[linux] sftp logIT/linux2022. 8. 26. 21:40
Table of Contents
목적 : sftp 프로토콜 사용시 사용자의 접속 시간, ip, 경로를 확인하기 위함
환경 : Ubuntu 20.04
man sftp-server
-f type = DAEMON, USER, AUTH, LOCAL0, LOCAL1, LOCAL2, LOCAL3, LOCAL4, LOCAL5, LOCAL6, LOCAL7.
-l type = QUIET, FATAL, ERROR, INFO, VERBOSE, DEBUG, DEBUG1, DEBUG2, DEBUG3
vi /etc/ssh/sshd_config
# Logging
SyslogFacility local4
#LogLevel DEBUG1
# override default of no subsystems
# log_facility, log_level 설정
# add
Subsystem sftp /usr/lib/openssh/sftp-server -f local4 -l INFO
systemctl restart sshd
vi /etc/rsyslog.d/50-default.conf # rsyslog 설정 추가
local3.* /var/log/sftp.log
systemctl restart rsyslog
vi /etc/logrotate.d/rsyslog # logrotate 등록
/var/log/syslog
/var/log/cmd.log
{
rotate 7
daily
missingok
notifempty
delaycompress
compress
postrotate
/usr/lib/rsyslog/rsyslog-rotate
endscript
}
/var/log/mail.info
/var/log/mail.warn
/var/log/mail.err
/var/log/mail.log
/var/log/daemon.log
/var/log/kern.log
/var/log/auth.log
/var/log/user.log
/var/log/lpr.log
/var/log/cron.log
/var/log/debug
/var/log/messages
# add
/var/log/sftp.log
{
rotate 4
weekly
missingok
notifempty
compress
delaycompress
sharedscripts
postrotate
/usr/lib/rsyslog/rsyslog-rotate
endscript
}
systemctl restart logrotate.service
'IT > linux' 카테고리의 다른 글
[linux] ubuntu Error: Waiting for cache lock (0) | 2022.09.30 |
---|---|
[linux] Google Authenticator (0) | 2022.09.30 |
[linux] ntp 설정 (0) | 2022.08.25 |
[linux] postfix error (0) | 2022.08.25 |
[linux] postfix command (0) | 2022.08.25 |
@주니- :: 주니
포스팅이 좋았다면 "좋아요❤️" 또는 "구독👍🏻" 해주세요!