1、https://blog.csdn.net/weixin_33739541/article/details/92033151
sshd服务日志存放在:/var/log/secure.
奇怪sshd配置文件中没有制定,但日志却存放在这?
vim /etc/rsyslog.conf
-
# The authpriv file has restricted access.
-
authpriv.* /var/log/secure
tailf /var/log/secure
因为secure存放了很多服务器的日志,对日志分析很麻烦,我们应该把日志另外存放,配置ssh配置文件
-
[
-
-
SyslogFacility AUTHPRIV
-
-
改 SyslogFacility local1
-
-
更改日志服务配置
-
[
-
-
local1.* /var/log/sshd.log
-
重启日志服务和sshd服务