čtvrtek 22. května 2008
Audit report - script to format output (similar to Solaris audit)
If you do audit user actions (commands) on a Linux box via auditd, then following script could help you to go through the logged data. It will show you user actions in Linux system in human-readable form.
The example below shows the common user "chick" who switched to root and then created and deleted file "somefile" in the /etc/directory. As you can see, the auid is persistent across su command, so the user is still seen as "chick" under authentic auid even he/she switched to root to perform the touch and remove on file.
time="02/29/2008 09:21:31" cwd=/root syscall=execve success=yes exit=0 pid=17695 auid=chick gid=root euid=root suid=root fsuid=root egid=root sgid=root comm=touch exe=/bin/touch argv[0]="touch" argv[1]="/etc/somefile"
time="02/29/2008 09:21:32" cwd=/root syscall=execve success=yes exit=0 pid=17697 auid=chick gid=root euid=root suid=root fsuid=root egid=root sgid=root comm=rm exe=/bin/rm argv[0]="rm" argv[1]="-i" argv[2]="/etc/somefile"
Here is the script:
The example below shows the common user "chick" who switched to root and then created and deleted file "somefile" in the /etc/directory. As you can see, the auid is persistent across su command, so the user is still seen as "chick" under authentic auid even he/she switched to root to perform the touch and remove on file.
# audit_report /var/log/audit/audit.log | grep somefile
time="02/29/2008 09:21:31" cwd=/root syscall=execve success=yes exit=0 pid=17695 auid=chick gid=root euid=root suid=root fsuid=root egid=root sgid=root comm=touch exe=/bin/touch argv[0]="touch" argv[1]="/etc/somefile"
time="02/29/2008 09:21:32" cwd=/root syscall=execve success=yes exit=0 pid=17697 auid=chick gid=root euid=root suid=root fsuid=root egid=root sgid=root comm=rm exe=/bin/rm argv[0]="rm" argv[1]="-i" argv[2]="/etc/somefile"
Here is the script:
#!/bin/bash
# @(#) audit_report 1.1@(#) 25/05/07
# ---------------------------------------------------
#
# audit_report: prints out specified input audit file
# archieved or actual log in sol format
#
# warning: this parser works with audit-1.0.14-1.EL4
# future version of the autitd may have
# different output field naming or order
# ---------------------------------------------------
FSPEC="${1}"
TMP_FILE="/tmp/audit_log_tmp"
# check valid argument
if [ "$FSPEC" = "" ]; then
echo "parameters: audit_report input_file" 1>&2
exit
fi
# check if file exists
if [ ! -f "$FSPEC" ]; then
echo "error: can't access $FSPEC" 1>&2
exit
fi
# check, if $TMPFILE exists
if [ -f ${TMP_FILE} ]; then
echo "info: ${TMP_FILE} exists, someone can be using audit_report or process terminated" 1>&2
echo -n "do you want me to delete the file to proceed? (y/n): " 1>&2
read INPUT
if [ "${INPUT}" = "y" ]; then
/bin/rm ${TMP_FILE}
else
exit
fi
fi
# ausearch path
if [ -x /sbin/ausearch ]; then
AUSEARCH=/sbin/ausearch
else
AUSEARCH=ausearch
fi
# sed path
if [ -x /bin/sed ]; then
SED=/bin/sed
else
SED=sed
fi
# extract filename, remove path
FNAME="`basename $FSPEC`"
# check if zipped
GZIP=`echo $FNAME | egrep ".gz$"`
if [ "$GZIP" = "" ]; then
if [ "${FNAME}" = "audit.log" ]; then
/bin/cp ${FSPEC} ${TMP_FILE}
SRCFILE=${TMP_FILE}
else
SRCFILE=${FSPEC}
fi
else
echo "info: unzipping: ${FSPEC}"
cp ${FSPEC} ${TMP_FILE}.gz
gunzip ${TMP_FILE}.gz
SRCFILE=${TMP_FILE}
fi
# parse plain text audit file
# 1) add text fields instead of numbers where possible
# 2) one record per line
# loop - processing audit file to sol format
${AUSEARCH} -i -if ${SRCFILE} | while read SHORT_LINE
do
if [ "${SHORT_LINE}" != "----" ]; then
SYMBOL=`echo ${SHORT_LINE} | tr '= ' ' ' | awk '{ print $2 }'`
case ${SYMBOL} in
PATH)
;;
CWD)
# $2 - date part
# $3 - time part
# $5 - actual working dir, cwd
# put the date-time into quotes
TIME_STAMP=`echo ${SHORT_LINE} | tr '(' '.'`
TIME_STAMP=`echo ${TIME_STAMP} | awk -F"." '{ print $2 }'`
TIME_STAMP="time=\"${TIME_STAMP}\" "
LINE1=`echo ${SHORT_LINE} | \
awk '{ print $5 }'`
;;
EXECVE)
# $ 5 - argv[0]
# $ 6 - argv[1]
# $ 7 - argv[2]
# $ 8 - argv[3]
LINE3=`echo ${SHORT_LINE} | \
awk '{ print $5 " " $6 " " $7 " " $8 }'`
;;
SYSCALL)
# $ 6 - syscall
# $ 7 - success
# $ 8 - exit code
# $ 9 to 12 - pointers
# $13 - nr of args
# $14 - pid
# $15 - auid
# $16 - uid
# $17 - gid
# $18 - euid
# $19 - suid
# $20 - fsuid
# $21 - egid
# $22 - sgid
# $23 - fsgid
# $24 - command
# $25 - executable
LINE2=`echo ${SHORT_LINE} | \
awk '{ print $6 " " $7 " " $8 " " $14 " " $15 " " $17 " " $18 " " $19 " " $20 " " $21 " " $22 " "
$24 " " $25 }'`
;;
*)
;;
esac
else
echo -n "${TIME_STAMP} "
echo -n "${LINE1} "
echo -n "${LINE2} "
echo -n "${LINE3} "
echo
fi
done
# cleanup temporary file
if [ "${SRCFILE}" = "${TMP_FILE}" ]; then
/bin/rm ${TMP_FILE}
fi
# end
Determine processor type and speed (Solaris)
# psrinfo -v
Status of virtual processor 0 as of: 12/28/2007 09:41:56
on-line since 12/14/2007 13:04:10.
The sparcv9 processor operates at 1062 MHz,
and has a sparcv9 floating point processor.
Status of virtual processor 1 as of: 12/28/2007 09:41:56
on-line since 12/14/2007 13:04:10.
The sparcv9 processor operates at 1062 MHz,
and has a sparcv9 floating point processor.
Status of virtual processor 2 as of: 12/28/2007 09:41:56
on-line since 12/14/2007 13:04:10.
The sparcv9 processor operates at 1062 MHz,
and has a sparcv9 floating point processor.
Status of virtual processor 3 as of: 12/28/2007 09:41:56
on-line since 12/14/2007 13:03:45.
The sparcv9 processor operates at 1062 MHz,
and has a sparcv9 floating point processor.
Determine if the system is running in 32-bit or 64-bit mode (Solaris)
# isainfo -v
64-bit sparcv9 applications
vis2 vis
32-bit sparc applications
vis2 vis v8plus div32 mul32
Intel with 32bit version
# isainfo -v
32-bit i386 applications
sse sse2 sse fxsr mmx cmov sep cx8 tsc fpu
Sun cluster commands (3.2)
Setup commands
scinstall
install primary or next cluster node
clsetup
menu driven re-configuration utility
cluster
interactive command shell for cluster management
cluster status
status for all cluster components
cluster list-cmds
lists available commands
Quorum device commands
clq status
quorum votes summary, quorum votes by node/device status
clq list
list all the quorum elements (devices/hosts)
clq show
cluster nodes (with reservation keys) and quorum device/s path/s
SCSI commands and devices
/usr/cluster/lib/sc/scsi -c inkeys -d /dev/did/rdsk/device
shows reservation keys (all possible/available keys for device)
/usr/cluster/lib/sc/scsi -c inresv -d /dev/did/rdsk/device
shows active reservation (server accessing quorum device)
cldev
Administer Sun Cluster device instances
cldevice status
status of disk devices
Server node commands
clnode list
list servers in cluster
clnode show-rev
cluster software version
clnode status
shows status of the clustered servers (Online/Offline)
Heart-beat links
clintr
HB endpoint status
scstat -W
Cluster Transport Paths
Cluster resource commands
clrs status
(rs as for for resource) resource status
clrs show -v resouirce-name
shows values of all resource attributes for given resource-name (as Type/Group/Class)
clrs show -p NetIflist resource-name
shows NetIflist resource attribute value
clrs set -p netiflist=primary@1,primary@3,primary@4 resource-name
set attrinute value(s)
Resource group commands
clrg status
(rg as for resource group) resource group status
clrg manage resource-group
put resource group under cluster management
clrg online resource-group
bring it online
clrg add-node -n hostnameX resource-group
allow service/resource-group to migrate/failover even to hostnameX
clrg switch -n hostnameX resource-group
fail-over resource group to hostnameX
Resource types
clrt list
(rc as for resource types: SUNW.SharedAddress, SUNW.LogicalHostname ...) prints registered SUNW resource types
Checksum
/usr/cluster/lib/sc/ccradm -i infrastructure
compute new checksum after changing cluster config in /etc/cluster/ccr/infrastructure file
Jak v LINUXu změnit nastavení jazyka (LOCALE)
# vi /etc/sysconfig/i18n
eng:
LANG="en_US.UTF-8"
czech:
LANG="cs_CZ.UTF-8"
eng:
LANG="en_US.UTF-8"
czech:
LANG="cs_CZ.UTF-8"
Přihlásit se k odběru:
Příspěvky (Atom)
Archiv blogu
-
▼
2008
(18)
-
▼
května
(18)
- SSL LDAP Search
- Vista & XP Profile Directory Locations
- Auditd configuration on Linux to track activity of...
- RedHat/CentosOS version 4 or 5 check in bash
- Simple use of test command
- ILOM - Quick
- Simple Solaris iptraf like script
- Allow vsftpd to use passive mode
- Disable yum kernel updates on CentOS Linux
- Audit report - script to format output (similar to...
- Determine processor type and speed (Solaris)
- Determine if the system is running in 32-bit or 64...
- Veritas Cluster - Links
- Sun cluster commands (3.2)
- Jak v LINUXu změnit nastavení jazyka (LOCALE)
- Poznámky k Nagiosu (dokumentace)
- Solaris 10 a příkazy CHOWN/CHGRP
- Problémy aktualizací Windows XP po instalaci SP3
-
▼
května
(18)