From owner-freebsd-questions Wed Jun 4 20:16:35 1997 Return-Path: Received: (from root@localhost) by hub.freebsd.org (8.8.5/8.8.5) id UAA03420 for questions-outgoing; Wed, 4 Jun 1997 20:16:35 -0700 (PDT) Received: from tok.qiv.com ([204.214.141.211]) by hub.freebsd.org (8.8.5/8.8.5) with ESMTP id UAA03405 for ; Wed, 4 Jun 1997 20:16:33 -0700 (PDT) Received: (from uucp@localhost) by tok.qiv.com (8.8.5/8.8.5) with UUCP id WAA00726; Wed, 4 Jun 1997 22:14:15 -0500 (CDT) Received: from localhost (jdn@localhost) by acp.qiv.com (8.8.5/8.8.5) with SMTP id WAA00829; Wed, 4 Jun 1997 22:10:57 -0500 (CDT) X-Authentication-Warning: acp.qiv.com: jdn owned process doing -bs Date: Wed, 4 Jun 1997 22:10:57 -0500 (CDT) From: "Jay D. Nelson" To: bsampley@best.com cc: questions@FreeBSD.ORG Subject: Re: logging all logins In-Reply-To: Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: owner-questions@FreeBSD.ORG X-Loop: FreeBSD.org Precedence: bulk On Wed, 4 Jun 1997 bsampley@best.com wrote: ->Greetings, -> ->If I want to log all logins (at the console, telnet and ftp, including You could add: auth.* /dev/console to /etc/syslog.conf ->failures) to my FBSD system, what's the best way to do this? How ->difficult would it be to create an automated script to rename and compress That's what /etc/newsyslog.conf does for you. ->the logfile everyday? Is it possible to log authorized logins to 1 file ->and failures to another file? For that I don't know unless failures log at a different level than successes. -- Jay -> ->Has anybody done something like this, if so, can you please email me your ->script/suggestions. -> ->Thanks in advance. -> ->Burton Sampley -> ->