Process accounting
Posted: Fri Dec 16, 2005 5:35 pm
Hips,
I'm about to send one of my server out in big world, and offer shell access for good friends and not so good friends for various needs.
I had set up and enabled process accounting with accton, and it was working just fine. Then I thought that I need bigger security, and decided to get grsecurity running.
Then problems started. I suppose some option in grsecurity destroys output for accton which logs into /var/log/pacct, and thus makes unusable everything in there.
I have tried to google around and searched forums how to correct this behaviour, but not seeing any help. All I find is that grsecurity has process accounting itself, but not too good documentation what I can do with it.
What I am looking is something similar as lastcomm from that old process accounting, which can be used to check commands executed per user.
Is anyone ran into similar troubles, or can anyone tell me how I should use grsecurity process accounting, or what I can use to easily check what users do on my server?
I'm about to send one of my server out in big world, and offer shell access for good friends and not so good friends for various needs.
I had set up and enabled process accounting with accton, and it was working just fine. Then I thought that I need bigger security, and decided to get grsecurity running.
Then problems started. I suppose some option in grsecurity destroys output for accton which logs into /var/log/pacct, and thus makes unusable everything in there.
I have tried to google around and searched forums how to correct this behaviour, but not seeing any help. All I find is that grsecurity has process accounting itself, but not too good documentation what I can do with it.
What I am looking is something similar as lastcomm from that old process accounting, which can be used to check commands executed per user.
Is anyone ran into similar troubles, or can anyone tell me how I should use grsecurity process accounting, or what I can use to easily check what users do on my server?