Linux permissions centralized management and behavior log audits

Source: Internet
Author: User
Tags stdin rsyslog


Useradd-g-u-c-s-d-g-m-D Change default properties

Userdel-r

Usermod

Groupadd

Groupdel

passwd--stdin

Chage Modifying the-l-e of password expiration properties

Su-C returns after execution

sudo normal user can have root privileges

Visudo

Newgrp

Id

W who last Lastlog whoami finger

Server User Rights Management transformation Scheme and implementation project

Minimize: Install software permissions (directory directory files) User Rights program run permissions

Ask questions, write good plans, discuss feasibility, finalize plans, implement deployment, summarize maintenance

Solution Planning Documentation

Attitude

Persuade others

Feasibility Summary Submission Review

Process Normalization Management

For user in AAA BBB CCC

Do

Useradd $user

echo "123123" | passwd--stdin $user >/dev/null 2>&1

Done

Sudo

650) this.width=650; "src="/e/u261/themes/default/images/spacer.gif "style=" Background:url ("/e/u261/lang/zh-cn/ Images/localimage.png ") no-repeat center;border:1px solid #ddd;" alt= "Spacer.gif"/>

Alias capitalization command full path more than one line of \ Line wrapping

Sudo-l

Training documentation

White list Wit

Absolute path Letter capitalization, alias type all= () default root (All) for all users

% User group! Command Forbidden Command

Log Audit Project

The suo command log records the operation of the sudo command

# Rpm-aq | Egrep "Sudo|rsyslog"

Sudo-1.8.6p3-12.el6.x86_64

Rsyslog-5.8.10-8.el6.x86_64

# echo "Defaults Logfile=/var/log/sudo.log" >>/etc/sudoers

[Email protected] ~]# visudo-c

/etc/sudoers: Parse correctly

# echo "Local2.debug/var/log/sudo.log" >>/etc/rsyslog.conf

#/etc/init.d/rsyslog Restart

# Ll/var/log/sudo.log

-RW-------1 root root 0 March 20:45/var/log/sudo.log

Record sudo

Rsync+inotify Rsyslog

Log Collection Solution

scribe Flume Storm Kibanan Logstash


This article is from the "what-all" blog, please be sure to keep this source http://hequan.blog.51cto.com/5701886/1759231

Linux permissions centralized management and behavior log audits

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.