System Administrator tips: how to check who deleted the file

Source: Internet
Author: User
Article title: System Administrator tips: how to check who deleted the file. Linux is a technology channel of the IT lab in China. Includes basic categories such as desktop applications, Linux system management, kernel research, embedded systems, and open source.
To enhance the security of systems and applications, administrators often need to know whether users have deleted specific files. The following describes how to achieve the administrator's goal through system audit.

The system security audit function allows you to manage system security with minimal system overhead. it only records object change events and does not record detailed data in the object.

The following is the system setting method:
1. run the go sectools command to Display the * Display the Security Tools Menu.

2. Select Option 10: Change Security Auditing

3. change the system value QAUDCTL to * OBJAUD and QAUDLVL to * DELETE. Press Enter.

4. if the security audit log does not exist in the system at this time, the system will create it.

5. run the command CHGOBJAUD to change the object audit.

6. in the CHGOBJAUD parameter, enter the name of the object you want to audit. Fill in * change at the parameter objaud.

7. Repeat Steps 5-6 to add the object you want to audit.

8. the created log is displayed. after running the go sectools command, select option 22.

9. fill in "DO" in the ENTTYP parameter -- it will record who, when, and what object has been deleted

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.