¡¡¡¡³É¹¦µØ¹ÜÀíÈκÎϵͳµÄ¹Ø¼üÖ®Ò»£¬ÊÇÒªÖªµÀϵͳÖÐÕýÔÚ·¢ÉúʲôÊ¡£Linux ÖÐÌṩÁËÒì³£ÈÕÖ¾£¬²¢ÇÒÈÕÖ¾µÄϸ½ÚÊÇ¿ÉÅäÖõġ£Linux ÈÕÖ¾¶¼ÒÔÃ÷ÎÄÐÎʽ´æ´¢£¬ËùÒÔÓû§²»ÐèÒªÌØÊâµÄ¹¤¾ß¾Í¿ÉÒÔËÑË÷ºÍÔĶÁËüÃÇ¡£»¹¿ÉÒÔ±àд½Å±¾£¬À´É¨ÃèÕâЩÈÕÖ¾£¬²¢»ùÓÚËüÃǵÄÄÚÈÝÈ¥×Ô¶¯Ö´ÐÐijЩ¹¦ÄÜ¡£ Linux ÈÕÖ¾´æ´¢ÔÚ /var/log Ŀ¼ÖС£ÕâÀïÓм¸¸öÓÉϵͳά»¤µÄÈÕÖ¾Îļþ£¬µ«ÆäËû·þÎñºÍ³ÌÐòÒ²¿ÉÄÜ»á°ÑËüÃǵÄÈÕÖ¾·ÅÔÚÕâÀï¡£´ó¶àÊýÈÕÖ¾Ö»ÓÐrootÕË»§²Å¿ÉÒÔ¶Á£¬²»¹ýÐÞ¸ÄÎļþµÄ·ÃÎÊȨÏ޾ͿÉÒÔÈÃÆäËûÈ˿ɶÁ¡£
¡¡¡¡RedHat Linux³£ÓõÄÈÕÖ¾Îļþ
¡¡¡¡RedHat Linux³£¼ûµÄÈÕÖ¾ÎļþÏêÊöÈçÏÂ
¡¡¡¡/var/log/boot.log
¡¡¡¡¸ÃÎļþ¼Ç¼ÁËϵͳÔÚÒýµ¼¹ý³ÌÖз¢ÉúµÄʼþ£¬¾ÍÊÇLinuxϵͳ¿ª»ú×Ô¼ì¹ý³ÌÏÔʾµÄÐÅÏ¢¡£
¡¡¡¡/var/log/cron
¡¡¡¡¸ÃÈÕÖ¾Îļþ¼Ç¼crontabÊØ»¤½ø³ÌcrondËùÅÉÉúµÄ×Ó½ø³ÌµÄ¶¯×÷£¬Ç°Ãæ¼ÓÉÏÓû§¡¢µÇ¼ʱ¼äºÍPID£¬ÒÔ¼°ÅÉÉú³öµÄ½ø³ÌµÄ¶¯×÷¡£CMDµÄÒ»¸ö¶¯×÷ÊÇcronÅÉÉú³öÒ»¸öµ÷¶È½ø³ÌµÄ³£¼ûÇé¿ö¡£REPLACE£¨Ìæ»»£©¶¯×÷¼Ç¼Óû§¶ÔËüµÄcronÎļþµÄ¸üУ¬¸ÃÎļþÁгöÁËÒªÖÜÆÚÐÔÖ´ÐеÄÈÎÎñµ÷¶È¡£ RELOAD¶¯×÷ÔÚREPLACE¶¯×÷ºó²»¾Ã·¢Éú£¬ÕâÒâζ×Åcron×¢Òâµ½Ò»¸öÓû§µÄcronÎļþ±»¸üжøcronÐèÒª°ÑËüÖØÐÂ×°ÈëÄÚ´æ¡£¸ÃÎļþ¿ÉÄÜ»á²éµ½Ò»Ð©·´³£µÄÇé¿ö¡£
¡¡¡¡/var/log/maillog
¡¡¡¡¸ÃÈÕÖ¾Îļþ¼Ç¼ÁËÿһ¸ö·¢Ë͵½ÏµÍ³»ò´Óϵͳ·¢³öµÄµç×ÓÓʼþµÄ»î¶¯¡£Ëü¿ÉÒÔÓÃÀ´²é¿´Óû§Ê¹ÓÃÄĸöϵͳ·¢Ë͹¤¾ß»ò°ÑÊý¾Ý·¢Ë͵½Äĸöϵͳ¡£ÏÂÃæÊǸÃÈÕÖ¾ÎļþµÄƬ¶Î£º
Sep 4 17:23:52 UNIX sendmail[1950]: g849Npp01950: from=root, size=25,
class=0, nrcpts=1,
msgid=<200209040923.g849Npp01950@redhat.pfcc.com.cn>,
relay=root@localhost
Sep 4 17:23:55 UNIX sendmail[1950]: g849Npp01950: to=lzy@fcceec.net,
ctladdr=root (0/0), delay=00:00:04, xdelay=00:00:03, mailer=esmtp, pri=30025,
relay=fcceec.net. [10.152.8.2], dsn=2.0.0, stat=Sent (Message queued)
/var/log/messages
¡¡¡¡¸ÃÈÕÖ¾ÎļþÊÇÐí¶à½ø³ÌÈÕÖ¾ÎļþµÄ»ã×Ü£¬´Ó¸ÃÎļþ¿ÉÒÔ¿´³öÈκÎÈëÇÖÆóͼ»ò³É¹¦µÄÈëÇÖ¡£ÈçÒÔϼ¸ÐУº
Sep 3 08:30:17 UNIX login[1275]: FAILED LOGIN 2 FROM (null) FOR suying,
Authentication failure
Sep 4 17:40:28 UNIX -- suying[2017]: LOGIN ON pts/1 BY suying FROM
fcceec.www.ec8.pfcc.com.cn
Sep 4 17:40:39 UNIX su(pam_unix)[2048]: session opened for user root by suying(uid=999)
¡¡¡¡¸ÃÎļþµÄ¸ñʽÊÇÿһÐаüº¬ÈÕÆÚ¡¢Ö÷»úÃû¡¢³ÌÐòÃû£¬ºóÃæÊǰüº¬PID»òÄں˱êʶµÄ·½À¨ºÅ¡¢Ò»¸öðºÅºÍÒ»¸ö¿Õ¸ñ£¬×îºóÊÇÏûÏ¢¡£¸ÃÎļþÓÐÒ»¸ö²»×㣬¾ÍÊDZ»¼Ç¼µÄÈëÇÖÆóͼºÍ³É¹¦µÄÈëÇÖʼþ£¬±»ÑÍûÔÚ´óÁ¿µÄÕý³£½ø³ÌµÄ¼Ç¼ÖС£µ«¸ÃÎļþ¿ÉÒÔÓÉ /etc/syslogÎļþ½øÐж¨ÖÆ¡£ÓÉ /etc/syslog.confÅäÖÃÎļþ¾ö¶¨ÏµÍ³ÈçºÎдÈë/var/messages¡£ÓйØÈçºÎÅäÖÃ/etc/syslog.confÎļþ¾ö¶¨ÏµÍ³ÈÕÖ¾¼Ç¼µÄÐÐΪ£¬½«ÔÚºóÃæÏêϸÐðÊö¡£
¡¡¡¡/var/log/syslog
¡¡¡¡Ä¬ÈÏRedHat Linux²»Éú³É¸ÃÈÕÖ¾Îļþ£¬µ«¿ÉÒÔÅäÖÃ/etc/syslog.confÈÃϵͳÉú³É¸ÃÈÕÖ¾Îļþ¡£ËüºÍ/etc/log/messagesÈÕÖ¾Îļþ²»Í¬£¬ËüÖ»¼Ç¼¾¯¸æÐÅÏ¢£¬³£³£ÊÇϵͳ³öÎÊÌâµÄÐÅÏ¢£¬ËùÒÔ¸üÓ¦¸Ã¹Ø×¢¸ÃÎļþ¡£ÒªÈÃϵͳÉú³É¸ÃÈÕÖ¾Îļþ£¬ÔÚ/etc/syslog.confÎļþÖмÓÉÏ£º *.warning /var/log/syslog
¡¡¡¡¸ÃÈÕÖ¾ÎļþÄܼǼµ±Óû§µÇ¼ʱlogin¼Ç¼ÏµĴíÎó¿ÚÁî¡¢SendmailµÄÎÊÌâ¡¢suÃüÁîÖ´ÐÐʧ°ÜµÈÐÅÏ¢¡£ÏÂÃæÊÇÒ»Ìõ¼Ç¼£º
Sep 6 16:47:52 UNIX login(pam_unix)[2384]: check pass; user unknown
/var/log/secure
¸ÃÈÕÖ¾Îļþ¼Ç¼Ó밲ȫÏà¹ØµÄÐÅÏ¢¡£¸ÃÈÕÖ¾ÎļþµÄ²¿·ÖÄÚÈÝÈçÏ£º
Sep 4 16:05:09 UNIX xinetd[711]: START: ftp pid=1815 from=127.0.0.1
Sep 4 16:05:09 UNIX xinetd[1815]: USERID: ftp OTHER :root
Sep 4 16:07:24 UNIX xinetd[711]: EXIT: ftp pid=1815 duration=135(sec)
Sep 4 16:10:05 UNIX xinetd[711]: START: ftp pid=1846 from=127.0.0.1
Sep 4 16:10:05 UNIX xinetd[1846]: USERID: ftp OTHER :root
Sep 4 16:16:26 UNIX xinetd[711]: EXIT: ftp pid=1846 duration=381(sec)
Sep 4 17:40:20 UNIX xinetd[711]: START: telnet pid=2016 from=10.152.8.2
/var/log/lastlog
¡¡¡¡¸ÃÈÕÖ¾Îļþ¼Ç¼×î½ü³É¹¦µÇ¼µÄʼþºÍ×îºóÒ»´Î²»³É¹¦µÄµÇ¼Ê¼þ£¬ÓÉloginÉú³É¡£ÔÚÿ´ÎÓû§µÇ¼ʱ±»²éѯ£¬¸ÃÎļþÊǶþ½øÖÆÎļþ£¬ÐèҪʹÓà lastlogÃüÁî²é¿´£¬¸ù¾ÝUIDÅÅÐòÏÔʾµÇ¼Ãû¡¢¶Ë¿ÚºÅºÍÉϴεǼʱ¼ä¡£Èç¹ûijÓû§´ÓÀ´Ã»ÓеǼ¹ý£¬¾ÍÏÔʾΪ"**Never logged in**"¡£¸ÃÃüÁîÖ»ÄÜÒÔrootȨÏÞÖ´ÐС£¼òµ¥µØÊäÈëlastlogÃüÁîºó¾Í»á¿´µ½ÀàËÆÈçϵÄÐÅÏ¢£º
Username Port From Latest
root tty2 Tue Sep 3 08:32:27 +0800 2002
bin **Never logged in**
daemon **Never logged in**
adm **Never logged in**
lp **Never logged in**
sync **Never logged in**
shutdown **Never logged in**
halt **Never logged in**
mail **Never logged in**
news **Never logged in**
uucp **Never logged in**
operator **Never logged in**
games **Never logged in**
gopher **Never logged in**
ftp ftp UNIX Tue Sep 3 14:49:04 +0800 2002
nobody **Never logged in**
nscd **Never logged in**
mailnull **Never logged in**
ident **Never logged in**
rpc **Never logged in**
rpcuser **Never logged in**
xfs **Never logged in**
gdm **Never logged in**
postgres **Never logged in**
apache **Never logged in**
lzy tty2 Mon Jul 15 08:50:37 +0800 2002
suying tty2 Tue Sep 3 08:31:17 +0800 2002
¡¡¡¡ÏµÍ³ÕË»§ÖîÈçbin¡¢daemon¡¢adm¡¢uucp¡¢mailµÈ¾ö²»Ó¦¸ÃµÇ¼£¬Èç¹û·¢ÏÖÕâЩÕË»§ÒѾµÇ¼£¬¾Í˵Ã÷ϵͳ¿ÉÄÜÒѾ±»ÈëÇÖÁË¡£Èô·¢ÏּǼµÄʱ¼ä²»ÊÇÓû§ÉϴεǼµÄʱ¼ä£¬Ôò˵Ã÷¸ÃÓû§µÄÕË»§ÒѾйÃÜÁË¡£
¡¡¡¡/var/log/wtmp
¡¡¡¡¸ÃÈÕÖ¾ÎļþÓÀ¾Ã¼Ç¼ÿ¸öÓû§µÇ¼¡¢×¢Ïú¼°ÏµÍ³µÄÆô¶¯¡¢Í£»úµÄʼþ¡£Òò´ËËæ×ÅϵͳÕý³£ÔËÐÐʱ¼äµÄÔö¼Ó£¬¸ÃÎļþµÄ´óСҲ»áÔ½À´Ô½´ó£¬Ôö¼ÓµÄËÙ¶ÈÈ¡¾öÓÚϵͳÓû§µÇ¼µÄ´ÎÊý¡£¸ÃÈÕÖ¾Îļþ¿ÉÒÔÓÃÀ´²é¿´Óû§µÄµÇ¼¼Ç¼£¬lastÃüÁî¾Íͨ¹ý·ÃÎÊÕâ¸öÎļþ»ñµÃÕâЩÐÅÏ¢£¬²¢ÒÔ·´Ðò´ÓºóÏòǰÏÔʾÓû§µÄµÇ¼¼Ç¼£¬lastÒ²Äܸù¾ÝÓû§¡¢ÖÕ¶Ë tty»òʱ¼äÏÔʾÏàÓ¦µÄ¼Ç¼¡£
¡¡¡¡ÃüÁîlastÓÐÁ½¸ö¿ÉÑ¡²ÎÊý£º
¡¡¡¡last -u Óû§Ãû ÏÔʾÓû§ÉϴεǼµÄÇé¿ö¡£
¡¡¡¡last -t ÌìÊý ÏÔʾָ¶¨ÌìÊý֮ǰµÄÓû§µÇ¼Çé¿ö¡£
¡¡¡¡/var/run/utmp
¡¡¡¡¸ÃÈÕÖ¾Îļþ¼Ç¼Óйص±Ç°µÇ¼µÄÿ¸öÓû§µÄÐÅÏ¢¡£Òò´ËÕâ¸öÎļþ»áËæ×ÅÓû§µÇ¼ºÍ×¢Ïúϵͳ¶ø²»¶Ï±ä»¯£¬ËüÖ»±£Áôµ±Ê±Áª»úµÄÓû§¼Ç¼£¬²»»áΪÓû§±£ÁôÓÀ¾ÃµÄ¼Ç¼¡£ÏµÍ³ÖÐÐèÒª²éѯµ±Ç°Óû§×´Ì¬µÄ³ÌÐò£¬Èç who¡¢w¡¢users¡¢fingerµÈ¾ÍÐèÒª·ÃÎÊÕâ¸öÎļþ¡£¸ÃÈÕÖ¾Îļþ²¢²»ÄܰüÀ¨ËùÓо«È·µÄÐÅÏ¢£¬ÒòΪijЩͻ·¢´íÎó»áÖÕÖ¹Óû§µÇ¼»á»°£¬¶øÏµÍ³Ã»Óм°Ê±¸üРutmp¼Ç¼£¬Òò´Ë¸ÃÈÕÖ¾ÎļþµÄ¼Ç¼²»ÊǰٷÖÖ®°ÙÖµµÃÐÅÀµµÄ¡£
¡¡¡¡ÒÔÉÏÌá¼°µÄ3¸öÎļþ£¨/var/log/wtmp¡¢ /var/run/utmp¡¢/var/log/lastlog£©ÊÇÈÕÖ¾×ÓϵͳµÄ¹Ø¼üÎļþ£¬¶¼¼Ç¼ÁËÓû§µÇ¼µÄÇé¿ö¡£ÕâЩÎļþµÄËùÓмǼ¶¼°üº¬ÁËʱ¼ä´Á¡£ÕâЩÎļþÊǰ´¶þ½øÖƱ£´æµÄ£¬¹Ê²»ÄÜÓÃless¡¢catÖ®ÀàµÄÃüÁîÖ±½Ó²é¿´ÕâЩÎļþ£¬¶øÊÇÐèҪʹÓÃÏà¹ØÃüÁîͨ¹ýÕâЩÎļþ¶ø²é¿´¡£ÆäÖУ¬utmpºÍwtmpÎļþµÄÊý¾Ý½á¹¹ÊÇÒ»ÑùµÄ£¬¶ølastlogÎļþÔòʹÓÃÁíÍâµÄÊý¾Ý½á¹¹£¬¹ØÓÚËüÃǵľßÌåµÄÊý¾Ý½á¹¹¿ÉÒÔʹÓÃmanÃüÁî²éѯ¡£
ÿ´ÎÓÐÒ»¸öÓû§µÇ¼ʱ£¬login³ÌÐòÔÚÎļþlastlogÖв鿴Óû§µÄUID¡£Èç¹û´æÔÚ£¬Ôò°ÑÓû§ÉϴεǼ¡¢×¢Ïúʱ¼äºÍÖ÷»úÃûдµ½±ê×¼Êä³öÖУ¬È»ºó login³ÌÐòÔÚlastlogÖмǼеĵǼʱ¼ä£¬´ò¿ªutmpÎļþ²¢²åÈëÓû§µÄutmp¼Ç¼¡£¸Ã¼Ç¼һֱÓõ½Óû§µÇ¼Í˳öʱɾ³ý¡£utmpÎļþ±»¸÷ÖÖÃüÁîʹÓ㬰üÀ¨who¡¢w¡¢usersºÍfinger¡£
¡¡¡¡ÏÂÒ»²½£¬login³ÌÐò´ò¿ªÎļþwtmp¸½¼ÓÓû§µÄutmp¼Ç¼¡£µ±Óû§µÇ¼Í˳öʱ£¬¾ßÓиüÐÂʱ¼ä´ÁµÄͬһutmp¼Ç¼¸½¼Óµ½ÎļþÖС£wtmpÎļþ±»³ÌÐòlastʹÓá£
¡¡¡¡/var/log/xferlog
¡¡¡¡¸ÃÈÕÖ¾Îļþ¼Ç¼FTP»á»°£¬¿ÉÒÔÏÔʾ³öÓû§ÏòFTP·þÎñÆ÷»ò´Ó·þÎñÆ÷¿½±´ÁËʲôÎļþ¡£¸ÃÎļþ»áÏÔʾÓû§¿½±´µ½·þÎñÆ÷ÉϵÄÓÃÀ´ÈëÇÖ·þÎñÆ÷µÄ¶ñÒâ³ÌÐò£¬ÒÔ¼°¸ÃÓû§¿½±´ÁËÄÄЩÎļþ¹©ËûʹÓá£
¡¡¡¡¸ÃÎļþµÄ¸ñʽΪ£ºµÚÒ»¸öÓòÊÇÈÕÆÚºÍʱ¼ä£¬µÚ¶þ¸öÓòÊÇÏÂÔØÎļþËù»¨·ÑµÄÃëÊý¡¢Ô¶³ÌϵͳÃû³Æ¡¢Îļþ´óС¡¢±¾µØÂ·¾¶Ãû¡¢´«ÊäÀàÐÍ£¨a£ºASCII£¬b£º¶þ½øÖÆ£©¡¢ÓëѹËõÏà¹ØµÄ±êÖ¾»òtar£¬»ò"_"£¨Èç¹ûûÓÐѹËõµÄ»°£©¡¢´«Êä·½Ïò£¨Ïà¶ÔÓÚ·þÎñÆ÷¶øÑÔ£ºi´ú±í½ø£¬o´ú±í³ö£©¡¢·ÃÎÊģʽ£¨a£ºÄäÃû£¬g£ºÊäÈë¿ÚÁr£ºÕæÊµÓû§£©¡¢Óû§Ãû¡¢·þÎñÃû£¨Í¨³£ÊÇftp£©¡¢ÈÏÖ¤·½·¨£¨l£ºRFC931£¬»ò0£©£¬ÈÏÖ¤Óû§µÄID»ò"*"¡£ÏÂÃæÊǸÃÎļþµÄÒ»Ìõ¼Ç¼£º
Wed Sep 4 08:14:03 2002 1 UNIX 275531
/var/ftp/lib/libnss_files-2.2.2.so b _ o a -root@UNIX ftp 0 * c
/var/log/kernlog
¡¡¡¡¡¡RedHat LinuxĬÈÏûÓмǼ¸ÃÈÕÖ¾Îļþ¡£ÒªÆôÓøÃÈÕÖ¾Îļþ£¬±ØÐëÔÚ/etc/syslog.confÎļþÖÐÌí¼ÓÒ»ÐУºkern.* /var/log/kernlog ¡£ÕâÑù¾ÍÆôÓÃÁËÏò/var/log/kernlogÎļþÖмǼËùÓÐÄÚºËÏûÏ¢µÄ¹¦ÄÜ¡£¸ÃÎļþ¼Ç¼ÁËϵͳÆô¶¯Ê±¼ÓÔØÉ豸»òʹÓÃÉ豸µÄÇé¿ö¡£Ò»°ãÊÇÕý³£µÄ²Ù×÷£¬µ«Èç¹û¼Ç¼ÁËûÓÐÊÚȨµÄÓû§½øÐеÄÕâЩ²Ù×÷£¬¾ÍҪעÒ⣬ÒòΪÓпÉÄÜÕâ¾ÍÊǶñÒâÓû§µÄÐÐΪ¡£ÏÂÃæÊǸÃÎļþµÄ²¿·ÖÄÚÈÝ£º
Sep 5 09:38:42 UNIX kernel: NET4: Linux TCP/IP 1.0 for NET4.0
Sep 5 09:38:42 UNIX kernel: IP Protocols: ICMP, UDP, TCP, IGMP
Sep 5 09:38:42 UNIX kernel: IP: routing cache hash table of 512 buckets, 4Kbytes
Sep 5 09:38:43 UNIX kernel: TCP: Hash tables configured (established 4096 bind 4096)
Sep 5 09:38:43 UNIX kernel: Linux IP multicast router 0.06 plus PIM-SM
Sep 5 09:38:43 UNIX kernel: NET4: Unix domain sockets 1.0/SMP for Linux NET4.0.
Sep 5 09:38:44 UNIX kernel: EXT2-fs warning: checktime reached, running e2fsck is recommended
Sep 5 09:38:44 UNIX kernel: VFS: Mounted root (ext2 filesystem).
Sep 5 09:38:44 UNIX kernel: SCSI subsystem driver Revision: 1.00
/var/log/Xfree86.x.log
¡¡¡¡¸ÃÈÕÖ¾Îļþ¼Ç¼ÁËX-WindowÆô¶¯µÄÇé¿ö¡£ÁíÍ⣬³ýÁË/var/log/ Í⣬¶ñÒâÓû§Ò²¿ÉÄÜÔÚ±ðµÄµØ·½ÁôϺۼ££¬Ó¦¸Ã×¢ÒâÒÔϼ¸¸öµØ·½£ºroot ºÍÆäËûÕË»§µÄshellÀúÊ·Îļþ£»Óû§µÄ¸÷ÖÖÓÊÏ䣬Èç.sent¡¢mbox£¬ÒÔ¼°´æ·ÅÔÚ/var/spool/mail/ ºÍ /var/spool/mqueueÖеÄÓÊÏ䣻ÁÙʱÎļþ/tmp¡¢/usr/tmp¡¢/var/tmp£»Òþ²ØµÄĿ¼£»ÆäËû¶ñÒâÓû§´´½¨µÄÎļþ£¬Í¨³£ÊÇÒÔ "."¿ªÍ·µÄ¾ßÓÐÒþ²ØÊôÐÔµÄÎļþµÈ¡£
¡¡¡¡¾ßÌåÃüÁî
¡¡¡¡wtmpºÍutmpÎļþ¶¼ÊǶþ½øÖÆÎļþ£¬ËüÃDz»Äܱ»ÖîÈçtailÖ®ÀàµÄÃüÁî¼ôÌù»òºÏ²¢£¨Ê¹ÓÃcatÃüÁ¡£Óû§ÐèҪʹÓÃwho¡¢w¡¢users¡¢lastºÍacµÈÃüÁîÀ´Ê¹ÓÃÕâÁ½¸öÎļþ°üº¬µÄÐÅÏ¢¡£
¡¡¡¡whoÃüÁî
¡¡¡¡whoÃüÁî²éѯutmpÎļþ²¢±¨¸æµ±Ç°µÇ¼µÄÿ¸öÓû§¡£whoµÄĬÈÏÊä³ö°üÀ¨Óû§Ãû¡¢ÖÕ¶ËÀàÐÍ¡¢µÇ¼ÈÕÆÚ¼°Ô¶³ÌÖ÷»ú¡£ÀýÈ磬¼üÈëwhoÃüÁȻºó°´»Ø³µ¼ü£¬½«ÏÔʾÈçÏÂÄÚÈÝ£º
chyang pts/0 Aug 18 15:06
ynguo pts/2 Aug 18 15:32
ynguo pts/3 Aug 18 13:55
lewis pts/4 Aug 18 13:35
ynguo pts/7 Aug 18 14:12
ylou pts/8 Aug 18 14:15
¡¡¡¡Èç¹ûÖ¸Ã÷ÁËwtmpÎļþÃû£¬ÔòwhoÃüÁî²éѯËùÓÐÒÔǰµÄ¼Ç¼¡£ÃüÁîwho /var/log/wtmp½«±¨¸æ×Ô´ÓwtmpÎļþ´´½¨»òɾ¸ÄÒÔÀ´µÄÿһ´ÎµÇ¼¡£
¡¡¡¡wÃüÁî
¡¡¡¡wÃüÁî²éѯutmpÎļþ²¢ÏÔʾµ±Ç°ÏµÍ³ÖÐÿ¸öÓû§ºÍËüËùÔËÐеĽø³ÌÐÅÏ¢¡£ÀýÈ磬¼üÈëwÃüÁȻºó°´»Ø³µ¼ü£¬½«ÏÔʾÈçÏÂÄÚÈÝ£º
3:36pm up 1 day, 22:34, 6 users, load average: 0.23, 0.29, 0.27
USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT
chyang pts/0 202.38.68.242 3:06pm 2:04 0.08s 0.04s -bash
ynguo pts/2 202.38.79.47 3:32pm 0.00s 0.14s 0.05 w
lewis pts/3 202.38.64.233 1:55pm 30:39 0.27s 0.22s -bash
lewis pts/4 202.38.64.233 1:35pm 6.00s 4.03s 0.01s sh /home/users/
ynguo pts/7 simba.nic.ustc.e 2:12pm 0.00s 0.47s 0.24s telnet mail
ylou pts/8 202.38.64.235 2:15pm 1:09m 0.10s 0.04s -bash
¡¡¡¡usersÃüÁî
¡¡¡¡usersÃüÁîÓõ¥¶ÀµÄÒ»ÐдòÓ¡³öµ±Ç°µÇ¼µÄÓû§£¬Ã¿¸öÏÔʾµÄÓû§Ãû¶ÔÓ¦Ò»¸öµÇ¼»á»°¡£Èç¹ûÒ»¸öÓû§Óв»Ö¹Ò»¸öµÇ¼»á»°£¬ÄÇËûµÄÓû§Ãû½«ÏÔʾÏàͬµÄ´ÎÊý¡£ÀýÈ磬¼üÈëusersÃüÁȻºó°´»Ø³µ¼ü£¬½«ÏÔʾÈçÏÂÄÚÈÝ£º
¡¡¡¡chyang lewis lewis ylou ynguo ynguo
¡¡¡¡lastÃüÁî
¡¡¡¡lastÃüÁîÍù»ØËÑË÷wtmpÀ´ÏÔʾ×Ô´ÓÎļþµÚÒ»´Î´´½¨ÒÔÀ´µÇ¼¹ýµÄÓû§¡£ÀýÈ磺
chyang pts/9 202.38.68.242 Tue Aug 1 08:34 - 11:23 (02:49)
cfan pts/6 202.38.64.224 Tue Aug 1 08:33 - 08:48 (00:14)
chyang pts/4 202.38.68.242 Tue Aug 1 08:32 - 12:13 (03:40)
lewis pts/3 202.38.64.233 Tue Aug 1 08:06 - 11:09 (03:03)
lewis pts/2 202.38.64.233 Tue Aug 1 07:56 - 11:09 (03:12)
¡¡¡¡Èç¹ûÖ¸Ã÷ÁËÓû§£¬ÄÇôlastÖ»±¨¸æ¸ÃÓû§µÄ½üÆÚ»î¶¯£¬ÀýÈ磬¼üÈëlast ynguoÃüÁȻºó°´»Ø³µ¼ü£¬½«ÏÔʾÈçÏÂÄÚÈÝ£º
ynguo pts/4 simba.nic.ustc.e Fri Aug 4 16:50 - 08:20 (15:30)
ynguo pts/4 simba.nic.ustc.e Thu Aug 3 23:55 - 04:40 (04:44)
ynguo pts/11 simba.nic.ustc.e Thu Aug 3 20:45 - 22:02 (01:16)
ynguo pts/0 simba.nic.ustc.e Thu Aug 3 03:17 - 05:42 (02:25)
ynguo pts/0 simba.nic.ustc.e Wed Aug 2 01:04 - 03:16 1+02:12)
ynguo pts/0 simba.nic.ustc.e Wed Aug 2 00:43 - 00:54 (00:11)
ynguo pts/9 simba.nic.ustc.e Thu Aug 1 20:30 - 21:26 (00:55)
¡¡¡¡acÃüÁî
¡¡¡¡acÃüÁî¸ù¾Ýµ±Ç°µÄ/var/log/wtmpÎļþÖеĵǼ½øÈëºÍÍ˳öÀ´±¨¸æÓû§Á¬½ÓµÄʱ¼ä£¨Ð¡Ê±£©£¬Èç¹û²»Ê¹ÓñêÖ¾£¬Ôò±¨¸æ×ܵÄʱ¼ä¡£ÀýÈ磬¼üÈëacÃüÁȻºó°´»Ø³µ¼ü£¬½«ÏÔʾÈçÏÂÄÚÈÝ£º
¡¡¡¡total 5177.47
¼üÈëac -dÃüÁȻºó°´»Ø³µ¼ü£¬½«ÏÔʾÿÌìµÄ×ܵÄÁ¬½Óʱ¼ä£º
Aug 12 total 261.87
Aug 13 total 351.39
Aug 14 total 396.09
Aug 15 total 462.63
Aug 16 total 270.45
Aug 17 total 104.29
Today total 179.02
¡¡¡¡¼üÈëac -pÃüÁȻºó°´»Ø³µ¼ü£¬½«ÏÔʾÿ¸öÓû§µÄ×ܵÄÁ¬½Óʱ¼ä£º
ynguo 193.23
yucao 3.35
rong 133.40
hdai 10.52
zjzhu 52.87
zqzhou 13.14
liangliu 24.34
total 5178.24
¡¡¡¡lastlogÃüÁî
¡¡¡¡lastlogÎļþÔÚÿ´ÎÓÐÓû§µÇ¼ʱ±»²éѯ¡£¿ÉÒÔʹÓÃlastlogÃüÁî¼ì²éÄ³ÌØ¶¨Óû§ÉϴεǼµÄʱ¼ä£¬²¢¸ñʽ»¯Êä³öÉϴεǼÈÕÖ¾ /var/log/lastlogµÄÄÚÈÝ¡£Ëü¸ù¾ÝUIDÅÅÐòÏÔʾµÇ¼Ãû¡¢¶Ë¿ÚºÅ£¨tty£©ºÍÉϴεǼʱ¼ä¡£Èç¹ûÒ»¸öÓû§´ÓδµÇ¼¹ý£¬lastlogÏÔʾ **Never logged**¡£×¢ÒâÐèÒªÒÔrootÉí·ÝÔËÐиÃÃüÁÀýÈ磺
rong 5 202.38.64.187 Fri Aug 18 15:57:01 +0800 2000
dbb **Never logged in**
xinchen **Never logged in**
pb9511 **Never logged in**
xchen 0 202.38.64.190 Sun Aug 13 10:01:22 +0800 2000
ÁíÍ⣬¿É¼ÓһЩ²ÎÊý£¬ÀýÈ磬"last -u 102"ÃüÁ±¨¸æUIDΪ102µÄÓû§£»"last -t 7"ÃüÁî±íʾÏÞÖÆÎªÉÏÒ»Öܵı¨¸æ¡£
¡¡¡¡½ø³Ìͳ¼Æ
¡¡¡¡UNIX¿ÉÒÔ¸ú×Ùÿ¸öÓû§ÔËÐеÄÿÌõÃüÁÈç¹ûÏëÖªµÀ×òÍíŪÂÒÁËÄÄÐ©ÖØÒªµÄÎļþ£¬½ø³Ìͳ¼Æ×Óϵͳ¿ÉÒÔ¸æËßÄã¡£Ëü»¹¶Ô¸ú×ÙÒ»¸öÇÖÈëÕßÓаïÖú¡£ÓëÁ¬½Óʱ¼äÈÕÖ¾²»Í¬£¬½ø³Ìͳ¼Æ×ÓϵͳĬÈϲ»¼¤»î£¬Ëü±ØÐëÆô¶¯¡£ÔÚLinuxϵͳÖÐÆô¶¯½ø³Ìͳ¼ÆÊ¹ÓÃacctonÃüÁ±ØÐëÓÃrootÉí·ÝÀ´ÔËÐС£acctonÃüÁîµÄÐÎʽΪ£ºaccton file£¬file±ØÐëÊÂÏÈ´æÔÚ¡£ÏÈʹÓÃtouchÃüÁî´´½¨pacctÎļþ£ºtouch /var/log/pacct£¬È»ºóÔËÐÐaccton£ºaccton /var/log/pacct¡£Ò»µ©accton±»¼¤»î£¬¾Í¿ÉÒÔʹÓÃlastcommÃüÁî¼à²âϵͳÖÐÈκÎʱºòÖ´ÐеÄÃüÁî¡£ÈôÒª¹Ø±Õͳ¼Æ£¬¿ÉÒÔʹÓò»´øÈκβÎÊýµÄacctonÃüÁî¡£
¡¡¡¡lastcommÃüÁ¸æÒÔǰִÐеÄÎļþ¡£²»´ø²ÎÊýʱ£¬lastcommÃüÁîÏÔʾµ±Ç°Í³¼ÆÎļþÉúÃüÖÜÆÚÄڼǼµÄËùÓÐÃüÁîµÄÓйØÐÅÏ¢¡£°üÀ¨ÃüÁîÃû¡¢Óû§¡¢tty¡¢ÃüÁ·ÑµÄCPUʱ¼äºÍÒ»¸öʱ¼ä´Á¡£Èç¹ûϵͳÓÐÐí¶àÓû§£¬ÊäÈëÔò¿ÉÄܺܳ¤¡£¿´ÏÂÃæµÄÀý×Ó£º
crond F root ?? 0.00 secs Sun Aug 20 00:16
promisc_check.s S root ?? 0.04 secs Sun Aug 20 00:16
promisc_check root ?? 0.01 secs Sun Aug 20 00:16
grep root ?? 0.02 secs Sun Aug 20 00:16
tail root ?? 0.01 secs Sun Aug 20 00:16
sh root ?? 0.01 secs Sun Aug 20 00:15
ping S root ?? 0.01 secs Sun Aug 20 00:15
ping6.pl F root ?? 0.01 secs Sun Aug 20 00:15
sh root ?? 0.01 secs Sun Aug 20 00:15
ping S root ?? 0.02 secs Sun Aug 20 00:15
ping6.pl F root ?? 0.02 secs Sun Aug 20 00:15
sh root ?? 0.02 secs Sun Aug 20 00:15
ping S root ?? 0.00 secs Sun Aug 20 00:15
ping6.pl F root ?? 0.01 secs Sun Aug 20 00:15
sh root ?? 0.01 secs Sun Aug 20 00:15
ping S root ?? 0.01 secs Sun Aug 20 00:15
sh root ?? 0.02 secs Sun Aug 20 00:15
ping S root ?? 1.34 secs Sun Aug 20 00:15
locate root ttyp0 1.34 secs Sun Aug 20 00:15
accton S root ttyp0 0.00 secs Sun Aug 20 00:15
¡¡¡¡½ø³Ìͳ¼ÆµÄÒ»¸öÎÊÌâÊÇpacctÎļþ¿ÉÄÜÔö³¤µÃÊ®·ÖѸËÙ¡£ÕâʱÐèÒª½»»¥Ê½µØ»ò¾¹ýcron»úÖÆÔËÐÐsaÃüÁîÀ´±£Ö¤ÈÕÖ¾Êý¾ÝÔÚϵͳ¿ØÖÆÄÚ¡£saÃüÁ¸æ¡¢ÇåÀí²¢Î¬»¤½ø³Ìͳ¼ÆÎļþ¡£ËüÄܰÑ/var/log/pacctÖеÄÐÅϢѹËõµ½ÕªÒªÎļþ/var/log/savacctºÍ /var/log/usracctÖС£ÕâЩժҪ°üº¬°´ÃüÁîÃûºÍÓû§Ãû·ÖÀàµÄϵͳͳ¼ÆÊý¾Ý¡£ÔÚĬÈÏÇé¿öÏÂsaÏȶÁËüÃÇ£¬È»ºó¶ÁpacctÎļþ£¬Ê¹±¨¸æÄܰüº¬ËùÓеĿÉÓÃÐÅÏ¢¡£saµÄÊä³öÓÐÏÂÃæÒ»Ð©±ê¼ÇÏî¡£
avio£ºÃ¿´ÎÖ´ÐÐµÄÆ½¾ùI/O²Ù×÷´ÎÊý¡£
cp£ºÓû§ºÍϵͳʱ¼ä×ܺͣ¬ÒÔ·ÖÖӼơ£
cpu£ººÍcpÒ»Ñù¡£
k£ºÄÚºËʹÓÃµÄÆ½¾ùCPUʱ¼ä£¬ÒÔ1kΪµ¥Î»¡£
k*sec£ºCPU´æ´¢ÍêÕûÐÔ£¬ÒÔ1k-coreÃëΪµ¥Î»¡£
re£ºÊµÊ±Ê±¼ä£¬ÒÔ·ÖÖӼơ£
s£ºÏµÍ³Ê±¼ä£¬ÒÔ·ÖÖӼơ£
tio£ºI/O²Ù×÷µÄ×ÜÊý¡£
u£ºÓû§Ê±¼ä£¬ÒÔ·ÖÖӼơ£
ÀýÈ磺
842 173.26re 4.30cp 0avio 358k
2 10.98re 4.06cp 0avio 299k find
9 24.80re 0.05cp 0avio 291k ***other
105 30.44re 0.03cp 0avio 302k ping
104 30.55re 0.03cp 0avio 394k sh
162 0.11re 0.03cp 0avio 413k security.sh*
154 0.03re 0.02cp 0avio 273k ls
56 31.61re 0.02cp 0avio 823k ping6.pl*
2 3.23re 0.02cp 0avio 822k ping6.pl
35 0.02re 0.01cp 0avio 257k md5sum
97 0.02re 0.01cp 0avio 263k initlog
12 0.19re 0.01cp 0avio 399k promisc_check.s
15 0.09re 0.00cp 0avio 288k grep
11 0.08re 0.00cp 0avio 332k awk
Óû§»¹¿ÉÒÔ¸ù¾ÝÓû§¶ø²»ÊÇÃüÁîÀ´Ìṩһ¸öÕªÒª±¨¸æ¡£ÀýÈ磬¼üÈëÃüÁî"sa -m"£¬½«ÏÔʾÈçÏÂÄÚÈÝ£º
885 173.28re 4.31cp 0avk
root 879 173.23re 4.31cp 0avk
alias 3 0.05re 0.00cp 0avk
qmailp 3 0.01re 0.00cp 0avk
¡¡¡¡syslogÉ豸
¡¡¡¡syslogÒѱ»Ðí¶àÈÕÖ¾º¯Êý²ÉÄÉ£¬ËüÓÃÔÚÐí¶à±£»¤´ëÊ©ÖС£ÈκγÌÐò¶¼¿ÉÒÔͨ¹ýsyslog ¼Ç¼Ê¼þ¡£syslog¿ÉÒԼǼϵͳʼþ£¬¿ÉÒÔдµ½Ò»¸öÎļþ»òÉ豸ÖУ¬»ò¸øÓû§·¢ËÍÒ»¸öÐÅÏ¢¡£ËüÄܼǼ±¾µØÊ¼þ»òͨ¹ýÍøÂç¼Ç¼ÁíÒ»¸öÖ÷»úÉϵÄʼþ¡£
¡¡¡¡syslogÉ豸ÒÀ¾ÝÁ½¸öÖØÒªµÄÎļþ£º/etc/syslogd£¨ÊØ»¤½ø³Ì£©ºÍ /etc/syslog.confÅäÖÃÎļþ¡£Ï°¹ßÉÏ£¬¶àÊýsyslog ÐÅÏ¢±»Ð´µ½/var/adm»ò/var/logĿ¼ÏµÄÐÅÏ¢ÎļþÖУ¨messages.*£©¡£Ò»¸öµäÐ͵Äsyslog¼Ç¼°üÀ¨Éú³É³ÌÐòµÄÃû×ÖºÍÒ»¸öÎı¾ÐÅÏ¢¡£Ëü»¹°üÀ¨Ò»¸öÉ豸ºÍÒ»¸öÓÅÏȼ¶·¶Î§£¨µ«²»ÔÚÈÕÖ¾ÖгöÏÖ£©¡£
ÿ¸ösyslogÏûÏ¢±»¸³ÓèÏÂÃæµÄÖ÷ÒªÉ豸֮һ£º
LOG_AUTH£ºÈÏ֤ϵͳlogin¡¢su¡¢gettyµÈ¡£
LOG_AUTHPRIV£ºÍ¬LOG_AUTH£¬µ«Ö»µÇ¼µ½ËùÑ¡ÔñµÄµ¥¸öÓû§¿É¶ÁµÄÎļþÖС£
LOG_CRON£ºcronÊØ»¤½ø³Ì¡£
LOG_DAEMON£ºÆäËûÏµÍ³ÊØ»¤½ø³Ì£¬Èçrouted¡£
LOG_FTP£ºÎļþ´«ÊäÐÒéftpd¡¢tftpd¡£
LOG_KERN£ºÄں˲úÉúµÄÏûÏ¢¡£
LOG_LPR£ºÏµÍ³´òÓ¡»ú»º³å³Ølpr¡¢lpd¡£
LOG_MAIL£ºµç×ÓÓʼþϵͳ¡£
LOG_NEWS£ºÍøÂçÐÂÎÅϵͳ¡£
LOG_SYSLOG£ºÓÉsyslogd£¨8£©²úÉúµÄÄÚ²¿ÏûÏ¢¡£
LOG_USER£ºËæ»úÓû§½ø³Ì²úÉúµÄÏûÏ¢¡£
LOG_UUCP£ºUUCP×Óϵͳ¡£
LOG_LOCAL0~LOG_LOCAL7£ºÎª±¾µØÊ¹Óñ£Áô¡£
syslogΪÿ¸öʼþ¸³Ó輸¸ö²»Í¬µÄÓÅÏȼ¶£º
LOG_EMERG£º½ô¼±Çé¿ö¡£
LOG_ALERT£ºÓ¦¸Ã±»Á¢¼´¸ÄÕýµÄÎÊÌ⣬ÈçϵͳÊý¾Ý¿â±»ÆÆ»µ¡£
LOG_CRIT£ºÖØÒªÇé¿ö£¬ÈçÓ²ÅÌ´íÎó¡£
LOG_ERR£º´íÎó¡£
LOG_WARNING£º¾¯¸æÐÅÏ¢¡£
LOG_NOTICE£º²»ÊÇ´íÎóÇé¿ö£¬µ«ÊÇ¿ÉÄÜÐèÒª´¦Àí¡£
LOG_INFO£ºÇ鱨ÐÅÏ¢¡£
LOG_DEBUG£º°üº¬Ç鱨µÄÐÅÏ¢£¬Í¨³£Ö»ÔÚµ÷ÊÔÒ»¸ö³ÌÐòʱʹÓá£
¡¡¡¡syslog.confÎļþÖ¸Ã÷syslogd³ÌÐò¼Ç¼ÈÕÖ¾µÄÐÐΪ£¬¸Ã³ÌÐòÔÚÆô¶¯Ê±²éѯÅäÖÃÎļþ¡£¸ÃÎļþÓɲ»Í¬³ÌÐò»òÏûÏ¢·ÖÀàµÄµ¥¸öÌõÄ¿×é³É£¬Ã¿¸öÕ¼Ò»ÐС£¶ÔÿÀàÏûÏ¢Ìṩһ¸öÑ¡ÔñÓòºÍÒ»¸ö¶¯×÷Óò¡£ÕâЩÓòÓÉtab·û¸ô¿ª£ºÑ¡ÔñÓòÖ¸Ã÷ÏûÏ¢µÄÀàÐͺÍÓÅÏȼ¶£»¶¯×÷ÓòÖ¸Ã÷syslogd½ÓÊÕµ½Ò»¸öÓëÑ¡Ôñ±ê×¼ÏàÆ¥ÅäµÄÏûϢʱËùÖ´Ðе͝×÷¡£Ã¿¸öÑ¡ÏîÊÇÓÉÉ豸ºÍÓÅÏȼ¶×é³ÉµÄ¡£µ±Ö¸Ã÷Ò»¸öÓÅÏȼ¶Ê±£¬ syslogd½«¼Ç¼һ¸öÓµÓÐÏàͬ»ò¸ü¸ßÓÅÏȼ¶µÄÏûÏ¢¡£ËùÒÔÈç¹ûÖ¸Ã÷ "crit"£¬ÄÇËùÓбêΪcrit¡¢alertºÍemergµÄÏûÏ¢½«±»¼Ç¼¡£Ã¿ÐеÄÐж¯ÓòÖ¸Ã÷µ±Ñ¡ÔñÓòÑ¡ÔñÁËÒ»¸ö¸ø¶¨ÏûÏ¢ºóÓ¦¸Ã°ÑËü·¢Ë͵½ÄĶù¡£ÀýÈ磬Èç¹ûÏë°ÑËùÓÐÓʼþÏûÏ¢¼Ç¼µ½Ò»¸öÎļþÖУ¬ÈçÏÂËùʾ£º
#Log all the mail messages in one place
mail.* /var/log/maillog
¡¡¡¡ÆäËûÉ豸ҲÓÐ×Ô¼ºµÄÈÕÖ¾¡£UUCPºÍnewsÉ豸ÄܲúÉúÐí¶àÍⲿÏûÏ¢¡£Ëü°ÑÕâЩÏûÏ¢´æµ½×Ô¼ºµÄÈÕÖ¾£¨/var/log/spooler£©Öв¢°Ñ¼¶±ðÏÞΪ"err"»ò¸ü¸ß¡£ÀýÈ磺
# Save mail and news errors of level err and higher in aspecial file.
uucp,news.crit /var/log/spooler
¡¡¡¡µ±Ò»¸ö½ô¼±ÏûÏ¢µ½À´Ê±£¬¿ÉÄÜÏëÈÃËùÓеÄÓû§¶¼µÃµ½£¬Ò²¿ÉÄÜÏëÈÃ×Ô¼ºµÄÈÕÖ¾½ÓÊÕ²¢±£´æ£º
#Everybody gets emergency messages£¬ plus log them on anther machine
*.emerg *
*.emerg @linuxaid.com.cn
¡¡¡¡alertÏûÏ¢Ó¦¸Ãдµ½rootºÍtigerµÄ¸öÈËÕ˺ÅÖУº
#Root and Tiger get alert and higher messages
*.alert root,tiger
¡¡¡¡ÓÐʱsyslogd½«²úÉú´óÁ¿µÄÏûÏ¢¡£ÀýÈ磬Äںˣ¨"kernel"É豸£©¿ÉÄܺÜÈß³¤¡£Óû§¿ÉÄÜÏë°ÑÄÚºËÏûÏ¢¼Ç¼µ½/dev/consoleÖС£ÏÂÃæµÄÀý×Ó±íÃ÷ÄÚºËÈÕÖ¾¼Ç¼±»×¢Ê͵ôÁË£º
#Log all kernel messages to the console
#Logging much else clutters up the screen
#kern.* /dev/console
¡¡¡¡Óû§¿ÉÒÔÔÚÒ»ÐÐÖÐÖ¸Ã÷ËùÓеÄÉ豸¡£ÏÂÃæµÄÀý×Ó°Ñinfo»ò¸ü¸ß¼¶±ðµÄÏûÏ¢Ë͵½/var/log/messages£¬³ýÁËmailÒÔÍâ¡£¼¶±ð"none"½ûÖ¹Ò»¸öÉ豸£º
#Log anything£¨except mail£©of level info or higher
#Don't log private authentication messages!
*.info:mail.none;authpriv.none /var/log/messages
¡¡¡¡ÔÚÓÐЩÇé¿öÏ£¬¿ÉÒÔ°ÑÈÕÖ¾Ë͵½´òÓ¡»ú£¬ÕâÑùÍøÂçÈëÇÖÕßÔõôÐÞ¸ÄÈÕÖ¾¾Í¶¼Ã»ÓÐÓÃÁË¡£Í¨³£Òª¹ã·º¼Ç¼ÈÕÖ¾¡£syslogÉ豸ÊÇÒ»¸ö¹¥»÷ÕßµÄÏÔÖøÄ¿±ê¡£Ò»¸öΪÆäËûÖ÷»úά»¤ÈÕÖ¾µÄϵͳ¶ÔÓÚ·À·¶·þÎñÆ÷¹¥»÷ÌØ±ð´àÈõ£¬Òò´ËÒªÌØ±ð×¢Òâ¡£
ÓиöСÃüÁîloggerΪsyslog£¨3£©ÏµÍ³ÈÕÖ¾ÎļþÌṩһ¸öshellÃüÁî½Ó¿Ú£¬Ê¹Óû§ÄÜ´´½¨ÈÕÖ¾ÎļþÖеÄÌõÄ¿¡£
¡¡¡¡Ó÷¨£ºlogger¡¡
¡¡¡¡ÀýÈ磺logger This is a test£¡
¡¡¡¡Ëü½«²úÉúÒ»¸öÈçϵÄsyslog¼Ç¼£ºAug 19 22:22:34 tiger: This is a test!
¡¡¡¡×¢Ò⣬²»ÒªÍêÈ«ÏàÐÅÈÕÖ¾£¬ÒòΪ¹¥»÷ÕߺÜÈÝÒ×ÐÞ¸ÄËüµÄ¡£
¡¡¡¡³ÌÐòÈÕÖ¾ÓëÆäËû
¡¡¡¡Ðí¶à³ÌÐòͨ¹ýά»¤ÈÕÖ¾À´·´Ó³ÏµÍ³µÄ°²È«×´Ì¬¡£suÃüÁîÔÊÐíÓû§»ñµÃÁíÒ»¸öÓû§µÄȨÏÞ£¬ËùÒÔËüµÄ°²È«ºÜÖØÒª£¬ËüµÄÈÕÖ¾ÎļþΪsulog¡£Í¬ÑùµÄ»¹ÓÐ sudolog¡£ÁíÍ⣬ÏñApacheÓÐÁ½¸öÈÕÖ¾£ºaccess_logºÍerror_log¡£»¹ÓÐһЩ³£Óõ½µÄÆäËûÈÕÖ¾¹¤¾ß£¬ÎÒÃǾͲ»Ò»Ò»²ûÊöÁË¡£
wise-man ÓÚ 2006-11-16 09:49:47·¢±í:
лл½éÉÜ£¬ÊÕ²ØÏÈ¡£