãû½«ÏÔʾÏàͬµÄ´ÎÊý¡£ÀýÈ磺users£¨»Ø³µ£©ÏÔ

ʾ£ºchyang lewis lewis ylou ynguo ynguo

¡¡¡¡last£ºlastÃüÁîÍù»ØËÑË÷wtmpÀ´ÏÔʾ×Ô´ÓÎļþµÚÒ»´Î´´½¨ÒÔÀ´µÇ¼¹ýµÄÓû§¡£ÀýÈ磺


chyang pts/9 202.38.68.242 Tue Aug 1 08:34 - 11:23 (02:49)
cfan pts/6 202.38.64.224 Tue Aug 1 08:33 - 08:48 (00:14)
chyang pts/4 202.38.68.242 Tue Aug 1 08:32 - 12:13 (03:40)
lewis pts/3 202.38.64.233 Tue Aug 1 08:06 - 11:09 (03:03)
lewis pts/2 202.38.64.233 Tue Aug 1 07:56 - 11:09 (03:12)


¡¡¡¡Èç¹ûÖ¸Ã÷ÁËÓû§£¬ÄÇôlastÖ»±¨¸æ¸ÃÓû§µÄ½üÆÚ»î¶¯£¬ÀýÈ磺last ynguo£¨»Ø³µ£©ÏÔʾ£º


ynguo pts/4 simba.nic.ustc.e Fri Aug 4 16:50 - 08:20 (15:30)
ynguo pts/4 simba.nic.ustc.e Thu Aug 3 23:55 - 04:40 (04:44)
ynguo pts/11 simba.nic.ustc.e Thu Aug 3 20:45 - 22:02 (01:16)
ynguo pts/0 simba.nic.ustc.e Thu Aug 3 03:17 - 05:42 (02:25)
ynguo pts/0 simba.nic.ustc.e Wed Aug 2 01:04 - 03:16 1+02:12)
ynguo pts/0 simba.nic.ustc.e Wed Aug 2 00:43 - 00:54 (00:11)
ynguo pts/9 simba.nic.ustc.e Thu Aug 1 20:30 - 21:26 (00:55)


¡¡¡¡ac£ºacÃüÁî¸ù¾Ýµ±Ç°µÄ/var/log/wtmpÎļþÖеĵǼ½øÈëºÍÍ˳öÀ´±¨¸æÓû§Á¬½áµÄʱ¼ä£¨Ð¡Ê±£©£¬

Èç¹û²»Ê¹ÓñêÖ¾£¬Ôò±¨¸æ×ܵÄʱ¼ä¡£ÀýÈ磺ac£¨»Ø³µ£©ÏÔʾ£ºtotal 5177.47

¡¡¡¡ac -d£¨»Ø³µ£©ÏÔʾÿÌìµÄ×ܵÄÁ¬½áʱ¼ä


Aug 12 total 261.87
Aug 13 total 351.39
Aug 14 total 396.09
Aug 15 total 462.63
Aug 16 total 270.45
Aug 17 total 104.29
Today total 179.02


¡¡¡¡ac -p £¨»Ø³µ£©ÏÔʾÿ¸öÓû§µÄ×ܵÄÁ¬½Óʱ¼ä


ynguo 193.23
yucao 3.35
rong 133.40
hdai 10.52
zjzhu 52.87
zqzhou 13.14
liangliu 24.34
total 5178.24


¡¡¡¡lastâZ?Ô¡??? ??¤ð?!log£ºlastlogÎļþÔÚÿ´ÎÓÐÓû§µÇ¼ʱ±»²éѯ¡£¿ÉÒÔʹÓÃlastlogÃüÁîÀ´¼ì²éÄ³ÌØ¶¨Óû§ÉÏ´Î

µÇ¼µÄʱ¼ä£¬²¢¸ñʽ»¯Êä³öÉϴεǼÈÕÖ¾/var/log/lastlogµÄÄÚÈÝ¡£Ëü¸ù¾ÝUIDÅÅÐòÏÔʾµÇ¼Ãû¡¢¶Ë¿Ú

ºÅ£¨tty£©ºÍÉϴεǼʱ¼ä¡£Èç¹ûÒ»¸öÓû§´ÓδµÇ¼¹ý£¬lastlogÏÔʾ"**Never logged**¡£×¢ÒâÐèÒª

ÒÔrootÔËÐиÃÃüÁÀýÈ磺


rong 5 202.38.64.187 Fri Aug 18 15:57:01 +0800 2000
dbb **Never logged in**
xinchen **Never logged in**
pb9511 **Never logged in**
xchen 0 202.38.64.190 Sun Aug 13 10:01:22 +0800 2000


¡¡¡¡ÁíÍ⣬¿ÉÒ»¼ÓһЩ²ÎÊý£¬ÀýÈ磬last -u 102½«±¨¸æUIDΪ102µÄÓû§£»last -t 7±íʾÏÞÖÆÉÏÒ»Öܵı¨¸æ¡£

¡¡¡¡3. ½ø³Ìͳ¼Æ

¡¡¡¡UNIX¿ÉÒÔ¸ú×Ùÿ¸öÓû§ÔËÐеÄÿÌõÃüÁÈç¹ûÏëÖªµÀ×òÍíŪÂÒÁËÄÄÐ©ÖØÒªµÄÎļþ£¬½ø³Ìͳ¼Æ×Óϵͳ¿É

ÒÔ¸æËßÄã¡£Ëü¶Ô»¹¸ú×ÙÒ»¸öÇÖÈëÕßÓаïÖú¡£ÓëÁ¬½Óʱ¼äÈÕÖ¾²»Í¬£¬½ø³Ìͳ¼Æ×Óϵͳȱʡ²»¼¤»î£¬Ëü±ØÐëÆô

¶¯¡£ÔÚLinuxϵͳÖÐÆô¶¯½ø³Ìͳ¼ÆÊ¹ÓÃacctonÃüÁ±ØÐëÓÃrootÉí·ÝÀ´ÔËÐС£AcctonÃüÁîµÄÐÎ

ʽaccton file£¬file±ØÐëÏÈ´æÔÚ¡£ÏÈʹÓÃtouchÃüÁîÀ´´´½¨pacctÎļþ£ºtouch /var/log/pacct£¬

È»ºóÔËÐÐaccton£º accton /var/log/pacct¡£Ò»µ©accton±»¼¤»î£¬¾Í¿ÉÒÔʹÓÃlastcommÃüÁî¼à²âϵͳ

ÖÐÈκÎʱºòÖ´ÐеÄÃüÁî¡£ÈôÒª¹Ø±Õͳ¼Æ£¬¿ÉÒÔʹÓò»´øÈκβÎÊýµÄacctonÃüÁî¡£

¡¡¡¡lastcommÃüÁ¸æÒÔǰִÐеÄÎļþ¡£²»´ø²ÎÊýʱ£¬lastcommÃüÁîÏÔʾµ±Ç°Í³¼ÆÎļþÉúÃüÖÜÆÚÄڼͼ

µÄËùÓÐÃüÁîµÄÓйØÐÅÏ¢¡£°üÀ¨ÃüÁîÃû¡¢Óû§¡¢tty¡¢ÃüÁ·ÑµÄCPUʱ¼äºÍÒ»¸öʱ¼ä´Á¡£Èç¹ûϵͳÓÐÐí¶àÓÃ

»§£¬ÊäÈëÔò¿ÉÄܺܳ¤¡£ÏÂÃæµÄÀý×Ó£º


crond F root ?? 0.00 secs Sun Aug 20 00:16
promisc_check.s S root ?? 0.04 secs Sun Aug 20 00:16
promisc_check root ?? 0.01 secs Sun Aug 20 00:16
grep root ?? 0.02 secs Sun Aug 20 00:16
tail root ?? 0.01 secs Sun Aug 20 00:16
sh root ?? 0.01 secs Sun Aug 20 00:15
ping S root ?? 0.01 secs Sun Aug 20 00:15
ping6.pl F root ?? 0.01 secs Sun Aug 20 00:15
sh root ?? 0.01 secs Sun Aug 20 00:15
ping S root ?? 0.02 secs Sun Aug 20 00:15
ping6.pl F root ?? 0.02 secs Sun Aug 20 00:15
sh root ?? 0.02 secs Sun Aug 20 00:15
ping S root ?? 0.00 secs Sun Aug 20 00:15
ping6.pl F root ?? 0.01 secs Sun Aug 20 00:15
sh root ?? 0.01 secs Sun Aug 20 00:15
ping S root ?? 0.01 secs Sun Aug 20 00:15
sh root ?? 0.02 secs Sun Aug 20 00:15
ping S root ?? 1.34 secs Sun Aug 20 00:15
locate root ttyp0 1.34 secs Sun Aug 20 00:15
accton S root ttyp0 0.00 secs Sun Aug 20 00:15


¡¡¡¡½ø³Ìͳ¼ÆµÄÒ»¸öÎÊÌâÊÇpacctÎļþ¿ÉÄÜÔö³¤µÄÊ®·ÖѸËÙ¡£ÕâʱÐèÒª½»»¥Ê½µÄ»ò¾­¹ýcron»úÖÆÔËÐÐsaÃü

ÁîÀ´±£³ÖÈÕÖ¾Êý¾ÝÔÚϵͳ¿ØÖÆÄÚ¡£saÃüÁ¸æ¡¢ÇåÀí²¢Î¬»¤½ø³Ìͳ¼ÆÎļþ¡£ËüÄܰÑ/var/log/pacctÖеÄÐÅ

ϢѹËõµ½ÕªÒªÎļþ/var/log/savacctºÍ/var/log/usracctÖС£ÕâЩժҪ°üº¬°´ÃüÁîÃûºÍÓû§Ãû·ÖÀàµÄϵͳ

ͳ¼ÆÊý¾Ý¡£saȱʡÇé¿öÏÂÏȶÁËüÃÇ£¬È»ºó¶ÁpacctÎļþ£¬Ê¹±¨¸æÄܰüâZ?Ô¡??? ??¤ð?!º¬ËùÓеĿÉÓÃÐÅÏ¢¡£saµÄÊä³öÓÐÏÂÃæÒ»

Щ±ê¼ÇÏ

¡¡¡¡avio--ÿ´ÎÖ´ÐÐµÄÆ½¾ùI/O²Ù×÷´ÎÊý

¡¡¡¡cp--Óû§ºÍϵͳʱ¼ä×ܺͣ¬ÒÔ·ÖÖÓ¼Æ

¡¡¡¡cpu--ºÍcpÒ»Ñù

¡¡¡¡k--ÄÚºËʹÓÃµÄÆ½¾ùCPUʱ¼ä£¬ÒÔ1kΪµ¥Î»

¡¡¡¡k*sec--CPU´æ´¢ÍêÕûÐÔ£¬ÒÔ1k-coreÃë

¡¡¡¡re--ʵʱʱ¼ä£¬ÒÔ·ÖÖÓ¼Æ

¡¡¡¡s--ϵͳʱ¼ä£¬ÒÔ·ÖÖÓ¼Æ

¡¡¡¡tio--I/O²Ù×÷µÄ×ÜÊý

¡¡¡¡u--Óû§Ê±¼ä£¬ÒÔ·ÖÖÓ¼Æ

¡¡¡¡ÀýÈ磺


842 173.26re 4.30cp 0avio 358k
2 10.98re 4.06cp 0avio 299k find
9 24.80re 0.05cp 0avio 291k ***other
105 30.44re 0.03cp 0avio 302k ping
104 30.55re 0.03cp 0avio 394k sh
162 0.11re 0.03cp 0avio 413k security.sh*
154 0.03re 0.02cp 0avio 273k ls
56 31.61re 0.02cp 0avio 823k ping6.pl*
2 3.23re 0.02cp 0avio 822k ping6.pl
35 0.02re 0.01cp 0avio 257k md5sum
97 0.02re 0.01cp 0avio 263k initlog
12 0.19re 0.01cp 0avio 399k promisc_check.s
15 0.09re 0.00cp 0avio 288k grep
11 0.08re 0.00cp 0avio 332k awk


¡¡¡¡Óû§»¹¿ÉÒÔ¸ù¾ÝÓû§¶ø²»ÊÇÃüÁîÀ´Ìṩһ¸öÕªÒª±¨¸æ¡£ÀýÈçsa -mÏÔʾÈçÏ£º


885 173.28re 4.31cp 0avk
root 879 173.23re 4.31cp 0avk
alias 3 0.05re 0.00cp 0avk
qmailp 3 0.01re 0.00cp 0avk


¡¡¡¡4. SyslogÉ豸

¡¡¡¡SyslogÒѱ»Ðí¶àÈÕÖ¾º¯Êý²ÉÄÉ£¬ËüÓÃÔÚÐí¶à±£»¤´ëÊ©ÖÐ--ÈκγÌÐò¶¼¿ÉÒÔͨ¹ýsyslog ¼Í¼Ê¼þ¡£
syslog¿ÉÒԼͼϵͳʼþ£¬¿ÉÒÔдµ½Ò»¸öÎļþ»òÉ豸ÖУ¬»ò¸øÓû§·¢ËÍÒ»¸öÐÅÏ¢¡£ËüÄܼͼ±¾µØÊ¼þ»òͨ¹ý

ÍøÂç¼Í¼ÁíÒ»¸öÖ÷»úÉϵÄʼþ¡£

¡¡¡¡SyslogÉ豸ÒÀ¾ÝÁ½¸öÖØÒªµÄÎļþ£º/etc/syslogd£¨ÊØ»¤½ø³Ì£©ºÍ/etc/syslog.confÅäÖÃÎļþ£¬Ï°¹ßÉÏ£¬

¶àÊýsyslogÐÅÏ¢±»Ð´µ½/var/adm»ò/var/logĿ¼ÏµÄÐÅÏ¢ÎļþÖУ¨messages.*£©¡£Ò»¸öµäÐ͵Äsyslog¼Í¼°ü

À¨Éú³É³ÌÐòµÄÃû×ÖºÍÒ»¸öÎı¾ÐÅÏ¢¡£Ëü»¹°üÀ¨Ò»¸öÉ豸ºÍÒ»¸öÓÅÏȼ¶·¶Î§£¨µ«²»ÔÚÈÕÖ®ÖгöÏÖ£©¡£

¡¡¡¡Ã¿¸ösyslogÏûÏ¢±»¸³ÓèÏÂÃæµÄÖ÷ÒªÉ豸֮һ£º

¡¡¡¡LOG_AUTH--ÈÏ֤ϵͳ£ºlogin¡¢su¡¢gettyµÈ

¡¡¡¡LOG_AUTHPRIV--ͬLOG_AUTH£¬µ«Ö»µÇ¼µ½ËùÑ¡ÔñµÄµ¥¸öÓû§¿É¶ÁµÄÎļþÖÐ

¡¡¡¡LOG_CRON--cronÊØ»¤½ø³Ì

¡¡¡¡LOG_DAEMON--ÆäËûÏµÍ³ÊØ»¤½ø³Ì£¬Èçrouted

¡¡¡¡LOG_FTP--Îļþ´«ÊäЭÒ飺ftpd¡¢tftpd

¡¡¡¡LOG_KERN--Äں˲úÉúµÄÏûÏ¢

¡¡¡¡LOG_LPR--ϵͳ´òÓ¡»ú»º³å³Ø£ºlpr¡¢lpd

¡¡¡¡LOG_MAIL--µç×ÓÓʼþϵͳ

¡¡¡¡LOG_NEWS--ÍøÂçÐÂÎÅϵͳ

¡¡¡¡LOG_SYSLOG--ÓÉsyslogd£¨8£©²úÉúµÄÄÚ²¿ÏûÏ¢

¡¡¡¡LOG_USER--Ëæ»úÓû§½ø³Ì²úÉúµÄÏûÏ¢

¡¡¡¡LOG_UUCP--UUCP×Óϵͳ

¡¡¡¡LOG_LOCAL0~LOG_LOCAL7--Ϊ±¾µØÊ¹Óñ£Áô

¡¡¡¡SyslogΪÿ¸öʼþ¸³Ó輸¸ö²»Í¬µÄÓÅÏȼ¶£º

¡¡¡¡LOG_EMERG--½ô¼±Çé¿ö

¡¡¡¡LOG_ALERT--Ó¦¸Ã±»Á¢¼´¸ÄÕýµÄÎÊÌ⣬ÈçϵͳÊý¾Ý¿âÆÆ»µ

¡¡¡¡LOG_CRIT--ÖØÒªÇé¿ö£¬ÈçÓ²ÅÌ´íÎó

¡¡¡¡LOG_ERR--´íÎó

¡¡¡¡LOG_WARNING--¾¯¸æÐÅÏ¢

¡¡¡¡LOG_NOTICE--²»ÊÇ´íÎóÇé¿ö£¬µ«ÊÇ¿ÉÄÜÐèÒª´¦Àí

¡¡¡¡LOG_INFO--Ç鱨ÐÅÏ¢

¡¡¡¡LOG_DEBUG--°üº¬Ç鱨µÄÐÅÏ¢£¬Í¨³£Ö¼ÔÚµ÷ÊÔÒ»¸ö³ÌÐòʱʹÓÃ

¡¡¡¡syslog.confÎļþÖ¸Ã÷syslogd³ÌÐò¼Í¼ÈÕÖ¾µÄÐÐΪ£¬¸Ã³ÌÐòÔÚÆô¶¯Ê±²éѯÅäÖÃÎļþ¡£¸ÃÎļþÓɲ»Í¬³Ì

Ðò»òÏûÏ¢·ÖÀàµÄµ¥¸öÌõÄ¿×é³É£¬Ã¿¸öÕ¼Ò»ÐС£¶ÔÿÀàÏûÏ¢Ìṩһ¸öÑ¡ÔñÓòºÍÒ»¸ö¶¯×÷Óò¡£ÕâЩÓòÓÉtab¸ô¿ª£º

Ñ¡ÔñÓòâZ?Ô¡??? ??¤ð?!Ö¸Ã÷ÏûÏ¢µÄÀàÐͺÍÓÅÏȼ¶£»¶¯×÷ÓòÖ¸Ã÷syslogd½ÓÊÕµ½Ò»¸öÓëÑ¡Ôñ±ê×¼ÏàÆ¥ÅäµÄÏûϢʱËùÖ´Ðе͝×÷¡£

ÿ¸öÑ¡ÏîÊÇÓÉÉ豸ºÍÓÅÏȼ¶×é³É¡£µ±Ö¸Ã÷Ò»¸öÓÅÏȼ¶Ê±£¬syslogd½«¼Í¼һ¸öÓµÓÐÏàͬ»ò¸ü¸ßÓÅÏȼ¶µÄÏûÏ¢¡£

ËùÒÔÈç¹ûÖ¸Ã÷"crit"£¬ÄÇËùÓбêΪcrit¡¢alertºÍemergµÄÏûÏ¢½«±»¼Í¼¡£Ã¿ÐеÄÐж¯ÓòÖ¸Ã÷µ±Ñ¡ÔñÓòÑ¡ÔñÁËÒ»¸ö

¸ø¶¨ÏûÏ¢ºóÓ¦¸Ã°ÑËû·¢Ë͵½ÄĶù¡£ÀýÈ磬Èç¹ûÏë°ÑËùÓÐÓʼþÏûÏ¢¼Í¼µ½Ò»¸öÎļþÖУ¬ÈçÏ£º


#Log all the mail messages in one place
mail.* /var/log/maillog


¡¡¡¡ÆäËûÉ豸ҲÓÐ×Ô¼ºµÄÈÕÖ¾¡£UUCPºÍnewsÉ豸ÄܲúÉúÐí¶àÍⲿÏûÏ¢¡£Ëü°ÑÕâЩÏûÏ¢´æµ½×Ô¼ºµÄÈÕÖ¾

£¨/var/log/spooler£©Öв¢°Ñ¼¶±ðÏÞΪ"err"»ò¸ü¸ß¡£ÀýÈ磺


# Save mail and news errors of level err and higher in aspecial file.
uucp,news.crit /var/log/spooler


¡¡¡¡µ±Ò»¸ö½ô¼±ÏûÏ¢µ½À´Ê±£¬¿ÉÄÜÏëÈÃËùÓеÄÓû§¶¼µÃµ½¡£Ò²¿ÉÄÜÏëÈÃ×Ô¼ºµÄÈÕÖ¾½ÓÊÕ²¢±£´æ¡£


#Everybody gets emergency messages£¬ plus log them on anther machine
*.emerg *
*.emerg @linuxaid.com.cn


¡¡¡¡alertÏûÏ¢Ó¦¸Ãдµ½rootºÍtigerµÄ¸öÈËÕ˺ÅÖУº


#Root and Tiger get alert and higher messages
*.alert root,tiger


¡¡¡¡ÓÐʱsyslogd½«²úÉú´óÁ¿µÄÏûÏ¢¡£ÀýÈçÄںˣ¨"kern"É豸£©¿ÉÄܺÜÈß³¤¡£Óû§¿ÉÄÜÏë°ÑÄÚºËÏûÏ¢¼Í¼

µ½/dev/consoleÖС£ÏÂÃæµÄÀý×Ó±íÃ÷ÄÚºËÈÕÖ¾¼Í¼±»×¢Ê͵ôÁË£º


#Log all kernel messages to the console
#Logging much else clutters up the screen
#kern.* /dev/console


¡¡¡¡Óû§¿ÉÒÔÔÚÒ»ÐÐÖÐÖ¸Ã÷ËùÓеÄÉ豸¡£ÏÂÃæµÄÀý×Ó°Ñinfo»ò¸ü¸ß¼¶±ðµÄÏûÏ¢Ë͵½/var/log/messages£¬

³ýÁËmailÒÔÍâ¡£¼¶±ð"none"½ûÖ¹Ò»¸öÉ豸£º


#Log anything£¨except mail£©of level info or higher
#Dont log private authentication messages!
*.info:mail.none;authpriv.none /var/log/messages


¡¡¡¡ÔÚÓÐЩÇé¿öÏ£¬¿ÉÒÔ°ÑÈÕÖ¾Ë͵½´òÓ¡»ú£¬ÕâÑùÍøÂçÈëÇÖÕßÔõôÐÞ¸ÄÈÕÖ¾¶¼Ã»ÓÐÓÃÁË¡£Í¨³£Òª¹ã·º¼Í¼

ÈÕÖ¾¡£SyslogÉ豸ÊÇÒ»¸ö¹¥»÷ÕßµÄÏÔÖøÄ¿±ê¡£Ò»¸öΪÆäËûÖ÷»úά»¤ÈÕÖ¾µÄϵͳ¶ÔÓÚ·À·¶·þÎñÆ÷¹¥»÷ÌØ±ð´à

Èõ£¬Òò´ËÒªÌØ±ð×¢Òâ¡£

¡¡¡¡ÓиöСÃüÁîloggerΪsyslog£¨3£©ÏµÍ³ÈÕÖ¾ÎļþÌṩһ¸öshellÃüÁî½Ó¿Ú£¬Ê¹Óû§ÄÜ´´½¨ÈÕÖ¾ÎļþÖеÄÌõ

Ä¿¡£Ó÷¨£ºlogger ÀýÈ磺logger This is a test£¡

¡¡¡¡Ëü½«²úÉúÒ»¸öÈçϵÄsyslog¼Í¼£ºAug 19 22:22:34 tiger: This is a test!

¡¡¡¡×¢Òâ²»ÒªÍêÈ«ÏàÐÅÈÕÖ¾£¬ÒòΪ¹¥»÷ÕߺÜÈÝÒ×ÐÞ¸ÄËüµÄ¡£

¡¡¡¡5. ³ÌÐòÈÕÖ¾

¡¡¡¡Ðí¶à³ÌÐòͨ¹ýά»¤ÈÕÖ¾À´·´Ó³ÏµÍ³µÄ°²È«×´Ì¬¡£suÃüÁîÔÊÐíÓû§»ñµÃÁíÒ»¸öÓû§µÄȨÏÞ£¬ËùÒÔËüµÄ°²È«

ºÜÖØÒª£¬ËüµÄÎļþΪsulog¡£Í¬ÑùµÄ»¹ÓÐsudolog¡£ÁíÍ⣬ÏëApacheÓÐÁ½¸öÈÕÖ¾£ºaccess_logºÍerror_log¡£

¡¡¡¡6. ÆäËûÈÕÖ¾¹¤¾ß


chklastlog
ftp://coast.cs.purdue.edu/pub/tools/unix/chklastlog/
chkwtmp
ftp://coast.cs.purdue.edu/pub/tools/unix/chkwtmp/
dump_lastlog
ftp://coast.cs.purdue.edu/pub/tools/unix/dump_lastlog.Z
spar
ftp://coast.cs.purdue.edu/pub/tools/unix/TAMU/
Swatch
http://www.lomar.org/komar/alek/pres/swatch/cover.html
Zap
ftp://caost.cs.purdue.edu/pub/tools/unix/zap.tar.gz
ÈÕÖ¾·ÖÀà·½·¨
http:/âZ?Ô¡??? ??¤ð?!/csrc.nist.gov/nissc/1998/proceedings/paperD1.pdf




ÔðÈα༭: liuqing9906
·¢±íÆÀÂÛ ²é¿´ÆÀÂÛ ¼ÓÈëÊÕ²Ø Email¸øÅóÓÑ ´òÓ¡±¾ÎÄ
Èç¹ûÄãÏë¶Ô¸ÃÎÄÕÂÆÀ·Ö, ÇëÏȵǽ, Èç¹ûÄãÈÔδע²á,Çëµã»÷×¢²áÁ´½Ó×¢²á³ÉΪ±¾Õ¾»áÔ±.
ƽ¾ùµÃ·Ö 0, ¹² 0 ÈËÆÀ·Ö
1 2 3 4 5 6 7 8 9 10
Copyright © 2002 -2003 Linuxeden.com-- Linuxeden ÐÂÎÅ Îĵµ ×ÊÁÏ ½Ì³Ì LinuxÒÁµéÔ°
All rights reserved.